Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Top Seven Cybersecurity Ripple Effects From 2020
Articles

Top Seven Cybersecurity Ripple Effects From 2020

Ilia SotnikovBy Ilia SotnikovMarch 11, 2021Updated:February 13, 20234 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The year 2020 definitely shook up the IT world. The urgent need to rely on distributed workforces forced organizations to accelerate their digital transformations and broadened the IT threat landscape. Looking closely at the ripple effects from 2020 it’s clear security pros won’t be able to yawn their way through 2021.

Here are seven key trends that that will impact organizations in 2021 and beyond:

1. Ransomware will become more sophisticated and will affect the physical world.

Ransomware will remain one of the most straightforward ways for cybercriminals to monetize a breach. Organizations will get better at thwarting attacks and recovering from incidents, but the arms race will continue and ransomware will evolve.

In particular, to compel organizations to pay the ransom, attackers will focus on making attacks more difficult to recover from. For example, they may “brick” devices by modifying the BIOS or other firmware. As operational technology and IoT devices become more common and communication protocols standardize, criminals will target them as well. As a result, attacks will have a much more visible impact on the physical world.

2. Cloud misconfigurations will be a top data breach cause.

The cloud played a huge role in enabling a swift shift to remote work in 2020. But lack of understanding of the shared responsibility model and the security hurdles in the cloud will cause serious problems in 2021. Indeed, the global shortage of IT pros skilled at cloud management and security, combined with lack of visibility into cloud design and workloads, will make cloud misconfigurations inevitable, leading to overexposed data and breaches.

3. MSPs will become lucrative targets for hackers.

With the worldwide IT skills shortage and financial downturn, more and more organizations will rely on managed services. Hackers will then ramp up their attacks on MSPs in order to compromise several businesses at once and monetize their activities at a devilishly high speed.

4. The rapid digital transformation in 2020 will have delayed effects.

Many organizations rushed through their digital transformation in 2020. There was almost no time for planning and testing, and often IT teams lacked sufficient knowledge and experience. Organizations had to prioritize service availability over security, which resulted in unpleasant tradeoffs, and IT pros faced with unfamiliar systems inevitably made mistakes. Some of the resulting security gaps have already been exploited, but we should expect more of them to come to light in the coming year.

5. Organizations will better align security and business needs by focusing on risk.

In 2020, executives had a front-row seat for seeing how closely business risks are associated with cyber events. In 2021, their interest in establishing a mature security posture will increase, and they will rethink their risk management strategies based on more realistic expectations.

Specifically, more organizations will recognize that the goal of a security program is to keep risk at acceptable level and enable resilience, not 100% protection. Accordingly, they will balance their security spend between protective measures and detection and response capabilities.

6. Executives will carefully scrutinize the efficacy of security investments.

A higher awareness of security threats among executives will bring new budgets for security programs, but also a higher level of scrutiny. They will want IT leaders to come up with specific metrics to prove the efficacy of existing security measures and justify the necessity and value of new investments.

Security leaders will also need to develop cost reduction plans. In particular, they should flag overlapping software to eliminate duplicate expenses, and review each solution for unused features and functionalities that could be leveraged, increasing ROI.

7. Insurance and legislation will drive mass adoption of fundamental security practices.

With more breaches being caused by companies failing to take adequate care of customer personal information, we will see both stricter enforcement of existing regulations and adoption of new privacy laws. Also, the grace period on enforcement of some compliance mandates during the early months on the pandemic will expire in 2021.

Faced with increased risk of non-compliance fines as a result of these developments, organizations will turn to cyber insurance. Those policies will come with their own security standards, such as regular risk assessment and effective detection and response capabilities. Organizations will be as focused on meeting those criteria as they will be on complying with the regulatory standards themselves.

Ilia Sotnikov
Ilia Sotnikov

Ilia Sotnikov is Security Strategist & Vice President of User Experience at Netwrix. He has over 20 years of experience in cybersecurity as well as IT management experience during his time at Netwrix, Quest Software, and Dell. In addition, Ilia is a regular contributor at Forbes Tech Council where he shares his knowledge and insights regarding cyber threats and security best practices with the broader IT and business community.

  • Ilia Sotnikov
    How to Defend Against High Cyberthreat Activity During the Holidays
  • Ilia Sotnikov
    Five Ways to Improve Your Security Posture, Fast
  • Ilia Sotnikov
    Top Cybersecurity Trends To Consider For The New Year
  • Ilia Sotnikov
    How To Control Costs And Risks As Data Subject Access Requests Increase

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}