Predictions for 2010
In December of 2009, Bill Brenner from CSO Magazine asked me what to expect from 2010. I’d actually never done one of these “predict the future” writeups before, but I took a shot at it. Bill ended up posting the more CxO of these. Here’s (roughly) the full set:
1. Economics will cause a few members of the “Old and Hoary Prediction Club” to finally come true.
One of the defining laws of security in general can be thought of as: “What could possibly go wrong is much more than what actually does.” Most bad things do not happen because they’re prevented. They don’t happen because “the bad guys” simply do not choose to do them. But this is truly the first major economic recession of the Information age, and whatever the numbers say, a *lot* of people are struggling. That’s motive. People who struggle get creative, by which I mean “start doing creative and profitable things they heard about”. Not everything that’s been predicted in previous years will come true, but at the end of 2010, look back to predictions for 2007, 2008, and 2009. Some of the wrong ones will have happened. One in particular is number two on this list:
2. Cyber extortion will finally enter the public consciousness.
There’s no good data on — wait, this is security. There’s not much in the way of good data on *anything*. But, facing a credible threat to a downtime sensitive, computer driven infrastructure, extortion demands do in fact get paid. Sometimes the system is large, like a public utility or a manufacturing facility. Sometimes it’s not exactly on the side of angels, like an online gaming establishment. And sometimes it’s just some random mom and pop, or even citizen, being told to spend $50 if they ever want to see their documents again. There’s no good way of knowing how big a problem this has been, but this may be the year that extortion, like credit card fraud and even more like identity theft, becomes part of the national conversation. Expect stock filings to start having to disclose unexpected expenses, some truly ill-advised marketing campaigns by security vendors, backlash (not at all entirely undeserved) that the threat is being wildly overblown, and continuing aggression towards the channels by which the extortionists get paid.
3. Prosecution for cybercrime will begin in earnest, starting with the sloppy rich.