Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecurityCybersecurity News

Expect 2022 to be the year of cybersecurity

By Stel Valavanis
cyber-security-network-freepik
November 11, 2021

2022 is just around the corner, and we are already following new developments in cybersecurity that will significantly impact your business in this upcoming year and the rest of the decade. Predicting the future may sometimes seem an impossible task, especially given the speed with which our world and the world of cybersecurity change, but there are already signs of two major shifts I see coming in 2022 that you will want to have on your radar.


#1. Regulations are Finally Coming

As many parts of the government tighten their control over cybersecurity, and court decisions set a new precedent: companies will have to adapt and respond. Yes, it represents added pressure and cost, but most changes should already be practiced by most organizations, and they do indeed elevate the security posture.


We have already begun to see indications and movement towards this, but my prediction is that we will see new regulations fast-tracked for cybersecurity standards, first in the form of executive orders to government suppliers (already started), and then expanding to regulated industries via more specialized government agencies. The policies and standards eyed by this legislative and regulatory shift of focus are already present, and we are seeing this administration make moves that have long been heralded. Recent rulings by the SEC, for example, put incident disclosure at the top of the list of things that will change, but policy and processes such as scanning and detection will also soon be scrutinized. Other areas of the economy, such as insurance, will be included as their connection to cybersecurity becomes stronger and clearer.


Court decisions and penalties such as government fines will set a precedent, and companies will make moves to avoid the newly articulated risks of non-compliance in cybersecurity. This will create a new cybersecurity floor, a standard by which many companies will have to rise to meet. The level of security to reach mere compliance will be closer to the standard of being highly secure, though many will still make their deployment decisions based on compliance versus security.


Further down the road, expect pressures from governments for more accountability for CISOs similar to CFOs. This could come in many forms, but the NYDFS regulations could be a template. Organizations will need to support CISO efforts to confidently attest to the company’s security posture.


Globally, cryptocurrency will face additional regulation and affect the nature of ransomware. Banks have long been expected to know their customer, and blockchain ledgers aren’t quite private but rather anonymous. Expect exchanges and others in the ecosystem to face unveiling customers under subpoena. Criminal gangs will employ new tactics that only larger organizations can perform.


The following are some specific regulations we expect to see in 2022:

 

  • SEC penalties for lack of transparency will extend to vulnerabilities and not just incident disclosure.

 

  • New cryptocurrency regulation in several countries will change the nature of ransomware, discouraging any but the bigger gangs who typically target larger organizations.


  • Ransomware disclosure laws (proposed by Senator Warren) will get push back for private companies. Still, the list of “terrorist organizations” that can’t be paid ransom will increase greatly to make up for it.


  • Cyber insurance coverage will increasingly depend on the existing level of cybersecurity posture, and organizations will have cybersecurity standards they’re expected to meet. 


#2. The Supply Chain Will Be Scrutinized

Gaps in the supply chain and inadequate security operations by vendors and third parties have been to blame for many of the notable attacks on private industry in the last decade or so with few consequences. However, the response from the industry has been a slight move to improve vendor management, but nothing of note. This will be an important area of focus in 2022, starting with greater disclosure.

 

For one, the myth that Cloud Computing is inherently more secure will be further exposed. In fact, the opposite is true, and those vendors will be scrambling to add in more caveats to cover their liability, but also to build and partner to fill those gaps or, at minimum, disclose their gaps. The backdoor inadvertently created by automated AWS appliance installations allowed hacker rootkits to be installed. Customers didn’t create that exposure, Amazon did. The potential risks of cloud computing will become too much to bear for many workloads, and the benefits of going to the cloud will diminish as security is prioritized over convenience. It’s become clear that the use of third-party vendors only outsources the work and not the risk. If something happens, the blame and responsibility will fall legally and socially on the company, not its vendors. In general, the whole IT supply chain is on notice, and we could see a big fallout if another such wide-scale incident like the SolarWinds, Hafnium, or Kaseya attack occurs.


Vendors will work to try to (quickly) fill in the security gaps that exist, although I don’t think it possible that they will ever be able to solve the frequent problems that employee errors and negligence present for cloud computing customers. Vendors may change their marketing language and service policies to make it more clear that the gaps they are unable to cover exist, but that will likely have the effect of warding off potential customers. Sophisticated and well-resourced customers can apply more controls and scrutiny, but they need more transparency and accountability to do so. In the further future, years from now, hosting providers may be willing to (or compelled to) take more responsibility for security vulnerabilities, but any such change would more likely be the result of regulation.


 As many of the reasons Cloud computing has been so popular are either made irrelevant by developments in cybersecurity (attacking and defending) or revealed to have been myths the entire time, the reasons to move to the cloud will become more specialized and may no longer be seen as a panacea for all business computing concerns. This seems an unlikely shift in momentum, however, and companies with high-security concerns will perhaps move certain workloads back to the premises or host them securely via private colocation, but the general business world’s move to the cloud will continue, creating more exposure as it does. Cloud computing infrastructure is the “pipeline” of the information age even more than the Internet itself. Its exposure should be of national economic concern.


Over the past few years, large-scale attacks like the Colonial Pipeline attack have shown how vulnerable the larger economic supply chain is to cybercrime. The stakes are higher now, as the infrastructure and ability of our country to do business are more severely impacted by a cyberattack. The collateral damage is too much to ignore. 


The fatigue many have developed over the effects of a data breach, such as identity theft, has not reached the height of what the actual effects of cyberattacks are quickly becoming. Without even intending to create large-scale problems, a cyberattack caused a large gas shortage in the United States. The effects were felt far and wide by many who have no ostensible relation to the target, except via supply chain. Affecting people outside the targeted organization means increased attention criminals don’t want. But their need to go for bigger payloads improved security measures, and the availability of cyber insurance have conspired to raise criminal activity to these new heights and greater exposure.


Good News and Bad News

It’s good news, and it’s bad news. Governments and industries are going to do more and do better. We will all be more secure because of it. But we need not resist these efforts, inconvenient as some may be. The threat of crime and its scale will increase in 2022 partly in response to our improving security posture and because cybercriminals are now large professional enterprises, whole ecosystems in fact, and they need to keep growing.

KEYWORDS: compliance cyber security risk management supply chain

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Stel valavanis onshoresecurity

Stel Valavanis, CEO onShore Security, is an internationally-recognized security thought leader. Valavanis is a member of Chicago Arch Angels and is an investor in a number of early-stage tech companies. He currently sits on the board of several leading nonprofits including the ACLU of Illinois where he advises on digital privacy. Valavanis is also an active alumnus of the University of Chicago.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

The Lourve

The Lourve Heist: What Was the State of the Museum’s Security?

The 2025 Security Benchmark Report

The 2025 Security Benchmark Report

American Airlines

Security Leaders Discuss Cyberattack on American Airlines Subsidiary

Office supplies

Security Leaders Share Why 77% Organizations Lose Data Due to Insider Risks

Going Down with the Ship

Going Down with the Ship

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • us-capitol

    Security practices state Capitols should put in place today

    See More
  • cybersecurity finger pointing

    97% of execs expect firms will be highly impacted by AI in a year

    See More
  • TrendMicroCRI

    80% of global businesses expect a breach of customer records in the next year

    See More

Related Products

See More Products
  • facility manager.jpg

    The Facility Manager's Guide to Safety and Security

  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

  • The Complete Guide to Physical Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing