# Cyber Attack Targets &amp; Outcomes to Watch Out for in 2019
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-01-11
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Top Cybersecurity Threat Predictions for 2019
Meta Description: CTO Morey Haber of BeyondTrust shares insights on attack vectors/targets and outcomes, highlighting privileged attacks and AI cyber threats.
URL: https://financedigest.com/cyber-attack-targets-outcomes-watch-2019html

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd060718-2-1736840145829-compressed.jpg)

_By_ **_Morey Haber,_** _CTO, BeyondTrust_

There are three jobs in this world where you can be completely wrong all the time and still not have to worry about being fired. One is a parent. Another is a weatherperson. And the last one is a [technology trends forecaster](https://www.financedigest.com/cardiac-valvulotome-market-growth-latest-trends-top-players-competition-technological-advancements-outlook-and-forecast-2028-2.html "Cardiac Valvulotome Market Growth, Latest Trends, Top Players, Competition, Technological Advancements, Outlook and Forecast 2028").Having failed as a weatherman, and with the results of my parenting skills still up for debate, I have turned my mental prowess toward bold predictions on the state of data breaches, [IT security](https://www.beyondtrust.com/), and cyber risks!

I have categorized this list of predictions into two categories—Attack Vectors/Targets, and Attack Outcomes. Attack vectors/targets include the mechanisms [cyber](https://www.financedigest.com/lloyds-of-london-investigates-possible-cyber-attack.html "Lloyd’s of London investigates possible cyber attack") attackers will use, as well as their ultimate objectives. Attack outcomes include how organizations will respond.

**Attack Vectors/Targets**

**_Privileged attacks continue_**

![Morey J. Haber](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/morey-450x676-1736840145808-compressed.jpg)

Morey J. Haber

Privileged attack vectors will continue to be the number one root cause of [breaches for both consumer and business data](https://www.financedigest.com/amazons-twitch-hit-by-data-breach-due-to-configuration-error.html "Amazon’s Twitch hit by data breach due to configuration error"). While [Gartner](https://www.gartner.com/smarterwithgartner/gartner-top-10-security-projects-for-2018/?utm_source=LinkedIn&utm_campaign=sm-swg&utm_medium=social&sf191209564=1) acknowledged that Privileged Access Management as the top security priority for 2018, many organizations are still in denial of their privileged account risks, which frequently stem from poor password management hygiene.

2019 will see even more high-profile breaches. Organizations must discover and manage their privileged accounts because the attack vector is not going away anytime soon, and ugly newspaper headlines will continue to plague boardrooms.

**_Well-known vulnerabilities will continue to dominate cyber-attack reports_**

The pattern of successful attacks through the use of well-known and entirely preventable vulnerabilities shows little sign of abating. [Organizations continue to focus](https://www.financedigest.com/organic-fertilizer-market-where-should-participant-focus-to-gain-maximum-roi-exclusive-report-by-future-market-insights.html "Organic Fertilizer Market | Where Should Participant Focus To Gain Maximum ROI | Exclusive Report By Future Market Insights") their efforts injudiciously, ignoring the lower severity vulnerabilities with known exploits in favor of largely academic, high severity vulnerabilities. This leaves their systems vulnerable to becoming footholds, which can then open up pathways for further exploitation, resulting in major data exfiltration incidents.

**_Artificial Intelligence (AI) on the attack―_** [**_Skynet is becoming self-aware_**](https://www.youtube.com/watch?v=4DQsG3TKQ0I) **_!_**

2019 will see an increasing number of attacks coordinated with the use of AI/Machine Learning. AI will analyze the available options for exploit and [develop strategies](https://www.financedigest.com/yves-mirabaud-says-we-are-on-track-with-our-development-strategy.html "Yves Mirabaud Says “We are on track with our development strategy”") that will lead to an increase in number of successful attacks.

AI will also be able to take information gathered from successful hacks and incorporate that into new attacks, potentially learning how to identify defense strategies from the pattern of available exploits. This evolution may potentially lead to attacks that are significantly harder to defend against.

**Industrial[control systems](https://www.financedigest.com/the-automation-control-system-market-to-see-through-the-probable-sea-change-through-digitization.html "The Automation Control System Market to see through the probable sea change through digitization") come into focus**

The [next few years](https://www.financedigest.com/suedzucker-expects-to-raise-its-sugar-prices-again-next-year.html "Suedzucker expects to raise its sugar prices again next year") will see an increase in the attention that ICS/SCADA systems attract from cybercriminals and nation-state hackers. The opportunity to create ransomware scenarios directly affecting [critical national infrastructure](https://www.financedigest.com/hiding-in-plain-sight-finance-as-critical-national-infrastructure.html "Hiding in plain sight – Finance as Critical National Infrastructure") will draw attention from cyber criminals motivated both, by financial gain, as well as those who are looking to develop weapons in the evolving cyber-frontline.

Historically, Operational Technology (OT) teams have been reluctant to engage with IT security practices, but we are seeing this change as all teams recognize that [cybersecurity is a critical aspect of business](https://www.financedigest.com/are-businesses-using-cybersecurity-as-a-scapegoat-for-a-desperate-return-to-office-working.html "Are Businesses Using Cybersecurity As A Scapegoat For A Desperate Return To Office Working?") continuity.

**The [supply chain is at risk</strong](https://www.financedigest.com/minimising-supply-chain-cyber-risks-by-asking-the-right-questions.html "MINIMISING SUPPLY CHAIN CYBER RISKS BY ASKING THE RIGHT QUESTIONS") >**

Major security breaches will continue to dominate the news, but the latest form of attacks on organizations will come in the form of an attack on their [supply chains](https://www.financedigest.com/eliminating-payment-barriers-the-future-of-supply-chain-payments-is-digitization.html "Eliminating Payment Barriers: The Future of Supply Chain Payments is Digitization").

Considering the recent [Bloomberg article](https://www.bloomberg.com/news/features/2018-10-04/the-big-hack-how-china-used-a-tiny-chip-to-infiltrate-america-s-top-companies) accusing China of embedding chips the size of a grain of rice into super micro servers, and previous attacks using embedded chips on printers purchased by the United States Government, the threat is very real.

Corporate attacks and corporate espionage will take on a whole new meaning as more [supply chain](https://www.financedigest.com/supply-chain-management-bpo-market-is-thriving-with-rising-latest-trends-2014-2020.html "Supply Chain Management BPO Market Is Thriving With Rising Latest Trends 2014 – 2020") attacks with embedded malware are discovered. But this is the tip of the iceberg in terms of cyber threats—the major devices targeted will be [IoT](https://www.beyondtrust.com/solutions/iot-security/) and will range anywhere from consumer-based routers to home-based nanny cams. Expect the supply chain for many vendors, including those that produce personal digital assistances, to be a new target from threat actors who infiltrate environments and insecure [DevOps](https://www.beyondtrust.com/solutions/devops-security/) processes.

**Attack Outcomes**

**_Android closes open access_**

Android will no longer be fully open and extensible. Google has already [announced](https://www.zdnet.com/article/google-restricts-which-android-apps-can-request-call-log-and-sms-permissions/) that only the “default” application can access calls and SMS texting data for the next release of Android, and the default application must be explicitly set in the configuration. No longer can multiple applications―including tools used for spam detection—be [shared with your favorite calling](https://www.financedigest.com/exclusive-with-eye-on-big-tech-energy-crisis-eu-telcos-call-for-shared-network-costs.html "Exclusive-With eye on Big Tech, energy crisis, EU telcos call for shared network costs") and texting applications.

Expect Google to continue this trend to fight malware and spyware by closing more of the [operating system](https://www.financedigest.com/robot-operating-system-market-is-witnessing-a-sustainable-growth-due-to-increase-in-demand-scrutinized-in-the-new-analysis.html "Robot Operating System Market is witnessing a Sustainable Growth Due to Increase in Demand Scrutinized in the New Analysis") in the name of security.

**_Monetizing data_**

[Infonomics](https://www.gartner.com/en/publications/infonomics) will begin to become mainstream and, just like other intellectual property, expect businesses to begin applying a value to the data and disclosing the information they have and what it costs “for sale”.

If you think this is farfetched, consider the value of GPS data over the last 30 years. From the early days of MapQuest to dedicated GPS receivers, [driving and transportation data](https://www.financedigest.com/how-alternative-data-drives-e-commerce-success.html "How Alternative Data Drives E-commerce Success") has become a commodity.

However, if you start layering other data―like traffic, construction, etc.—used by the likes of Waze, you have a high-valued database that will become crucial for [autonomous cars](https://www.financedigest.com/impact-of-covid-19-outbreak-on-autonomous-car-market.html "Impact Of Covid-19 Outbreak On Autonomous Car Market"). There is real value there, and it will come at a [price to car](https://www.financedigest.com/upset-by-high-prices-gms-cruise-develops-its-own-chips-for-self-driving-cars.html "Upset by high prices, GM’s Cruise develops its own chips for self-driving cars") manufacturers. The data itself therefore has a value, and businesses will begin [rating themselves more publicly](https://www.financedigest.com/sp-global-fined-1-1-million-euros-for-premature-credit-rating-publications.html "S&P Global fined 1.1 million euros for premature credit rating publications") on the Infonomics they possess. And not just to private equity firms or other businesses looking at [merger and acquisition](https://www.financedigest.com/how-to-handle-cyber-security-during-mergers-and-acquisitions.html "How to Handle Cyber Security during Mergers and Acquisitions") activities, or purchase of the information.

**_Millennials ruin everything―evolving definitions of privacy_**

The millennial generation will share almost anything on the Internet. [Social media has proven that almost anything goes](https://www.financedigest.com/elon-musk-goes-viral-on-chinese-social-media-with-ancient-poem-post.html "Elon Musk goes viral on Chinese social media with ancient poem post") regardless of its perceived sensitivity. This implies that nearly an entire generation has a lower sensitivity to private data and that a “who cares” attitude for sensitive [information](https://www.financedigest.com/health-care-information-systems-market-growth-set-to-surge-significantly-during-2018-2026.html "Health Care Information Systems Market Growth Set to Surge Significantly during 2018 – 2026") is beginning its own movement.

In addition, as we become numb to data exposure, expect some [push back](https://www.financedigest.com/ukraine-pushes-russian-forces-back-restricts-gas-flow-to-europe.html "Ukraine pushes Russian forces back, restricts gas flow to Europe") from the youngest voting group regarding the data being exposed due to a hack. If most sensitive personal data is public (like name, email, address, birthday, etc.) and only the most [important information](https://www.financedigest.com/software-to-display-your-businesss-important-information.html "Software to Display Your Business’s Important Information") protected (national ID numbers, bank records, credit cards), the value is diminished for anything already being exposed today and the “who cares” movement has begun.

Expect data classification to evolve based on the youngest users, and what we consider private today will not be private, or of a concern, tomorrow.

**_Centralized information brokers emerge_**

In an effort to protect and control the exposure of [personal data](https://www.financedigest.com/data-privacy-and-navigation-how-our-personal-data-is-used-in-navigation-apps.html "Data Privacy and Navigation: How our personal data is used in Navigation Apps."), information ‘brokers’ will begin to emerge. These services will [provide](https://www.financedigest.com/unprecedented-constructive-disruption-to-drive-the-sleep-service-providers-market.html "Unprecedented, constructive disruption to drive the Sleep Service Providers Market") centralized mechanisms that allow granular sharing of data so that only the essential data is shared for whatever service you are signing up to.

The EU has been working on digital identity in this form for several years and may well be the first to bring that into full effect, but others will follow in providing a mechanism by which our data is decentralized. This will help limit individual data exposures when [systems are compromised and allow more control by individuals over their data and who has legitimate access](https://www.financedigest.com/telehealth-monitoring-to-rule-the-the-transseptal-access-systems-market.html "Telehealth monitoring to rule the The Transseptal Access Systems Market") to it.

In closing, as in any cyber defense strategy, I first recommend getting the basics right—secure your privileged accounts, eliminate excessive user privileges, ensure secure remote access to critical systems, patch the vulnerabilities with known exploits, and report, report, report.

I wish you all a prosperous and attack-free 2019!


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

