Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

2018 will see governments bring the fight to cyber criminals

by The Gurus
January 2, 2018
in This Week's Gurus
Share on FacebookShare on Twitter

David Ferbrache, chief technology officer in KPMG’s cyber security practice, highlights ten cyber security trends we can look out for in 2018. He said:

 

  1. Everyone will be waiting for 25th May

“This is the day that the General Data Protection Regulation (GDPR) comes into force. Most firms have taken time to understand what GDPR may mean for them, and in many cases have reviewed (or even partially disposed of) their holdings of personal data. It is far harder to predict quite how sanctions under GDPR will be applied by the various regulators. We can expect a few high profile examples to be made early on, but perhaps not the tsunami some expect. Nevertheless, privacy rights are on the agenda, and we can expect zero regulatory tolerance for the long delays in notification of major breaches seen recently.”

 

  1. Criminals will hunt out the weak points

“Organised crime groups are on the hunt for new ways to monetise stolen information and access to systems, and in a post Bank of Bangladesh world they will be increasingly creative in how they do this. We can expect more attempts to initiate fraudulent payment transactions (often with a social engineering elements), as well as ongoing interest in our core financial infrastructure including payment and trading platform gateways. Growing demands are being placed on fraud control and anti-money laundering systems to catch these transactions, while customers demand instantaneous financial transfers. If these controls fail, expect to see a $100 million pay-out from a cyber-attack”.

 

  1. Governments will continue to block and tackle cybercrime

“As criminals industrialise cyber-attacks using crime as a service model to rent attack tools and ransomware, governments are increasingly looking for ways to disrupt the infrastructure used by criminals. Closer links with telcos and service providers are being built along with the operational processes needs to block sites hosting malware, detect and counter phishing attacks. Trusted DNS services and Domain-based Message Authentication, Reporting and Conformance (DMARC) will be rolled out at scale across the community by both the National Cyber Security Centre and by organisations such as the Global Cyber Alliance. These community measures linked to improved intelligence sharing will start to make a difference.”

 

  1. A new model of cyber security will emerge

“As firms invest more in cloud computing, a new model for cyber security is emerging. Increasingly, firms can look to cloud providers to embed good IT security, but firms still own the problem of setting their requirements and determining just who can access what. The shift towards DevOps and agile development, build on these more flexible infrastructures also demands new ways of embedding security into the development lifecycle and an equally agile test regime. Security can no longer engage at the end of development cycles, and if it does, it risks being seen as a blocker rather than an enabler.”

 

  1. Automation of controls and compliance will be the order of the day

“Firms are coming under pressure to contain their burgeoning cyber security budgets. Manpower intensive compliance processes are beginning to give way to continuous testing and controls monitoring, helping firms build a more accurate picture of their IT estate – helping the CIO as well as the CISO. The growing demand for supply chain security and third party assurance will also lead to a burgeoning industry of testing firms offering risk scoring and testing services for those third parties.”

 

  1. Digital channels will demand customer centric security

“Digital channels are becoming more and more sophisticated demanding new consumer identity and access management approaches, dynamic transaction risk scoring and fraud controls, and an emphasis on usable non-intrusive security measures which don’t impact the consumer’s experience. Open Banking and the arrival of Payment Services Directive 2 will drive richer interactions between a new ecosystem of payment service providers and the banks who handle our money. A new world of open API is on the horizon, but concerns over criminal exploitation of these rich interfaces abound.”

 

  1. The internet of insecure things continues

“Criminal groups continue to exploit insecure ‘internet of things’ devices as sources of attack traffic for denial of service attacks, leading to more and more extortion attacks but also an increasingly sophisticated response from the international community involving telcos, content delivery networks and Distributed Denial of Service (DDoS) mitigation firms. Unfortunately, this response won’t be consistent globally, and many nations may find themselves vulnerable to these attacks which will cause major disruption in 2018.”

 

  1. The Shadow of State activity lengthens

“As countries invest to develop their cyber espionage and offensive capabilities, we will see more signs of their activities. Disclosures of high end techniques used by nations will continue, fuelling the opportunistic re-purposing of these vulnerabilities by less sophisticated States and organised crime groups. Expect more evidence of industrial control system attack tools being tested as States explore the potential of this new form of warfare.”

 

  1. Balkanisation continues and paranoia grows

“States continue to intervene to protect their national security interests in cyberspace, risking an increasingly complex framework of international regulation and controls around the supply chain for critical infrastructure firms. While there will be some moves to align regulation across the global financial sector around the G7 fundamental elements of cyber security, this will take time and effort to achieve.”

 

  1. Resilience and speed matters

“Regulators are focussing on resilience – the ability of an organisation to anticipate, absorb and adapt to disruptive events – whether cyber-attack, technology failure, physical events or collapse of a key supplier. Exercises and playbooks are in fashion as firms try to build the muscle memory they need to respond to a cyber-attack quickly and confidently, while cyber insurance is finding its place not just as a means of cost reimbursement but as a channel for access to specialist support in a crisis.”

Tags: CybersecurityTechnology
ShareTweet
Previous Post

The path for SMEs and GDPR

Next Post

Defending the oil and gas sector from cyber-attacks

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol