{"id":44677,"date":"2020-01-07T09:05:02","date_gmt":"2020-01-07T09:05:02","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=44677"},"modified":"2020-01-08T09:04:04","modified_gmt":"2020-01-08T09:04:04","slug":"proofpoints-2020-predictions-for-the-middle-east","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/01\/07\/proofpoints-2020-predictions-for-the-middle-east\/","title":{"rendered":"Proofpoint\u2019s 2020 predictions for the Middle East"},"content":{"rendered":"\n<p><strong><em>Proofpoint has gathered its top predictions for CIOs to watch out for in 2020. Emile Abou Saleh, Regional Director, Middle East and Africa at Proofpoint, tells us downloaders and botnets abound while supply chains and account compromises will drive phishing.<\/em><\/strong><\/p>\n\n\n\n<p>During 2019, there were many trends within the threat\nlandscape that help paint a picture of what we can expect in 2020. These\ninclude the results of widespread RAT and downloader distribution, significant\nevolution in impostor attacks and increasingly sophisticated attacks on cloud\napplications.<\/p>\n\n\n\n<p>Notably, email will remain the initial threat vector\nof choice for most actors, driving credential phishing campaigns; targeted\nattacks with malware to establish a beachhead within organisations; and for\nwidespread distribution of banking Trojans, downloaders, backdoors and more. <\/p>\n\n\n\n<p>However, cloud-based email systems like Microsoft\nOffice 365 and GSuite will themselves also be key targets for threat actors,\nproviding platforms for future attacks and lateral movement within targeted organisations.<\/p>\n\n\n\n<p>As cybercriminals are increasingly shifting their\nfocus from targeting infrastructure to targeting people, in 2020 it is vital\nthat organisations\nin the Middle East, as well as across the globe, recognise the human factor threat as\nany organisation,\nregardless of its geography, is a target of those threat actors. <\/p>\n\n\n\n<p>Aligned with this, Proofpoint gathered the below top\npredictions for CIOs to watch out in 2020:<\/p>\n\n\n\n<p><strong>Ransomware<\/strong><\/p>\n\n\n\n<p>Despite its near absence as a primary payload in\nmalicious emails, ransomware continued to make headlines throughout 2019,\nlargely in so-called \u2018big game hunting attacks.\u2019 We expect these types of\nattacks \u2013 in which threat actors focus on high-ransom attacks on servers and\nendpoints in mission-critical environments that are most likely to pay to\ndecrypt their files for rapid recovery &#8211; to continue in 2020. <\/p>\n\n\n\n<p>Additionally, organisations will\nincreasingly find that once they are victims of ransomware, they have already\nbeen compromised with a versatile malware strain that creates potential future\nvulnerabilities and exposes data and intellectual property.<\/p>\n\n\n\n<p><strong>Complex infection chains<\/strong><\/p>\n\n\n\n<p>While most users have largely been conditioned to\navoid attachments from unknown senders, the increasing prevalence of cloud\napplications and storage means that we are all conditioned to click through\nlinks to view, share and interact with a variety of content. <\/p>\n\n\n\n<p>Threat actors will continue to <a>capitalise\n<\/a>on this in 2020, both because of its effectiveness in social engineering\nand because URLs can be used to mask increasingly complex infection chains that\nmake detection more difficult than a simply linked payload. <\/p>\n\n\n\n<p>Whereas URLs frequently linked to an executable for a\nmalicious document in the past, 2020 will see increases in the use of URL\nshorteners, traffic distribution systems and other hops to hide final payloads\nfrom defenders and automated systems.<\/p>\n\n\n\n<p><strong>Abusing legitimate services<\/strong><\/p>\n\n\n\n<p>Threat actors will expand their abuse of\nlegitimate services for hosting and distributing malicious email campaigns,\nmalware and phishing kits. Similarly, the widespread abuse of\nother legitimate cloud-based hosting services for malware delivery will\ncontinue, <a>capitalising <\/a>on our conditioning to click\nthrough links for shared content and the inability for most organisations to\nblacklist services like Dropbox and Box.<\/p>\n\n\n\n<p>Finally, we predict malvertising activity associated\nwith the Keitaro traffic distribution system (TDS) will expand and continue in\n2020 based on its traffic statistics and the difficulty in blacklisting IPs\nassociated with this type of service.<\/p>\n\n\n\n<p><strong>Brute force attacks get smarter<\/strong><\/p>\n\n\n\n<p>As organisations continue to adopt cloud-based\nproductivity and collaboration software, these platforms become increasingly\nattractive targets for threat actors. <\/p>\n\n\n\n<p>While traditional brute force attacks on these and\nother cloud services will continue in 2020, we expect these attacks to become increasingly\nadvanced.<\/p>\n\n\n\n<p>Additionally, while adoption of multifactor\nauthentication is helping to mitigate risks associated with cloud attacks,\nvendors and organisations\nalike are finding that robust implementation carries its own challenges,\ndriving organisations\nto look at biometrics and other potential solutions to secure their\ninfrastructure, whether owned or purchased as a service.<\/p>\n\n\n\n<p><strong>Supply chains expose vertical and horizontal partners<\/strong><\/p>\n\n\n\n<p>Supply chain vulnerabilities took centre stage with\nthe breaches of major retailers in 2013 and 2014. While threat actors have\ncontinued to exploit the supply chain for everything from credit card theft to\nbusiness email compromise (BEC), we expect this tactic to become even more\nsophisticated in 2020.<\/p>\n\n\n\n<p>We also anticipate organisations will\nbegin looking more closely at the wide range of suppliers with which they\nengage. Knowing who these suppliers are and requiring specific types of email\nsecurity in vendor contracts will be critical to limiting threat actors\u2019\nability to hop from one supplier to another until they compromise intended\ntargets. <\/p>\n\n\n\n<p>Furthermore, this will also drive further adoption of\nDMARC as information security teams come together with procurement teams to\ndemand standards-based approaches to vendor security.<\/p>\n\n\n\n<p><strong>Training takes <\/strong><strong>centre<\/strong><strong> stage<\/strong><\/p>\n\n\n\n<p>While automated systems can prevent many threats from\nreaching inboxes, users remain the final line of defence, especially as threat\nactors turn to voice and SMS phishing and multi-channel attacks. <\/p>\n\n\n\n<p>As a result, training is a critical component of\nsecurity but scarce resources demand that organisations be\nincreasingly selective about the training they provide for their users. In\norder to effectively train employees on cybersecurity and ensure those\ntrainings capture the main key-learnings, organisations must\noffer localised\ncontent into different languages taking into consideration the diverse cultural\nbackground of the workforce especially in countries such as the United Arab\nEmirates. <\/p>\n\n\n\n<p>In 2020, we expect that training priorities will be\ndriven by threat intelligence and the types of threats organisations are\nactually experiencing. Additionally, there will be a wider adoption of\nin-client email reporting mechanisms including automation to avoid overwhelming\nIT resources. <\/p>\n\n\n\n<p>Finally, given the challenge in detecting the attacks\nwith automated systems, we also expect that organisations will\nfocus training on internal phishing and email account compromise.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Proofpoint has gathered its top predictions for CIOs to watch out for in 2020. Emile Abou Saleh, Regional Director, Middle East and Africa at Proofpoint, tells us downloaders and botnets abound while supply chains and account compromises will drive phishing. During 2019, there were many trends within the threat landscape that help paint a picture [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":44680,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,13,185],"tags":[10993,3595,155,10996,10995,562,587,7710,1043,10994],"class_list":["post-44677","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-top-stories","category-uae","tag-account-compromises","tag-botnets","tag-cio","tag-complex-infection-chains","tag-downloaders","tag-middle-east","tag-phishing","tag-proofpoint","tag-ransomware","tag-supply-chains"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/44677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=44677"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/44677\/revisions"}],"predecessor-version":[{"id":44699,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/44677\/revisions\/44699"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/44680"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=44677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=44677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=44677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}