Future risks in the world of information security
- Mar 9, 2022
- 3 min read
Updated: Mar 25, 2022
Better hacker tools are available every day, on hacker websites that, themselves, proliferate. These tools are improved regularly and, increasingly, less and less technologically proficient criminals - and computer-literate terrorists - are thus enabled to cause more and more damage to target networks and systems.
There are a number of trends that lie behind these increases in threats to computer-based information security, which when taken together suggest that things will continue to get worse, not better:
1. The use of distributed computing is increasing. Computing power has migrated from centralised mainframe computers and data processing centres to a distributed network of desktop computers, laptop computers, microcomputers, and mobile devices, and this makes information security much more difficult to ensure.
2. There is an unstoppable trend towards mobile computing. The use of laptop computers, personal digital assistants (PDAS), mobile and smart phones, digital cameras, portable projectors, MP3 players and iPads has made working from home and while travelling relatively straightforward, with the result that network perimeters have become increasingly porous. This means that the number of remote access points to networks, and the number of easily accessible endpoint devices, have increased dramatically, and this has increased the opportunities for those who wish to break into networks and steal or corrupt information.
3. There has been a dramatic growth in the use of the internet for business and social media communication, and the development of wireless, voice over IP (VOIP) and broadband technologies is driving this even further. The internet provides an effective, immediate and powerful method for organisations to communicate on all sorts of issues. This exposes all these organisations to the security risks that go with connection to the internet:
The internet is really just a backbone connection that enables every computer in the world to connect to every other computer. This gives criminals a direct means of reaching any and every organisation that is connected to the internet.
The internet is inherently a public space. It is accessible by anyone from anywhere and consists of the millions of connections, some permanent and some temporary, that come about because of this. It has no built-in security and no built-in protection for confidential or private information.
The internet (together with cellular telephony) is also, in effect, a worldwide medium for criminals and hackers to communicate with one another, to share the latest tricks and techniques and to work together on interesting projects.
Better hacker tools are available every day, on hacker websites that, themselves, proliferate. These tools are improved regularly and, increasingly, less and less technologically proficient criminals - and computer-literate terrorists - are thus enabled to cause more and more damage to target networks and systems.
Increasingly, hackers, virus writers and spam operators are cooperating to find ways of spreading more spam - not just because it's fun, but because there's a lot of money to be made out of the direct email marketing of dodgy products. Phishing, pharming and other internet fraud activity will continue evolving and are likely to become an ever bigger problem.
4. This is leading, inevitably, to an increase in 'blended' threats, which can only be countered with a combination of technologies and processes.
5. Increasingly sophisticated technology defences, particularly around user authorisation and authentication, will drive an increase in ‘social engineering-derived hacker attacks.
6. Computer literacy is becoming more widespread. While most people today have computer skills, the next generation are growing up with a level of familiarity with computers that will enable them to develop and deploy an entirely new range of threats. Instant messaging is an example of a new technology that was better than e-mail in that it was faster and more immediate, but has many more security vulnerabilities than e-mail. We will see many more such technologies emerging.
7. Wireless technology - whether Wi-Fi or Bluetooth - makes information and the internet available cheaply and easily from virtually anywhere, thereby potentially reducing the perceived value and importance of information and certainly exposing confidential and sensitive information more and more to casual access.
8. The falling price of computers and mobile devices has brought computing within most people's reach. The result is that most people now have enough computer experience to pose a threat to an organisation if they are prepared to apply themselves just a little bit to take advantage of the opportunities identified above.


Comments