Dec 30, 2025

AI Analysis of Cybersecurity Predictions 2026



Lots of cybersecurity predictions for 2026 have been popping up lately. For me, any single prediction report isn’t very interesting, because these forecasts come from different perspectives and with different agendas. For vendors in particular, predictions are often a marketing tool - a way to convince organizations that their products are must-have purchases.

That’s why it’s much more useful to analyze multiple prediction reports from different sources and look for common patterns.


AI to Help

This time I used AI to help - specifically NotebookLM, which I’ve found to be an effective tool for analyzing large document sets and generating overviews. I uploaded 23 cybersecurity prediction reports and used it to identify the common themes. I then used ChatGPT to shorten and clarify the explanations produced by NotebookLM.

The findings fall into four main categories:

  1. Artificial Intelligence
  2. Identity and Access
  3. Evolving Threat Landscape
  4. Governance and Workforce

Cybersecurity Predictions for 2026

Artificial Intelligence (AI)

Agentic AI Shift

AI stops assisting and starts acting. 

Autonomous AI agents run tasks, make decisions, and execute actions at machine speed. They trust and talk to other machines, creating machine-to-machine trust instead of human logins. In the Agentic SOC, AI handles alerts and response, while humans supervise and investigate.

πŸ‘‰ Security shifts from protecting people to controlling powerful, autonomous machines.

AI-Driven Threats

Cybercrime goes fully automated. 

AI finds and exploits vulnerabilities at machine speed, creates deepfake CEOs to scam money in real time, hijacks AI systems through prompt injection, and runs perfectly written, hyper-personalized scams at massive scale.

πŸ‘‰ Attacks become faster, smarter, and harder to spot — because the attacker is no longer human.

Defensive AI

Defensive AI turns security from reactive to machine-speed proactive.

AI now automatically blocks attacks, predicts where the next hit will come from, and runs custom in-house tools tuned to your environment - so humans stop drowning in alerts and start running the fight.

πŸ‘‰ You can’t outclick AI attackers - so you deploy AI defenders.

Identity and Access

Zero Trust Normalization

The network disappears and identity becomes the perimeter.

Every human, machine, and AI agent is continuously verified based on behavior and intent — not just a login. Old VPNs die, replaced by Zero Trust Network Access (ZTNA), which gives access only to what’s needed and hides everything else.

πŸ‘‰ Trust nothing, verify everything, expose almost nothing. 

Non-Human Identities

Non-Human Identities become the biggest security risk as machines and AI agents outnumber humans 80-to-1. 

Over-privileged machine accounts and shadow AI agents move invisibly across systems, while attackers skip passwords and steal tokens and cookies to hijack trusted sessions.

πŸ‘‰ You’re no longer breached through users — you’re breached through your machines.

Evolving Threat Landscape

Ransomware Evolution

Ransomware evolves into pure extortion.

Attackers stop encrypting and start stealing data, using AI to find your most embarrassing, valuable secrets and threaten to leak them. They go quiet, apply pressure through regulators and families, and increasingly hit critical infrastructure to maximize impact.

πŸ‘‰ It’s no longer about locked files — it’s about stolen truth used as a weapon.

Supply Chain Vulnerabilities

Supply chain attacks go platform-level.
 
Hackers stop picking companies and start hitting hyperscalers, ID-verification hubs, and open-source libraries to breach thousands at once. One weak cloud, one fake identity check, or one poisoned open-source software package becomes a global infection vector.

πŸ‘‰ Your biggest risk now lives in someone else’s code and cloud.

Quantum Threat

Today’s encryption has an expiration date.

Attackers are already stealing encrypted data to decrypt later when quantum machines arrive. The fix is Post-Quantum Cryptography and crypto-agility — knowing where your crypto is and being able to swap algorithms fast.

πŸ‘‰ If you don’t upgrade your crypto now, tomorrow’s quantum computers will read your secrets like yesterday’s newspaper.

Governance and Workforce

Regulatory Pressures

Regulatory pressure goes real-time and unforgiving.

The EU Cyber Resilience Act forces secure-by-design and 24-hour breach reporting. Cyber resilience becomes mandatory to do business, with boards personally liable.  Loose guidelines die, replaced by enforceable baselines and automated compliance.

πŸ‘‰ No resilience, no market access — and no excuses.

Workforce Dynamics

The cyber workforce flips to AI command mode.

There aren’t enough people, so teams scale with AI instead of headcount. Diversity grows (and improves leadership), while AI literacy becomes mandatory for every cyber role.

πŸ‘‰ Fewer humans, more AI — but smarter, more diverse people running the machines.

Market Growth

Cybersecurity explodes into a trillion-dollar market.

AI, critical infrastructure, and digital everything push global cyber spend past $1T by 2031 — with no real ceiling because crime sets the price. At the same time, cyber budgets spread beyond the CISO into cloud, product, and compliance teams.

πŸ‘‰ Cybersecurity stops being an IT cost and becomes a board-level business investment.

Recommendations for actions

By 2026, cybersecurity is no longer about protecting IT - it is about governing autonomous systems, machine identities, and digital trust at scale. Organizations that fail to adapt will not just be breached - they will become ungovernable.

To stay in control, leadership must act across six strategic fronts:

1. Govern AI Like a Workforce

AI agents must be treated as employees with admin rights. Boards must mandate AI governance, runtime controls, immutable audit trails, and identity-based oversight for every autonomous system.

2. Move from Identity to Intent

Passwords and biometrics are no longer enough. Security must shift to continuous behavioral and intent-based verification, backed by out-of-band checks for high-risk actions and aggressive cleanup of machine identities.

3. Automate Defense at Machine Speed

Manual security cannot compete with AI attackers. Organizations must deploy continuous exposure management, ZTNA, automatic remediation, and cloud runtime controls to prevent breaches before they spread.

4. Prepare for the Quantum Cliff

Encrypted data is already being stolen for future decryption. Boards must fund crypto-agility and cryptographic inventories (CBOMs) now, or today’s secrets will become tomorrow’s liabilities.

5. Rebuild the Cyber Workforce

Talent shortages won’t be solved by hiring alone. Teams must use AI, build custom tools, mandate AI literacy, and tap new talent pipelines to scale human capability.

6. Secure the Entire Ecosystem

Your risk now lives in clouds, suppliers, and AI models you don’t control. Organizations must gain visibility into fourth parties and treat AI models as high-risk supply chain assets.


Do It Yourself

I made the sources available on NotebookLM, so you are welcome to explore it with your own questions. Here's also a generated mindmap of the predictions categories. If you don’t feel like deep-diving into the sources, you can also try the NotebookLM-generated podcast



Dec 29, 2024

Book recommendations part II



In 2019, I shared 15 book recommendations tailored for CSOs and CISOs, focusing on security, leadership, and personal growth. Now, five years later, I’m expanding that list with 15 more outstanding reads - books that have influenced my thinking and earned my 5-star rating. Whether you’re a seasoned professional or just curious about these topics, this list offers insights and inspiration to sharpen your skills and broaden your horizons.

As an experienced security and cybersecurity leader, I often look beyond the “security box”: I already understand what needs to be done in security, but figuring out how to make it happen is more challenging. That’s why I gravitate toward books on human behavior, emerging technologies, business, leadership, risk management—and a bit of science fiction for a glimpse into the future. 

You can find my complete reading list on my website or on Goodreads. Since 2019, I’ve rated more than 100 books with four or five stars. Keep in mind, my ratings are influenced by my existing knowledge, current interests, and the books I've read earlier, so your experience may differ.

Interestingly, my reading habits have shifted over the past five years: I used to consume a fairly even mix of physical books, e-books, and audiobooks (with e-books edging out slightly). Now, half of my book consumption is done in audio format, and e-books have become my least used medium.

Now to the books I've selected. Grouped per high-level topic, in no particular order.

Security

🌟Strategic Security: Forward Thinking for Successful Executives by Jean Perois

An excellent overview of the challenges in running a security department, paired with practical strategies to address them. Topics range from strategic thinking and selling security initiatives to implementing and measuring security programs, building awareness, fostering creativity, and personal development. A highly recommended read - even for seasoned security practitioners.

🌟This Is How They Tell Me the World Ends: The Cyberweapons Arms Race by Nicole Perlroth

A through examination of the vulnerabilities in our increasingly digital world. While the author discusses many high-profile breaches and incidents that have already been extensively documented, they do so in a refreshingly insightful way. This book offers the most detailed exploration of the software vulnerability market I’ve encountered. It’s truly concerning that governments allocate vast sums of money to acquire vulnerabilities for offensive or surveillance purposes.

🌟Security Chaos Engineering: Sustaining Resilience in Software and Systems by Kelly Shortridge, Aaron Rinehart

A book that questions conventional approaches to building secure IT systems. By reframing the discussion from security to resilience, the author offers a fresh perspective on software design and implementation, particularly regarding application design, development, and testing. 

🌟Putin's Trolls: On the Frontlines of Russia's Information War Against the World by Jessikka Aro

Jessikka is a Finnish journalist who has faced harassment, smear campaigns, and threats ever since she began reporting on Russian disinformation operations and troll factories. This book not only explores her personal experiences but also highlights other cases in which Russia has attempted to discredit and silence journalists and researchers.

Business, Leadership

🌟Chaos Monkeys: Obscene Fortune and Random Failure in Silicon Valley by Antonio García Martínez

An entertaining look at the Silicon Valley startup scene and the early days of Facebook’s advertising model. This book offers a starkly cynical perspective that might make you reconsider your startup ambitions.

🌟The Four Workarounds: Strategies from the World's Scrappiest Organizations for Tackling Complex Problems by Paulo Savaget

A great book on real-world "hacking", introducing four workaround strategies - piggyback, loophole, roundabout, and the next best - supported by numerous examples. It’s all about creatively navigating rules to solve problems and getting things done.

🌟Devops for the Modern Enterprise: Winning Practices to Transform Legacy It Organizations by Mirco Hering

An excellent, concise introduction to Agile IT, covering both the technical foundations and the human elements critical to success.

🌟The Death Of Expertise: The Campaign Against Established Knowledge and Why it Matters by Thomas M. Nichols

A fascinating look at a world where disagreeing with someone is considered an insult and all opinions - no matter how far-fetched - are deemed equally valid. The author examines what’s wrong with our education system, why having vast amounts of information hasn’t made us any smarter, and how rising competition is affecting journalism. There’s also a critical discussion of how people confuse democracy with the notion that all opinions hold the same weight. While experts aren’t always right, the book delves into the potential implications of dismissing expertise altogether.

Artificial Intelligence

🌟AI 2041: Ten Visions for Our Future by Kai-Fu Lee, Chen Qiufan

This collection features ten AI-themed sci-fi stories by Chen Qiufan, each paired with commentary and insights from AI expert Kai-Fu Lee. It’s an excellent blend of fiction and factual analysis, perfect for sci-fi enthusiasts interested in learning about AI. The stories touch on a wide range of AI concepts - from natural language processing and deepfakes to VR/AR/MR, smart cities, autonomous weapons, and the displacement of jobs by AI. Particularly commendable is the attention to security, privacy, and ethics, offering a balanced and thought-provoking perspective.

🌟Scary Smart: The Future of Artificial Intelligence and How You Can Save Our World by Mo Gawdat

This book explores both the positive and negative potential outcomes of AI and proposes ways to amplify the benefits. The author posits that three events are inevitable: (1) AI will emerge, unstoppable; (2) it will surpass human intelligence; and (3) mistakes will be made. Because there’s no reliable way to contain a superintelligence, the author argues we must teach it to care for humanity as if we were its parents. 

Human Behavior

🌟Never Split the Difference: Negotiating As If Your Life Depended On It by Chris Voss

I've read quite a lot about behavioral  economics, but it's been mostly quite theoretical and academic studies. This book gives excellent advice how to use that knowledge in practice. Interesting cases varying from negotiating apartment rent to negotiating ransom with kidnappers.

🌟The Future of the Mind: The Scientific Quest to Understand, Enhance, and Empower the Mind by Michio Kaku

An eye-opening and highly entertaining book that explores what we know about how the brain works, the studies and experiments undertaken to deepen our understanding, and the intriguing possibilities of re-wiring our minds. It even ventures into sci-fi territory by considering what might happen if we could upload our brains into a computer.

🌟The Unthinkable: Who Survives When Disaster Strikes - and Why by Amanda Ripley

An exploration of human behavior during disasters, this book emphasizes the unpredictability of how people will react - who might freeze, who might act heroically, and how the brain and body can fail in surprising ways (including temporary stress-induced blindness). One key takeaway is that mentally rehearsing worst-case scenarios in advance can be life-saving when crises strike.

🌟The 48 Laws of Power by Robert Greene

Empathy, teamwork, ethical decisions? Nope. How about manipulation, taking credit for work of others and crushing your enemies?  The book is a compelling yet troubling read, presenting 48 laws that flip today's expected  norms on their head, making for a peculiarly refreshing experience. Each law is backed by historical narratives, making it a recommended read for its thought-provoking content, albeit with a caution against using it as a behavioral blueprint.

🌟Humankind: A Hopeful History by Rutger Bregman

You’ve probably heard about Lord of the Flies, the Stanford Prison Experiment, the Bystander Effect, or other studies and stories suggesting that people are inherently selfish, untrustworthy, and even dangerous - leading us to treat one another with defensiveness and suspicion. This author, however, dismantles those assumptions, arguing that most people are actually quite decent at heart. According to the book, “homo puppy” (humankind’s cooperative, playful nature) has triumphed in large part because we’re wired to work together. It’s an excellent read that prompts reflection on your own biases and behaviors - a worthwhile exercise, even if you don’t fully agree with the author’s conclusions.

The end - with a bonus

That's it - I hope you found it useful. All of my previous recommendations remain valid, so feel free to check those out as well. 

As the saying goes - “All work and no play makes Jack a dull boy” (famously quoted in The Shining) - I’d also like to include two bonus suggestions for those who enjoy science fiction: The Three-Body Problem series by Liu Cixin and the Bobiverse series by Dennis E. Taylor are excellent.

Happy reading - and now that you know my preferences, I’d love to hear your reading suggestions!



Dec 7, 2023

Ready or not - EU legislation will challenge you

 



A tsunami of EU legislation

A tsunami of EU legislation is on the horizon for organizations. How are you preparing for it?

  1. Bring it on -  we're actively preparing
  2. We're aware, but believe there's ample time
  3. What regulation? 

If you chose (1), congratulations are in order. You likely have a vigilant compliance team keeping the organization up-to-date with coming new requirements. 

For those who chose (2), I strongly recommend an immediate evaluation. New regulation is a 'grey rhino' risk - large, apparent, and approaching, yet often disregarded as distant and non-urgent. 

This post specifically addresses response (3). I'll provide a high-level overview of what's coming to motivate you to start preparing. Read on to understand the implications of these categories and how they might affect your organization.

EU legislation schedule

Below, you'll find a snapshot of new or impending EU legislation. I've categorized them into three groups: Security & Safety, Data, Digitalization & Privacy, and Artificial Intelligence. While I've grouped these based on each law's primary focus, it's important to note that most of these laws intersect across several areas.



(regulation map updated 12th Jan 2024)

Take note of the distinction between regulations and directives. A regulation is a binding legislative act that must be implemented in full across the EU. In contrast, a directive is a legislative act that establishes a goal for EU countries to achieve. However, the method of achieving these goals is left to the individual countries, which can craft their own laws accordingly.

Below, you'll find a very brief explanation of each regulation and directive mentioned in the above image. For comprehensive details, visit the EUR-Lex site, which is a database of European Union law available in all EU languages.

Selected legislation in brief

NIS2: EU directive 2022/2555 on measures for a high common level of cybersecurity across the Union 

The Network and Information Systems 2 Directive is an update to NIS1 focused on improving cybersecurity. It introduces tougher rules to tackle emerging cyber threats and digital challenges. The directive now covers additional sectors, demanding that organizations report major incidents and follow stricter risk management and reporting guidelines. This aims to boost cyber defenses, especially in key sectors.

CER: EU directive 2022/2557 on the resilience of critical entities 

The Critical Entities Resilience Directive is designed to strengthen the protection of vital infrastructure in the EU against threats like natural disasters, terrorism, internal threats, and sabotage. It requires EU countries to pinpoint crucial organizations that deliver key services vital for society and the economy.

DORA: EU regulation 2022/2554 on digital operational resilience for the financial sector

The Digital Operational Resilience Act focuses on increasing the digital robustness of the EU's financial sector. It establishes a detailed set of rules for handling digital risks in financial markets. DORA applies to many financial entities like banks, payment services, investment firms, and insurance companies. Its purpose is to make sure these organizations can manage and endure different types of digital threats effectively.

eEvidence: EU regulation 2018/0108 on electronic evidence in criminal proceedings

The eEvidence Regulation simplifies how law enforcement agencies in the EU can access electronic evidence for criminal probes. It introduces new tools for quicker and more efficient access to digital data (like emails and texts) across borders. The regulation also sets out clear guidelines for member states on managing data access requests, especially those involving private companies, during investigations.

RED: EU delegated regulation 2022/30 to increase cybersecurity and privacy for wireless devices

The Radio Equipment Directive provides a regulatory framework for the marketing of radio equipment. It aims to create a single market for radio equipment by setting essential requirements for safety, health, electromagnetic compatibility, and efficient radio spectrum use. RED was revised to include Article 3.3, which now addresses the security of radio interfaces. This revision mandates that all radio equipment placed on the EU market must comply with this updated regulation to achieve CE marking, signifying conformity with health, safety, and environmental protection standards​.

GPSR: EU regulation 2021/0170 on general product safety

The General Product Safety Regulation is set to become a significant component of the EU's product safety legal framework, replacing the current General Product Safety Directive and the Food Imitating Product Directive. Its goal is to improve the internal market's functioning while ensuring a high level of health, safety, and consumer protection. This is achieved by setting fundamental safety standards for consumer products sold in the EU market.

CRA: EU regulation on horizontal cybersecurity requirements for products with digital elements

The Cyber Resilience Act focuses on establishing uniform cybersecurity standards for products with digital components. Its main objective is to safeguard cyber and data security throughout the entire lifespan of such products. This applies to any product designed for use with a data connection, either physical or logical, to a device or network. The Act mandates that manufacturers must offer security support and software updates to fix known vulnerabilities. 

CSA: EU regulation to  strengthen preparedness to cybersecurity threats and incidents

The EU Cyber Solidarity Act is designed to improve the EU's preparedness, detection, and response to cybersecurity incidents. This Act aims to create a "European cybersecurity shield" and comes with a significant budget to strengthen EU-wide efforts against cybersecurity threats. The Act focuses on improving threat detection, increasing awareness of cybersecurity situations, and strengthening the preparedness and response strategies for major and large-scale cyber threats and attacks. 

Data Act: EU regulation on harmonized rules on fair access to and use of data

The Data Act is aimed at creating harmonized rules for fair access to and use of data generated within the EU. Its primary objectives are to promote fairness, enhance competition, and encourage data-driven innovation. This Act includes regulations on data sharing, access, reuse, and portability. It also encompasses guidelines for data sharing agreements, provisions for accessing data during public emergencies, and obligations for transitioning between cloud services.

DMA: EU regulation 2022/1925 on contestable and fair markets in the digital sector 

The Digital Markets Act Regulation is designed to promote a fairer and more contestable digital economy. The DMA targets the regulation of activities of companies, particularly large platforms, in the digital sector, introducing specific prohibitions and obligations for these 'big tech' companies to ensure competition and fairness. This regulation is part of the EU's effort to address and manage the dominance of large tech companies and to create a level playing field in the digital market.

DGA: EU regulation 2022/868 on European data governance

The Data Governance Act sets out regulations for the re-use of public sector data. It aims to create a unified market in the EU for data mediation services and the processing of data for altruistic reasons. The DGA's main focus is on easing the sharing of data within the EU and across various sectors.

DSA: EU regulation 2022/2065 on a single market for digital services 

Digital Services Act updates the Electronic Commerce Directive 2000 and focuses on illegal content, transparent advertising, and disinformation. It establishes a framework for regulating digital services within the EU, amending previous directives to address the current digital market. It outlines the responsibilities of digital services, particularly those acting as intermediaries, to connect consumers with goods, services, and content, aiming to create a safer and more accountable online environment.

CSRD: EU directive 2022/2464 regarding corporate sustainability reporting

The Corporate Sustainability Reporting Directive (CSRD) requires more companies to provide detailed reports on their environmental and social impact. It aims to make businesses more transparent about how they affect society and the environment.

ePrivacy: EU regulation on privacy and electronic communications

The ePrivacy Regulation will succeed the ePrivacy Directive of 2002. This regulation is an extension of the GDPR and is specifically focused on cookies and other tracking technologies, with a promise of even more stringent protection of internet user privacy. Aimed at companies in the digital economy, the ePrivacy imposes additional requirements related to the processing of personal data.

AI Act: EU regulation on laying down harmonised rules on artificial intelligence

The EU Artificial Intelligence Act is designed to strengthen rules concerning data quality, transparency, human oversight, and accountability. It also addresses ethical questions and implementation challenges across various sectors. The AI Act would classify AI systems according to their risk level and establish specific development and usage requirements for these systems. 

AI Liability: EU directive on civil liability rules to artificial intelligence

The AI Liability Directive seeks to establish uniform rules for non-contractual civil liability regarding damage caused by AI systems. It introduces a 'presumption of causality' that would make it easier for victims to prove damages inflicted by AI-powered software or products. This directive would enable victims to hold providers, developers, or users of AI technology accountable for harm to health, property, or fundamental rights, such as privacy. The directive aligns with the AI Act. 

Be compliant out there!

As you can see, there's a substantial amount to review. It's crucial to assess your current situation and plan for compliance accordingly. The recurring themes in these regulations appear to be thorough risk management, the responsibility of leadership, and significant sanctions in the event of non-compliance.

I strongly recommend that you begin assessing the impact of these upcoming regulations on your organization.

Dec 28, 2022

The quest for the truth in cybersecurity data



(Photo by Chris Liverani on Unsplash)

As the saying goes, "if you torture the data long enough, it will confess." Interpreting cybersecurity statistics can be challenging, especially those that receive media attention. It is important to approach these statistics with a critical eye and consider the context in which they were collected, the potential biases of the data sources, and other factors that could impact their accuracy and relevance.

For example, it was recently reported that ransomware attacks in Finland have increased significantly in 2022. However, upon further investigation, I found out that while there were 3 ransomware attacks on essential service providers in 2021, there were 11 such attacks in 2022. This is a whopping 300% increase!

To understand if the increase is really significant, let's consider the total number of essential service providers in Finland, which is estimated to be between 1000 and 2000. Using the conservative number 1000, this means that in 2021, ransomware attacks targeted 0.3% of essential service providers, while in 2022, the number rose to 1.1%. Alternatively, the increase could be described as a 0.8 percentage point increase.

Four times more ransomware attacks this year, or 300% increase, or 0.8 percentage points increase or just saying that there were 8 attacks more than last year? Your pick depending on what message you want to deliver.

Analysing the trustworthiness of cybersecurity statistics or survey results can be hard work. My tips for a quick and dirty analysis are:
  • Do you believe that the source of the information is objective?
  • Is the tone of the message matter-of-fact rather than attention-seeking?
  • Is the method of data collection and analysis described?
  • Do the conclusions make sense based on your own view of the situation?
I would be much more inclined to believe the results if I would get Yes to all four questions. 

If you want to dig deeper, you may consider the following factors:
  • The context in which the statistics were collected and reported
  • Any potential biases of the data sources
  • Whether the study covers only successful breaches or also blocked attacks
  • The possibility of cherry-picking or random variation in the results
  • The source and size of the data and how it was sampled, as well as any explanation of uncertainty levels
  • The clarity of terminology, such as the use of terms like "breach," "incident," and "hack"
  • The understanding that correlation does not equal causation
  • The consideration of absolute risk, not just relative risk
  • The presence of other studies that support the results
Going back to that ransomware attack increase example. It's one thing to understand what has happened and another thing to understand why. My example just showed that conclusions can be delivered differently depending on an agenda. Reason for ransomware attacks increase could be for example Russian-Ukrainian war related activity, criminal activity, increase in zero-day vulnerabilities, changes to organizations infrastructure because of remote work or combination of many. The why would be important to know in order to understand risk and decide about possible actions.

Surveys and statistics can be useful in understanding the state of cybersecurity and trends in the field. However, it is important to approach these statistics with caution and consider all of the factors that could impact their accuracy and relevance.

With cybersecurity statistics and surveys, it also applies, that if the results sound too good or too bad - they are probably not true. 


May 23, 2021

Predicting cybersecurity events in Finland


(Photo by Dollar Gill on Unsplash)

During March-April 2021 I've been speaking/chairing at a few cybersecurity events and courses. Since it's been all remote because of the pandemic, I've spiced up the events by online surveys. One survey was about predicting likelihood of certain cybersecurity events happening in Finland. It was interesting to see and discuss the results.

I asked participants to estimate the likelihood of the following events happening before the end of 2022.
  1. Finland enforces legislation to require ISO 27001 certifications from the largest essential service providers
  2. Cyber security accountability / leadership will be centralized in Finnish government (e.g. Cyber Ministry)
  3. Finland will be among the top three countries in the Estonian national cyber security index (2020: #1 Greece, #2 Czech, #3 Estonia - #8 Finland)
  4. A Finnish cyber security company (Revenue >10M€) will be acquired by a foreign company.
  5. A major cloud provider will have an interruption of service lasting 8 or more hours impacting many Finnish organization
  6. A Finnish company (other than Vastaamo) with over 100 employees will go out of business due to a cyber-attack
  7. Cyber-attack causes physical damage which leads to death(s)
  8. A Finnish company gets over 1 million EUR GDPR sanction
All 86 participants were experienced security and/or cybersecurity professionals and answers were given anonymously. 

Cybersecurity predictions results

Finnish cyber security company acquired (4), major cloud service interruption (5) and cyber-attack forcing a company out of business (6) were predicted to be most probable. All three events average likelihood were between 60-70%. The least probable event was a cyber-attack causing deathly physical damage. Average and medium results didn't have big difference.

Interestingly almost all events got estimates from 0% to 100%. Only exceptions were Estonian national cyber security index result (3) which top estimate was 90% likelihood and cyber-attack forcing a company out of business (6) which lowest estimate was 10% likelihood. In short, security and cybersecurity estimates were all over the scale. Standard deviation was large - between 25 and 30. 

This was not intended to be any serious study, but a fun survey of how Finnish security and cybersecurity professionals see the probability of some events in almost two years timeframe. 
 

Apr 12, 2020

COVID-19: Making sense of cybersecurity for home workers

(Photo by Ali Yahya on Unsplash)

Countermeasures against COVID-19 infection has changed the way we work and communicate. Everyone who can work from home are advised or forced to do so. Some are experienced remote workers, but many are at the first time working out-of-office weeks or months in a row.

Many (if not all) cybersecurity companies and authorities are publishing remote working security guidelines. Despite good advice and intentions, in my opinion many are missing the point. At least from the large organization's point of view where employees use company managed devices.

The advice I've seen typically has a mix of several target audiences: IT departments, remote workers in general, remote workers stuck at home and even individuals using personal devices. It may be difficult to figure out what's home worker's responsibility.

Here´s what is special for remote working currently:
  • People are working at home - not at cafes, libraries or other public spaces.
  • The whole family is working at home, kids included.
  • Everyone is worried on bigger issues than cybersecurity: health of their family, job security, money, etc.
  • Everyone is extra stressed because of social distancing and lockdowns. 
The following advice is given from typical large organization's point of view, where remote workers use company provided devices and software, and have professional IT team supporting them.

Do NOT worry:
  • Security of your company provided devices. It´s the responsibility of the IT team to make sure that devices, network connections and access to applications are secure: encrypted hard disk, VPN access to company network, strong authentication, anti-malware software in place and all software up-to-date.
  • How the security of your home network may affect remote work. It´s good to change default password of your home wifi access point and check the device configuration in order to protect you home. However, your company devices should be protected regardless of your home network. They are configured to allow access also in random cafes after all.
  • Absolute confidentiality of work related matters. In reality there may be several family members at home working around the same kitchen table. Do your best and try to find a private corner for the most confidential discussions, but don't stress too much about it.
What you CAN do to protect work related confidential information and company network:
  • Follow the company guidelines. Each company may have some special requirements depending on the work and selected tools. Make sure to follow internal communications and act accordingly.
  • Use and protect the company device. Keep your company device to yourself and lock the screen when not in use. Sorry, but you need to get personal devices for your own and your family's leisure use. 
  • Keep the data at company network or device. Use only your company provided device and file/document storage to store data. If you must handle printed material, make sure to destroy them later in accordance with your company guidelines.
  • Keep your passwords to yourself. Nobody - and I mean nobody - should ask and get your password. Not even your trusted IT team or service desk. Do not reuse company password in services which are not work related.
  • Think (extra carefully) before you click. Use your common sense when receiving surprising or suspicious emails or other messages. Do not open attachments or links without checking their authenticity. Criminals are busy trying to profit from fear and uncertainty. Phishing and scams are now more common. 
  • Ask for help. If you are unsure what to do, see something suspicious or accidentally click a phishing link, contact your organization's service desk or IT support. Better safe than sorry.
In these extraordinary times organizations should take as much cybersecurity burden from employees as we can. Following the simple advice above the users are the strong link of security while the other strong link must be your IT which takes care of technical protection.

Note, that if the use of employees' own devices is allowed to access company network and confidential data, then a totally new can of worms is opened. Don't want to go there now. Good luck.

Take care and stay safe!


Jul 19, 2019

Book recommendations for CSOs and CISOs


bookshelf
I read 20-30 books per year. I've been keeping track of my readings on my web-site since started experimenting with HTML (needed some reason to update the content regularly). Lately I've been using Goodreads as well. I read to keep myself up-to-date professionally. It means topics from security, risk management, business and leadership. When I need something more relaxing, I turn to scifi, fantasy or crime mostly.

I went through my list and decided to give some book recommendations for Chief Security Officers and Chief Information Security Officers. We all need more to read right? First tried to keep the list short with 10 books, but quickly realized that it's too hard and settled with 15 recommendations.

So, here you are, 15 great books I recommend.

🌟Security Engineering by Ross Anderson 

Probably the best security book ever and should be found on every security professional's bookshelf. The book covers security topics broadly including not only technical security, but also topics like psychology and economics. First and second editions are available online and Anderson is just writing third edition.

🌟Thinking, Fast and Slow by Daniel Kahneman 

Nowadays it's more and more understood that good security solutions must take human behavior into account. Unusable security guidelines are disregarded and bad solutions are circumvented. Kahneman's book explains thoroughly human biases and behavior. It's also helps CSO/CISO to understand what may affect his own decision making and how better influence others. If Kahneman's feel a bit too heavy, try first Dan Ariely's Predictably IrrationalThe Upside of Irrationality and The (Honest) Truth About Dishonesty.

🌟Unsecurity by Evan Francen 

After working couple of decades as a security professional one starts to wonder why same problems exists year after year and general information security level seems to decrease instead of getting better. Increasing complexity of digital world is of course one reason, but security industry and profession has also failed in many areas. Francen's book nicely summarize what's wrong with information security.


We are choking to information, data, statistics and infographics. All this can presented - accidentally or on purpose - in a misleading way. Skills to navigate through all figures, tables and graphics are critical as well as an ability to evaluate their trustworthiness. As Levitin says in his book: There are not two sides to a story when one side is a lie.

🌟Geekonomics, The Real Cost of Insecure Software by David Rice 

Software is running the world and code is law as Lawrence Lessig has famously said. We tend to concentrate too much on devices and networks when protecting digital world. We must focus more on software, applications, code. Rice's book is about software industry and reasons why we have so much bad software. It's also good to check Gary McGraw's classic Software Security: Building Security In.


Excellent and rare inside look how the Board of large, global company works. Useful for CSOs and CISOs who are working with executive teams and boards - interesting to everyone. Siilasmaa coined the term paranoid optimism, which means combining vigilance and a healthy dose of realistic fear with a positive, forward-looking outlook expressed via scenario-based thinking.

🌟Team of Teams: New Rules of Engagement for a Complex World by Stanley McChrystal

Organizations want to be agile and move from hierarchical organizations to networked models where employees and teams get more autonomy. Modern communication tools, network and data enables that, but not without leader's deliberate efforts to allow and nurture decision making at all levels. McChrystal writes about his experiences how traditional, hierarchical  military organization was changed to a network of empowered individuals and teams.

🌟Factfulness: Ten Reasons We're Wrong About The World - And Why Things Are Better Than You Think by Hans Rosling

Rosling explains why our world view is mostly wrong and how to avoid common misconceptions. When thinking of poverty, education, population growth, income, life-expectancy, etc. the world is much better place than generally thought. Even highly educated people, business leaders and decision makers often don't understand what the world is like today - neither did I.


A startup can be defined as a human institution designed to create a new product or service under conditions of extreme uncertainty. A startup can also be a part of large organization, not only a new, small company.  The book explains Build → Measure  Learn loop and how to minimize the total time through this feedback loop. Today almost everything imaginable is possible to build (with enough time, money and other resources), so the question today is not can it be done, but should it be done. There's also a bestseller This Is Lean by Modig & Γ…hlstrΓΆm,

🌟Homo Deus: A Brief History of Tomorrow by Yuval Noah Harari

Homo Deus is amazing look at the human history and predictions of the future of human evolution with algorithms, robotics and artificial intelligence. I would also recommend reading Harari's Sapiens to put current state of world in perspective and 21 Lessons for the 21st Century for today's challenges.

Most of Schneier's books are good. For here I picked Outliers, since it gives a thorough look at trust and what makes us trustworthy. The role of trust is increasingly important in our digital environment - organizations, products, applications and services cant success without employees, customers and citizens to trust them. Interesting claim in the book was that some level of rule-breaking is needed in the society in order to innovation and social progress become impossible. Schneier's latest Click Here to Kill Everybody is good read about Internet of Things challenges.

🌟How to Measure Anything in Cybersecurity Risk by  Douglas W. Hubbard  and Richard Seiersen

It's a common argument that security can not be measured properly, hence we have lots of qualitative metrics instead of quantitative ones. Hubbard argues that anything can be measured, also security and cybersecurity. Good reading to understand how statistical models can help measuring the security status with raw data. The Failure of Risk Management is another Hubbard's book worth reading.



So much is written about US NSA surveillance methods that it's refreshing to have a look what Russia is doing. The book documents the history of Russia's surveillance system development. It starts from the pre-Internet era, explains how the SORM system was developed, describes Russia's attempts to change Internet governance via ITU and ICANN, documents the Sochi Olympics surveillance efforts and didn't forget the story of Snowden getting an asylum at Russia


If you have been in business long enough, you may remember CarderPlanet and Russian Business Network. It's useful to read a bit about criminals and law officers trying to catch them. Especially because Menn tells the story from the perspective of the good guys.

🌟The Adventures of an IT Leader by Robert D. Austin, Shannon O'Donnell and Richard L. Nolan

This is fictional story where a business manager is appointed as a new CIO of the company. Since he doesn't have any ICT background he needs to learn how everything works and how he can keep track of ICT functionality and business requirements. Useful from security management point of view to read how a new CIO gradually finds ways for better communications and metrics. Also, the biggest challenge the fresh CIO faces is a serious security incident.

Many great books left out so you better check my site or Goodreads where I have more books with ratings. My ratings are of course timebound. How I've rated the book depended on my knowledge, skills and interest at the time of reading. Goodreads also creates nice yearly statistics.

Happy reading and let me know what I should read (or nowadays also listen) next.

Feb 3, 2018

What, me hacker?



















I spent week 4/2018 on EC-Council Certified Ethical Hacker (CEH) training. After over 13 years in CSO position looking corporate security mostly from governance and risk management perspective, this may not be the most obvious choice. Let me explain.

Last spring Finnish Information Security Association awarded me as the CISO of the year 2017. As if the honor wouldn't been enough, I also got a free place on CEH course (sponsored by Arrow ECS). I postponed the opportunity nine months, but decided to attend the training now before the offer expires. Course normal price is 3,500€ after all.

I haven't been on full week's training in ages. I think the previous time was in 2011 when I attended SABSA security architecture training. By the way, got my first security certification, CISSP, 20 years ago. I attended the first ever CISSP training held in Finland 1998.

It certainly was interesting (and tiresome) week. Huge amount of information and loads of hacking/auditing/pentesting tools not to mention hands-on labs. The courseware had about 1800 slides and 20 hours' worth of labs. The instructor presented maybe one third of the slides with quick pace pointing out the most important stuff. The material was from 2015 and therefore a bit outdated, but the instructor filled in the gaps. Expectation was, that after nine-to-five day in classroom, students would continue studying and doing labs at home in the evening. I spent hour or two every evening to browse through the days material and did some labs.

The following topics were covered:

  • Introduction to Ethical Hacking
  • Footprinting and Reconnaissance
  • Scanning Networks
  • Enumeration
  • System Hacking
  • Malware Threats
  • Sniffing
  • Social Engineering
  • Session Hijacking
  • Hacking Webservers
  • Hacking Web Applications
  • SQL Injection
  • Hacking Wireless Networks
  • Hacking Mobile Platforms
  • Evading IDS, Firewalls, and Honeypots
  • Cryptography











  • I was surprised how well I still remembered network protocols, attack methods and basic auditing tools. It's after all over 15 years from my consultancy days and more than 20 when I knew Unix security inside out. Of course, I follow information security threats, trends and technology closely all the time. Security expertise requires lifelong learning.


    I expected that the course would have emphasized ethical questions more. It's CEH, not CH, right? Ethics of hacking was discussed briefly a few times, but not so thoroughly as one would have expected. CEH code of ethics can be found here.

    At the end of the week we had an opportunity to take certification test. There's 4 hours to answer 125 multiple-choice questions and have to get 75% correct in order to pass. Here's a site where you can test your skills, if you will. Whatever certification test you are taking, I've found that practice tests are very useful way to prepare yourself. You need to set your brain in to the right mode and understand how you are expected to answer.

    I finished the certification test in 1,5 hours and passed with score 93,6%. So, I'm Certified Ethical Hacker now :-)

    Don't worry. I'm not going after bug bounties. I'm leaving that to those with real hands-on skills. Had a fun week, though, and have even more respect for whitehat hackers who help organizations via bug bounty programs or responsible vulnerability disclosure.

    However, next time I'm hiring security auditor, CEH certificate is not enough to impress me :-)


    Dec 30, 2017

    Information security state of the play





    It's that time of the year again when information security predictions start pouring in. Many, if not most of them are pretty uninteresting since the world doesn't magically change with the new year. Predictions are also all over the place depending on who made the predictions and what they are selling.

    My favorite is Information Security Forum's Threat Report, which is updated yearly and looks two years ahead. The report is mostly intended for business leaders and information security leaders (CSO, CRO, CISO - depending of your organization). I especially like that it's created via studying available research, interviewing experts and running several member workshops to discuss changes seen and expected in member organizations. The Executive Summary is available for download, the whole 50+ report is for members only. (Full disclosure: I'm a member of the ISF Executive Board).

    Instead of making my own predictions - as if my 2010 predictions would need an update - I'm presenting how I see the current status of information security. By the way, in my vocabulary information security covers IT security, cyber security and digital security, if you fancy those terms.

    User is not the weakest link

    We humans are not rational decision makers who analyze pros and cons thoroughly. We mostly try to manage through the day (and IT challenges) with minimum effort, have lots of biases and are clever enough to go around (security) obstacles. It seems that often IT systems and applications are not built for humans. Since the artificial intelligence is not here quite yet, we still need to consider users as part of the solution and build people-friendly systems. Hence, I like the design thinking and service design approach - if only information security would be considered on those workshops.

    Regular information security awareness training is required in order to promote secure behavior and build good security culture. We don't want our users to be clueless either. Also, I would recommend security practitioners to study behavioral economics and psychology. 

    Most of the information security is a byproduct of good IT governance

    When you know and manage your IT assets properly and have basic information security tools and processes in place, you are in a pretty good shape already. Have a good architecture, know your assets, make proper installations, have rigorous change management process, make (and test) backups, patch your systems and keep user accounts up-to-date. You certainly need some security tools and processes: antivirus, firewalls, log collection and analysis for starters.

    On top of that there are no end of additional security tools and services which you may consider based on your threat and risk estimation. You have to know what you are protecting and against whom, right?

    Most organizations have still lots to do with these basics. It's hard to protect something you don't know.

    Information security is too important to be left just to information security experts

    You may have started wondering where information security specialists are needed? Yes, all the basics shouldn't need any infosec experts. Architects, sysadmins and network admins worth their salt can manage most of it. Firewalls and VPNs are just network components, antivirus and log management something any sysadmin can handle.

    Information security specialists could be hired to promote security, evaluate risks, help with trickiest cases, tackle the challenges with new technology and keep the management aware of the information security status. Remember, however, that it's not the CISO or information security experts who secure the organization. Information security is part of everyone's daily work.

    Many organizations have hired just one information security expert, call him CISO, and expect him/her to understand all of information security. That's impossible. Information security covers everything from cryptography to secure architecture to enterprise risk management. Can't expect one poor person to handle all of it. Think about categories: Manage - design - implement - evaluate. Different roles and skills are needed.

    Evaluate your service providers information security promise and capabilities

    More and more of ICT are acquired from different service or cloud providers. From information security perspective this is usually a good thing, since good security is a lifeblood for most service providers. You need to verify, though. Ask service providers to prove they capabilities. Security certifications, audit reports and documented security promise of the service is a good start for evaluation.

    Don't forget to have information security in the contracts as well. I recommend having your own security contract template ready and start negotiations with it. Be flexible, though. Usually it's better to allow service provider to follow its own standards and processes - just check that those are good enough for you. It's difficult to change the service provider processes - exceptions tend to be forgotten.

    Go ahead with new technology, but understand your risks

    There's a lot of technology innovation going on and of course business wants to follow trying out innovative ways to make use of new, often immature technology. However, the sad truth is that the innovation of information security tools and products has been and is falling behind.




    Business may and should innovate, but at the same time we need to understand the possibility of increasing risk. New business models and plans making use of new technology, cloud and apps just have to consider information security risks. Crash test dummies has a very limited use in organizations.

    An old infosec dog is learning new tricks - constantly

    I regularly see articles and posts demanding that information security experts need to stop being naysayers. I wonder where they have found those old-school security guys who deny everything? In my (fairly wide) circles all my colleagues have been business-oriented and forward-looking for years. Maybe it's time for some business people to see the light and be more open-minded for security-enhancing suggestions? Information security is about enabling business and managing risk.

    Business buzzwords like agile, cloud, devops, experimentation, big data, design thinking, API-driven business and machine learning mean that there's no rest for information security experts either. We information security professionals must adapt on agility, insecurity, risk tolerance, openness, user oriented approach and continuous change.

    In fact information security practitioners should embrace new technology and trends. Think how to use them for better security instead of trying to delay the inevitable.

    It's software, stupid

    Everything is running on software. Everything from critical infrastructure to cars and mobile phones. I'm amazed how weak the understanding of secure software development still is. It seems that many organizations are still relying on external audits after their software has been developed. Fixing bugs in production is 100x more expensive than in planning phase. This is age-old software development truth, but apparently not too much cared about. If you don't think security requirements already when sketching your software, you may burn your fingers, sooner or later.

    Don't forget to demand secure software from your vendors also - ask for evidence.

    CISO on the board - not just yet


    There is more and more noise about bringing information security expertise on the company board or management team. Most of the noise is coming from the infosec people, of course. In my experience there are very few - shall I say forerunner organizations - which has raised information security leader on the top management.

    In my mind being on the board is not mandatory in order to success as a information security leader. But it's mandatory to have regular dialogue with top management and business. Being at most one hop away from the CEO in the organizational structure is ideal.



    Organizational hierarchy is not the key issue. It's critical that the top management shows its commitment to information security and that information security leader has regular access to the top management. I believe that information security leader's most important job is to keep the board and management team aware of information security status, risks and risk mitigation possibilities.

    Good luck with 2018 and beyond

    Current environment is very complex with new technology, massive amounts of software and global connections. It's difficult - if not impossible - to understand and therefore also extremely hard to protect. Information security standards help and regulation forces us to implement the security baseline. Let's make information security great again with good IT management, risk assessments, user focus, vendor evaluations, secure software development, constant learning and real commitment from the top management.

    Jan 6, 2016

    Threat Cloud 2016

    It's time to check again what a word cloud would reveal from different security predictions without reading the actual predictions. There are tons of (cyber) security predictions available from different organizations. I'm using the predictions from the same organizations I used for 2014 and 2015 word clouds in order to see the changes better: FireEye, Fortinet, Information Security Forum, Kaspersky, Microsoft, Sophos, Symantec, Trend Micro, WatchGuard and Websense,

    The first word cloud is from the combined text of all predictions.



    What's the conclusion from that? Mostly attacks against devices and data? Doesn't seem to differ much from last year. One change at least is that word mobile is not visible as it was last year, but Apple is.

    The second was created using only the headlines from each prediction paper.



    Not much change. It's a bit more clear that predictions included ransomware.

    Some companies use "funny" headlines for their predictions (even Star Wars theme) which didn't make sense without reading the full text. Some predictions were even positive (!), but since most were about threats I didn't bother to make any difference between them.

    So, in summary 2016 is predicted to bring us attacks against devices (IoT), more malware to take victim's data as hostage and Apple is expected to be a target.

    Of course word cloud brings out only the common themes and lots of interesting threats are missed unless you actually read the papers. Problem is that I find many predictions biased and threats are all over the place depending who is making the predictions (and what solutions they are selling). I really would like to see a study analyzing different prediction papers and connections between threats and companies predicting them. Maybe even a study analyzing past predictions and their accuracy.

    My favorite threat predictions come from the ISF, which are gathered from it's members and analyzed by the ISF team. Must say that I'm biased here, since I'm sitting on the ISF Executive Board. Favored ISF predictions even before that, though.

    ISF Threat Horizon 2017 executive summary is available for download, the full paper is is free for members only. Here're the headlines for your convenience.



    I advice you  not to focus too much on threats and media headlines. Threat info just add some spice to your daily security work.