Showing posts with label ISF. Show all posts
Showing posts with label ISF. Show all posts

Jan 6, 2016

Threat Cloud 2016

It's time to check again what a word cloud would reveal from different security predictions without reading the actual predictions. There are tons of (cyber) security predictions available from different organizations. I'm using the predictions from the same organizations I used for 2014 and 2015 word clouds in order to see the changes better: FireEye, Fortinet, Information Security Forum, Kaspersky, Microsoft, Sophos, Symantec, Trend Micro, WatchGuard and Websense,

The first word cloud is from the combined text of all predictions.



What's the conclusion from that? Mostly attacks against devices and data? Doesn't seem to differ much from last year. One change at least is that word mobile is not visible as it was last year, but Apple is.

The second was created using only the headlines from each prediction paper.



Not much change. It's a bit more clear that predictions included ransomware.

Some companies use "funny" headlines for their predictions (even Star Wars theme) which didn't make sense without reading the full text. Some predictions were even positive (!), but since most were about threats I didn't bother to make any difference between them.

So, in summary 2016 is predicted to bring us attacks against devices (IoT), more malware to take victim's data as hostage and Apple is expected to be a target.

Of course word cloud brings out only the common themes and lots of interesting threats are missed unless you actually read the papers. Problem is that I find many predictions biased and threats are all over the place depending who is making the predictions (and what solutions they are selling). I really would like to see a study analyzing different prediction papers and connections between threats and companies predicting them. Maybe even a study analyzing past predictions and their accuracy.

My favorite threat predictions come from the ISF, which are gathered from it's members and analyzed by the ISF team. Must say that I'm biased here, since I'm sitting on the ISF Executive Board. Favored ISF predictions even before that, though.

ISF Threat Horizon 2017 executive summary is available for download, the full paper is is free for members only. Here're the headlines for your convenience.



I advice you  not to focus too much on threats and media headlines. Threat info just add some spice to your daily security work.

Jan 11, 2015

Concensus of 2015 security predictions

I find many security predictions unusable, uninteresting and often just pure marketing material or even misleading. Just for the fun of it, I still like to see the big picture of latest predictions. As in previous years I got security predictions from ten different companies and instead of reading them all, I just put all predictions together and created a word-cloud from combined text.

I used predictions from the same companies as last year: Fortinet, Information Security Forum, Kaspersky, Microsoft, Sophos, Symantec, WatchGuard, Websense, Trend Micro and FireEye.

Here's the "concensus" word-cloud:

2015 security predictions















Compare that to last year's predictions:

2014 security predictions
















Couple of observations. The big ones - as in previous year - are data, devices, mobile and malware. There's a bit more focus on information now, not just data. In 2015 cyber is back. It was big on 2013 list, but less so last year. On the other hand, privacy have disappeared. It wasn't big before, but at least it was there.

My summary last year was: Expect data-stealing malware attacks against all devices.

Since no groundbreaking threats are seen, my summary this year is: Expect attacks against Internet-facing (cyber) systems. The attackers are more likely to go after valuable information, not just raw data.

This year I also tried another approach. I created a separate word-cloud from only the topics of security threats found from the predictions:

2015 security threats - topics only















Interestingly, from that picture, Internet of Things pops out. However, since the vendors often like to play with words when thinking of topic names and headlines, I find the full-text word cloud more interesting. Can't deny the security threat of IoT, though.

Feel free to make you own interpretations or - god forbid - read the individual predictions. You may also check this good summary of the 15 security predictions for 2015.

To me personally, the most useful security predictions document is Information Security Forum's (ISF) Threat Horizon report. It's freely available only to members and for others it's a bit expensive. However, a year old The Executive Summary of Threat Horizon 2016 is downloadable for free (requires registration). A new Threat Horizon 2017 should be out for members pretty soon now.

The Executive Summary of Threat Horizon 2016 shows this threat development according to global member organizations of the ISF:














Check also my word-clouds from previous years. Word-cloud of 2014 security predictions and Mother of all 2013 security predictions.