Panel
Cyber Resilience: New Line of Defense for Business
Milken InstituteJames Kaplan, Catherine Allen, Jonathan Kaltwasser, Tim Rains, Ray Rothrock, Andrew Rubin
- Cyber attacks are projected to increase in frequency and visibility, with threats evolving from intellectual property theft to disruption and eventual destruction that could cause companies to cease operations overnight.
- Critical infrastructures, including the electric grid, face persistent risks of cyber warfare and nation-state attacks, potentially undermining confidence in financial systems and causing significant economic impact or anarchy.
- Attackers are expected to operate with heightened speed and agility, shifting from hours and days to seconds and minutes, which will outpace current defense capabilities and allow them to overtake defenders in rate of change.
- Despite increased sophistication, compromises will continue to rely on four primary methods: weak passwords, misconfigured systems, unpatched vulnerabilities, and social engineering.
- The attack surface is forecast to grow exponentially and parabolically, driven by 90% of the world's data being created in the last two years, rendering past protection tools insufficient.
- Defense strategies must shift from prevention-only models to "protect, detect, and respond" frameworks, as prevention alone will not stop breaches and losses currently outpace cyber budget investments.
- A friction point is expected to persist between the need for business agility and security requirements, with no cohesive solution currently available to balance these competing priorities.
- Organizations are expected to move workloads to cloud environments like AWS and Azure to remain competitive, though this creates security friction and risks inherent "monocultures" where single vulnerabilities can compromise vast numbers of identical machines.
- Digital infrastructure is anticipated to remain fragile due to a lack of documentation and outdated components, necessitating a systemic rebuild to ensure resilience.
- Security missions will expand to include reducing the attack surface and blast radius alongside traditional safety, acknowledging that breaches are inevitable.
- Cloud environments are expected to serve as a game changer by leveraging scale and machine learning to analyze 14 billion daily authentications for real-time prediction and prevention.
- A crisis is projected where boards cannot continuously double cyber budgets, creating a necessity for better resilience measurements and new standards similar to GAAP or UL stamps to guide investment.
- Concepts such as a "Cyber Underwriter's Laboratory" and cyber insurance models are expected to emerge to objectively certify security practices and tie premiums to attested postures.
- Cybersecurity education is expected to remain deficient, with encryption and security largely absent from most computer science and graduate school curriculums.
- A talent gap is predicted where the number of STEM students in the US, Canada, and UK declines by 2025, necessitating policy adjustments to allow international students from countries like Morocco, Saudi Arabia, and Peru to work in the US.
- Personal security is expected to degrade due to consumer devices collecting voice prints and data, while digital natives may assume all activities are risk-free on mobile devices.
- Trust in the digital economy is identified as a critical future challenge, as people may stop using technology if they do not trust it.
- The US military faces a disconnect between its roles as a user, protector, and exploiter of the internet, which complicates mutual support with industry and prohibits physical interposition to defend commercial networks due to the speed of light.
- Enterprise-grade solutions are expected to evolve beyond perimeter defense to include internal network protection using heuristics and identity-based access controls.
- Microsoft is expected to continue sharing threat intelligence and botnet IP addresses with governments and national CERT teams via public reports.
- The US Navy is expected to continue focusing cybersecurity investments on areas where compromise leads to critical mission failures.
- The cybersecurity industry, comprising 1,400 companies, is expected to see the vast majority continue relying on prevention strategies predicted to fail in the long run.