What Cybersecurity Trends Were Emerging in 2021?

1.4K views
•
February 8, 2021
by
RSAC Cybersecurity
YouTube video player
What Cybersecurity Trends Were Emerging in 2021?

TL;DR

Cybersecurity resilience emerged as a central priority, especially for remote work, software supply chains, and trusted communications. Other prominent trends included software bills of materials, zero trust, SASE, information manipulation, deepfake-enabled fraud, ransomware, and practical threat-information sharing among enterprises, vendors, governments, and industry groups.

Transcript

Hi, this is Britta Glade. I'm Senior Director of Content and Curation for RSA Conference, and I'm here today with Dr. Hugh Thompson, who's Program Chair for RSA Conference. Good to see you, Hugh. Hey, Britta. Great to see you, and thanks everybody for, for tuning in. Really appreciate it. Indeed. We have completed the agenda build process for RSA C... Read More

Key Insights

  • Resilience is a central cybersecurity responsibility because security organizations help enterprises continue operating when working conditions change. The submissions showed security teams protecting business continuity while also adapting their own practices during a challenging period.
  • Remote-work security involves both technology and people because employees now operate in environments that enterprises cannot fully control. The volume and variety of submissions justified an entire conference track devoted to securing the remote workforce.
  • Software supply-chain security was already a mature conference theme before SolarWinds because related submissions arrived before that incident. The agenda included software bills of materials, software integrity, product security, application security, equipment origins, implants, and defensive planning.
  • Zero trust and SASE address situations where trusted people or entities must connect across infrastructure that cannot automatically be trusted. Their growth among session proposals reflected wider concern about intermediaries, equipment provenance, and confidence in complex technology supply chains.
  • Information manipulation is an enterprise-security risk because attackers can influence decisions through convincing stories and fabricated communications. The problem extends beyond political debate and directly affects security, compliance, governance, and the reliability of data used by organizations.
  • Deepfake technology can strengthen business compromise attacks by imitating a chief executive through generated audio or video. Fraud attempts may arrive through phone calls, messaging platforms, or social media, so defending only the email channel is insufficient.
  • Ransomware and business email compromise remained persistent themes while attackers rapidly adapted their stories to current events. The discussion noted that fraudulent appeals had shifted from familiar inheritance scams toward COVID vaccination narratives, demonstrating adversaries' responsiveness.
  • Information sharing has become more practical through common languages, protocols, and schemas for exchanging indicators of compromise and threat data. Sessions focused on using ISACs, contributing information, coordinating among security vendors, and incorporating submissions from governments beyond the United States.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why was resilience a major cybersecurity trend in 2021?

Resilience became a major theme because security organizations were responsible for helping enterprises continue operating while businesses changed how work was performed. Conference submissions showed that cybersecurity teams had adapted under difficult conditions and supported broader organizational continuity. The theme also connected multiple subjects, including remote-work protection, human behavior, software supply chains, trusted connections, and incident planning.

Q: How should organizations approach remote-work security?

Organizations should treat remote-work security as both a technical and human challenge. Employees may work in environments that the enterprise cannot directly control, so traditional assumptions about managed offices no longer cover the full risk. The conference submissions therefore examined more than setup practices, combining technology-oriented defenses with attention to the human implications of protecting a distributed workforce.

Q: Why did software supply-chain security receive increased attention?

Software supply-chain security received increased attention because confidence in software, products, applications, and equipment had become a sustained concern. Many related proposals were submitted before the SolarWinds incident, showing that the topic had been developing for years. After that incident, software bills of materials, equipment provenance, implants, planning, and actionable defensive strategies became even more relevant to the conference agenda.

Q: What is a software bill of materials in the conference discussion?

A software bill of materials was presented as an important topic within the broader discussion of software integrity and supply-chain security. The transcript does not provide a formal definition, but it connects the subject with understanding software origins, building confidence in products, assessing supply-chain risk, and responding to incidents such as SolarWinds. It had been tracked thematically for some time.

Q: How do zero trust and SASE relate to supply-chain risk?

Zero trust and SASE were associated with the need to connect trusted individuals or entities when the systems between them might not deserve automatic trust. Their prominence reflected concerns about equipment origins, software integrity, and confidence in intermediary infrastructure. The proposed sessions treated these approaches as part of a broader response to supply-chain uncertainty and the challenge of establishing trustworthy communications.

Q: How can deepfakes change business compromise attacks?

Deepfakes can make business compromise attacks more persuasive by generating audio or video that appears to come from a chief executive or another trusted person. A fraudulent request may therefore arrive through a phone call, messaging service, or social platform instead of email. Enterprises must consider communication provenance and protect decision-making across multiple channels, particularly for urgent financial requests.

Q: Why is information manipulation a cybersecurity issue?

Information manipulation is a cybersecurity issue because attackers can alter how employees think and act by presenting convincing false communications. It affects practical enterprise responsibilities such as security, compliance, and governance, not only public or political debate. Defenders must address data provenance and recognize that manipulated content can support fraud through email, telephone calls, messaging, social media, generated audio, or generated video.

Q: How has cybersecurity information sharing become more practical?

Cybersecurity information sharing has become more practical through common languages, protocols, and schemas that support the exchange of indicators of compromise and threat data. Rather than merely agreeing that organizations should cooperate, sessions focused on obtaining intelligence from industry peers, using and contributing to ISACs, enabling security vendors to share with one another, and incorporating information supplied by governments from multiple countries.

Summary & Key Takeaways

  • Resilience connected many of the proposed RSA Conference topics because security teams had helped businesses change how work was performed during challenging conditions. Remote-work security received an entire track, with sessions addressing both technical controls and the human consequences of protecting employees operating in environments that enterprises could not directly control.

  • Software supply-chain integrity had attracted substantial attention even before the SolarWinds incident. Proposed sessions covered software bills of materials, equipment provenance, product security, application security, implants, zero trust, and SASE. The conference planned actionable guidance and hands-on labs focused on understanding incidents, strengthening planning, and applying defensive strategies.

  • Information manipulation was becoming both a societal concern and an immediate enterprise-security problem. Deepfakes could expand business email compromise beyond email into telephone calls, messaging, and social media. Meanwhile, information-sharing sessions had evolved toward practical use of common languages, protocols, schemas, industry organizations, vendor collaboration, and government participation.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚