2021 cybersecurity predictions: The intergalactic battle begins
A version of this article appeared in Dark Reading. It has been updated and syndicated here.Cybersecurity predictions are something of a tradition in our industry, as we look towards the year to come and see what may lie ahead in a field that can have more changes than Lady Gaga at the GRAMMYs. Sometimes we’re right, and sometimes a once-in-a-generation pandemic comes along and challenges us in ways we could never have expected.
Let’s not focus on that, however. This is about 2021, and while we will take some of 2020’s adaptations with us, there is a whole lot in store for the future of cybersecurity, and the most interesting things aren’t even happening here on earth.
That’s right, we’re predicting that 2021 is the year we take a new kind of space race into the mainstream: keeping our galaxy safe from cyber threats.
NASA already employs cybersecurity people that work outside earth’s realm (and it’s weirder than you think)
It’s likely no shock that NASA employs many security experts, as well as engineers with a deep focus on fortifying NASA’s software and operations to withstand the most powerful of cyberattacks.
… what might surprise is the fact that they employ a senior satellite engineer -- 28-year-old Kenneth F. Harris II -- to protect and defend satellites in orbit. Far from an automated process, Kenneth is a real-life Superman who stands (metaphorically) between NASA’s satellites and the numerous deliberate attempts to physically attack them, in addition to helping mitigate the risk of potential cyber threats that could come from anywhere on Earth.
What’s at stake if a nation’s satellites are damaged? A deliberate collision, or bad actor managing to leverage a software vulnerability could potentially disrupt GPS networks, weather warnings and forecasts, and the communications systems we take for granted every day.
It’s a threat that might literally be out of our orbit, but we’re confident that security people focused on space asset protection will be a niche area that experiences big demand going forward.
Governments are already assembling space forces… and they’re going to need security experts
In December 2019, the United States Government introduced a new branch of its military operations, this time, in space. America’s Space Force is a technology-centric department with a focus on preserving space as a “global commons”, according to US Secretary of Defense, Mark Esper: “It's important not just to our security, but to our commerce, our way of life, our understanding of the planet, weather, you name it. So it's very important that we — we now treat it that way and make sure that we're prepared to defend ourselves and preserve space,” he said.
In October 2020, it was reported that as many as 130 cyber experts from the US Air Force would be redeployed to the Space Force ranks, with Maj. Gen. Kimberly Crider, Space Force Chief Technology and Innovation Officer, identifying space as “the next front of the cyber conflict”.
While the USA may have been one of the frontrunners in assembling a Space Force, at a time where it might seem a little over the top and more like a comic book plot than a serious department, space cyber warfare is already a risk area, and it goes without saying that most countries will eventually follow suit with a program of their own.
Tesla has already put a car in space, while computers drive on our roads
In 2018, Elon Musk sent a self-driving Tesla vehicle into space. By October 2020, the car piloted by a spacesuit-clad mannequin nicknamed ‘Starman’ has clocked 1.3 billion miles, and has now cruised past Mars.
While this situation isn’t a cybersecurity issue, it is curious that we’ve got a car doing an infinite intergalactic version of a NASCAR race, while our roads here on Earth are slowly, but surely, being populated with cars driven by computers. Anything powered by software carries at least some element of cyber risk, and automotive software has been compromised before, with the outcome signaling the potential for catastrophe. Tesla has already been tested several times by security researchers, with one exploit resulting in the autonomous, involuntary acceleration of the vehicle from 35 to 85 miles per hour. Yikes. Still, Tesla’s comprehensive security programs set a high standard for the industry in terms of testing and compliance.
Autonomous vehicles are the future of our personal travel, but all eyes will be on the software security aspect of their build as more players than the likes of Tesla enter the market, and it’s likely we will see this market explode from 2021.
So much advancement, and we’re still forgetting the human factor
Despite the inherent risks of brand new tech, we are certainly in a very exciting time. Most industries are innovating with cutting-edge use of software, and we can’t wait to see what’s next.
However, it seems that the cybersecurity industry as a whole is a little stuck. Everywhere we turn, the most common advice for organizations that want to build more secure software is to keep buying tools, automated scanners, and other solutions that are essentially leaving it all up to robots to solve our security problems. Huge data breaches every other day prove that this approach needs a serious upgrade, and that we are not utilizing all the options at our disposal.Gartner’s Hype Cycle for Application Security 2020 report details a wide array of the latest security solutions, in fact, it’s hard to think of a technology solution they haven’t outlined as a viable option for secure application development. It seems comprehensive, and it seems like good advice. Sadly, though, there isn’t one mention of the human factor at play in secure application development, nor the immensely beneficial role that trained, security-aware developers can play in reducing common software vulnerabilities. It is by far the most economical solution for recurring software bugs, and one which would free up tools and security experts to work out the more complex problems.
Perhaps we need to end with a question, rather than a prediction. Will 2021 be the year that industry analysts keep humans front-of-mind in the race to ramp up secure software development?
We’re predicting that 2021 is the year we take a new kind of space race into the mainstream: keeping our galaxy safe from cyber threats.
Chief Executive Officer, Chairman, and Co-Founder
Secure Code Warrior is here for your organization to help you secure code across the entire software development lifecycle and create a culture in which cybersecurity is top of mind. Whether you’re an AppSec Manager, Developer, CISO, or anyone involved in security, we can help your organization reduce risks associated with insecure code.
Book a demoChief Executive Officer, Chairman, and Co-Founder
Pieter Danhieux is a globally recognized security expert, with over 12 years experience as a security consultant and 8 years as a Principal Instructor for SANS teaching offensive techniques on how to target and assess organizations, systems and individuals for security weaknesses. In 2016, he was recognized as one of the Coolest Tech people in Australia (Business Insider), awarded Cyber Security Professional of the Year (AISA - Australian Information Security Association) and holds GSE, CISSP, GCIH, GCFA, GSEC, GPEN, GWAPT, GCIA certifications.
A version of this article appeared in Dark Reading. It has been updated and syndicated here.Cybersecurity predictions are something of a tradition in our industry, as we look towards the year to come and see what may lie ahead in a field that can have more changes than Lady Gaga at the GRAMMYs. Sometimes we’re right, and sometimes a once-in-a-generation pandemic comes along and challenges us in ways we could never have expected.
Let’s not focus on that, however. This is about 2021, and while we will take some of 2020’s adaptations with us, there is a whole lot in store for the future of cybersecurity, and the most interesting things aren’t even happening here on earth.
That’s right, we’re predicting that 2021 is the year we take a new kind of space race into the mainstream: keeping our galaxy safe from cyber threats.
NASA already employs cybersecurity people that work outside earth’s realm (and it’s weirder than you think)
It’s likely no shock that NASA employs many security experts, as well as engineers with a deep focus on fortifying NASA’s software and operations to withstand the most powerful of cyberattacks.
… what might surprise is the fact that they employ a senior satellite engineer -- 28-year-old Kenneth F. Harris II -- to protect and defend satellites in orbit. Far from an automated process, Kenneth is a real-life Superman who stands (metaphorically) between NASA’s satellites and the numerous deliberate attempts to physically attack them, in addition to helping mitigate the risk of potential cyber threats that could come from anywhere on Earth.
What’s at stake if a nation’s satellites are damaged? A deliberate collision, or bad actor managing to leverage a software vulnerability could potentially disrupt GPS networks, weather warnings and forecasts, and the communications systems we take for granted every day.
It’s a threat that might literally be out of our orbit, but we’re confident that security people focused on space asset protection will be a niche area that experiences big demand going forward.
Governments are already assembling space forces… and they’re going to need security experts
In December 2019, the United States Government introduced a new branch of its military operations, this time, in space. America’s Space Force is a technology-centric department with a focus on preserving space as a “global commons”, according to US Secretary of Defense, Mark Esper: “It's important not just to our security, but to our commerce, our way of life, our understanding of the planet, weather, you name it. So it's very important that we — we now treat it that way and make sure that we're prepared to defend ourselves and preserve space,” he said.
In October 2020, it was reported that as many as 130 cyber experts from the US Air Force would be redeployed to the Space Force ranks, with Maj. Gen. Kimberly Crider, Space Force Chief Technology and Innovation Officer, identifying space as “the next front of the cyber conflict”.
While the USA may have been one of the frontrunners in assembling a Space Force, at a time where it might seem a little over the top and more like a comic book plot than a serious department, space cyber warfare is already a risk area, and it goes without saying that most countries will eventually follow suit with a program of their own.
Tesla has already put a car in space, while computers drive on our roads
In 2018, Elon Musk sent a self-driving Tesla vehicle into space. By October 2020, the car piloted by a spacesuit-clad mannequin nicknamed ‘Starman’ has clocked 1.3 billion miles, and has now cruised past Mars.
While this situation isn’t a cybersecurity issue, it is curious that we’ve got a car doing an infinite intergalactic version of a NASCAR race, while our roads here on Earth are slowly, but surely, being populated with cars driven by computers. Anything powered by software carries at least some element of cyber risk, and automotive software has been compromised before, with the outcome signaling the potential for catastrophe. Tesla has already been tested several times by security researchers, with one exploit resulting in the autonomous, involuntary acceleration of the vehicle from 35 to 85 miles per hour. Yikes. Still, Tesla’s comprehensive security programs set a high standard for the industry in terms of testing and compliance.
Autonomous vehicles are the future of our personal travel, but all eyes will be on the software security aspect of their build as more players than the likes of Tesla enter the market, and it’s likely we will see this market explode from 2021.
So much advancement, and we’re still forgetting the human factor
Despite the inherent risks of brand new tech, we are certainly in a very exciting time. Most industries are innovating with cutting-edge use of software, and we can’t wait to see what’s next.
However, it seems that the cybersecurity industry as a whole is a little stuck. Everywhere we turn, the most common advice for organizations that want to build more secure software is to keep buying tools, automated scanners, and other solutions that are essentially leaving it all up to robots to solve our security problems. Huge data breaches every other day prove that this approach needs a serious upgrade, and that we are not utilizing all the options at our disposal.Gartner’s Hype Cycle for Application Security 2020 report details a wide array of the latest security solutions, in fact, it’s hard to think of a technology solution they haven’t outlined as a viable option for secure application development. It seems comprehensive, and it seems like good advice. Sadly, though, there isn’t one mention of the human factor at play in secure application development, nor the immensely beneficial role that trained, security-aware developers can play in reducing common software vulnerabilities. It is by far the most economical solution for recurring software bugs, and one which would free up tools and security experts to work out the more complex problems.
Perhaps we need to end with a question, rather than a prediction. Will 2021 be the year that industry analysts keep humans front-of-mind in the race to ramp up secure software development?
A version of this article appeared in Dark Reading. It has been updated and syndicated here.Cybersecurity predictions are something of a tradition in our industry, as we look towards the year to come and see what may lie ahead in a field that can have more changes than Lady Gaga at the GRAMMYs. Sometimes we’re right, and sometimes a once-in-a-generation pandemic comes along and challenges us in ways we could never have expected.
Let’s not focus on that, however. This is about 2021, and while we will take some of 2020’s adaptations with us, there is a whole lot in store for the future of cybersecurity, and the most interesting things aren’t even happening here on earth.
That’s right, we’re predicting that 2021 is the year we take a new kind of space race into the mainstream: keeping our galaxy safe from cyber threats.
NASA already employs cybersecurity people that work outside earth’s realm (and it’s weirder than you think)
It’s likely no shock that NASA employs many security experts, as well as engineers with a deep focus on fortifying NASA’s software and operations to withstand the most powerful of cyberattacks.
… what might surprise is the fact that they employ a senior satellite engineer -- 28-year-old Kenneth F. Harris II -- to protect and defend satellites in orbit. Far from an automated process, Kenneth is a real-life Superman who stands (metaphorically) between NASA’s satellites and the numerous deliberate attempts to physically attack them, in addition to helping mitigate the risk of potential cyber threats that could come from anywhere on Earth.
What’s at stake if a nation’s satellites are damaged? A deliberate collision, or bad actor managing to leverage a software vulnerability could potentially disrupt GPS networks, weather warnings and forecasts, and the communications systems we take for granted every day.
It’s a threat that might literally be out of our orbit, but we’re confident that security people focused on space asset protection will be a niche area that experiences big demand going forward.
Governments are already assembling space forces… and they’re going to need security experts
In December 2019, the United States Government introduced a new branch of its military operations, this time, in space. America’s Space Force is a technology-centric department with a focus on preserving space as a “global commons”, according to US Secretary of Defense, Mark Esper: “It's important not just to our security, but to our commerce, our way of life, our understanding of the planet, weather, you name it. So it's very important that we — we now treat it that way and make sure that we're prepared to defend ourselves and preserve space,” he said.
In October 2020, it was reported that as many as 130 cyber experts from the US Air Force would be redeployed to the Space Force ranks, with Maj. Gen. Kimberly Crider, Space Force Chief Technology and Innovation Officer, identifying space as “the next front of the cyber conflict”.
While the USA may have been one of the frontrunners in assembling a Space Force, at a time where it might seem a little over the top and more like a comic book plot than a serious department, space cyber warfare is already a risk area, and it goes without saying that most countries will eventually follow suit with a program of their own.
Tesla has already put a car in space, while computers drive on our roads
In 2018, Elon Musk sent a self-driving Tesla vehicle into space. By October 2020, the car piloted by a spacesuit-clad mannequin nicknamed ‘Starman’ has clocked 1.3 billion miles, and has now cruised past Mars.
While this situation isn’t a cybersecurity issue, it is curious that we’ve got a car doing an infinite intergalactic version of a NASCAR race, while our roads here on Earth are slowly, but surely, being populated with cars driven by computers. Anything powered by software carries at least some element of cyber risk, and automotive software has been compromised before, with the outcome signaling the potential for catastrophe. Tesla has already been tested several times by security researchers, with one exploit resulting in the autonomous, involuntary acceleration of the vehicle from 35 to 85 miles per hour. Yikes. Still, Tesla’s comprehensive security programs set a high standard for the industry in terms of testing and compliance.
Autonomous vehicles are the future of our personal travel, but all eyes will be on the software security aspect of their build as more players than the likes of Tesla enter the market, and it’s likely we will see this market explode from 2021.
So much advancement, and we’re still forgetting the human factor
Despite the inherent risks of brand new tech, we are certainly in a very exciting time. Most industries are innovating with cutting-edge use of software, and we can’t wait to see what’s next.
However, it seems that the cybersecurity industry as a whole is a little stuck. Everywhere we turn, the most common advice for organizations that want to build more secure software is to keep buying tools, automated scanners, and other solutions that are essentially leaving it all up to robots to solve our security problems. Huge data breaches every other day prove that this approach needs a serious upgrade, and that we are not utilizing all the options at our disposal.Gartner’s Hype Cycle for Application Security 2020 report details a wide array of the latest security solutions, in fact, it’s hard to think of a technology solution they haven’t outlined as a viable option for secure application development. It seems comprehensive, and it seems like good advice. Sadly, though, there isn’t one mention of the human factor at play in secure application development, nor the immensely beneficial role that trained, security-aware developers can play in reducing common software vulnerabilities. It is by far the most economical solution for recurring software bugs, and one which would free up tools and security experts to work out the more complex problems.
Perhaps we need to end with a question, rather than a prediction. Will 2021 be the year that industry analysts keep humans front-of-mind in the race to ramp up secure software development?
Click on the link below and download the PDF of this resource.
Secure Code Warrior is here for your organization to help you secure code across the entire software development lifecycle and create a culture in which cybersecurity is top of mind. Whether you’re an AppSec Manager, Developer, CISO, or anyone involved in security, we can help your organization reduce risks associated with insecure code.
View reportBook a demoChief Executive Officer, Chairman, and Co-Founder
Pieter Danhieux is a globally recognized security expert, with over 12 years experience as a security consultant and 8 years as a Principal Instructor for SANS teaching offensive techniques on how to target and assess organizations, systems and individuals for security weaknesses. In 2016, he was recognized as one of the Coolest Tech people in Australia (Business Insider), awarded Cyber Security Professional of the Year (AISA - Australian Information Security Association) and holds GSE, CISSP, GCIH, GCFA, GSEC, GPEN, GWAPT, GCIA certifications.
A version of this article appeared in Dark Reading. It has been updated and syndicated here.Cybersecurity predictions are something of a tradition in our industry, as we look towards the year to come and see what may lie ahead in a field that can have more changes than Lady Gaga at the GRAMMYs. Sometimes we’re right, and sometimes a once-in-a-generation pandemic comes along and challenges us in ways we could never have expected.
Let’s not focus on that, however. This is about 2021, and while we will take some of 2020’s adaptations with us, there is a whole lot in store for the future of cybersecurity, and the most interesting things aren’t even happening here on earth.
That’s right, we’re predicting that 2021 is the year we take a new kind of space race into the mainstream: keeping our galaxy safe from cyber threats.
NASA already employs cybersecurity people that work outside earth’s realm (and it’s weirder than you think)
It’s likely no shock that NASA employs many security experts, as well as engineers with a deep focus on fortifying NASA’s software and operations to withstand the most powerful of cyberattacks.
… what might surprise is the fact that they employ a senior satellite engineer -- 28-year-old Kenneth F. Harris II -- to protect and defend satellites in orbit. Far from an automated process, Kenneth is a real-life Superman who stands (metaphorically) between NASA’s satellites and the numerous deliberate attempts to physically attack them, in addition to helping mitigate the risk of potential cyber threats that could come from anywhere on Earth.
What’s at stake if a nation’s satellites are damaged? A deliberate collision, or bad actor managing to leverage a software vulnerability could potentially disrupt GPS networks, weather warnings and forecasts, and the communications systems we take for granted every day.
It’s a threat that might literally be out of our orbit, but we’re confident that security people focused on space asset protection will be a niche area that experiences big demand going forward.
Governments are already assembling space forces… and they’re going to need security experts
In December 2019, the United States Government introduced a new branch of its military operations, this time, in space. America’s Space Force is a technology-centric department with a focus on preserving space as a “global commons”, according to US Secretary of Defense, Mark Esper: “It's important not just to our security, but to our commerce, our way of life, our understanding of the planet, weather, you name it. So it's very important that we — we now treat it that way and make sure that we're prepared to defend ourselves and preserve space,” he said.
In October 2020, it was reported that as many as 130 cyber experts from the US Air Force would be redeployed to the Space Force ranks, with Maj. Gen. Kimberly Crider, Space Force Chief Technology and Innovation Officer, identifying space as “the next front of the cyber conflict”.
While the USA may have been one of the frontrunners in assembling a Space Force, at a time where it might seem a little over the top and more like a comic book plot than a serious department, space cyber warfare is already a risk area, and it goes without saying that most countries will eventually follow suit with a program of their own.
Tesla has already put a car in space, while computers drive on our roads
In 2018, Elon Musk sent a self-driving Tesla vehicle into space. By October 2020, the car piloted by a spacesuit-clad mannequin nicknamed ‘Starman’ has clocked 1.3 billion miles, and has now cruised past Mars.
While this situation isn’t a cybersecurity issue, it is curious that we’ve got a car doing an infinite intergalactic version of a NASCAR race, while our roads here on Earth are slowly, but surely, being populated with cars driven by computers. Anything powered by software carries at least some element of cyber risk, and automotive software has been compromised before, with the outcome signaling the potential for catastrophe. Tesla has already been tested several times by security researchers, with one exploit resulting in the autonomous, involuntary acceleration of the vehicle from 35 to 85 miles per hour. Yikes. Still, Tesla’s comprehensive security programs set a high standard for the industry in terms of testing and compliance.
Autonomous vehicles are the future of our personal travel, but all eyes will be on the software security aspect of their build as more players than the likes of Tesla enter the market, and it’s likely we will see this market explode from 2021.
So much advancement, and we’re still forgetting the human factor
Despite the inherent risks of brand new tech, we are certainly in a very exciting time. Most industries are innovating with cutting-edge use of software, and we can’t wait to see what’s next.
However, it seems that the cybersecurity industry as a whole is a little stuck. Everywhere we turn, the most common advice for organizations that want to build more secure software is to keep buying tools, automated scanners, and other solutions that are essentially leaving it all up to robots to solve our security problems. Huge data breaches every other day prove that this approach needs a serious upgrade, and that we are not utilizing all the options at our disposal.Gartner’s Hype Cycle for Application Security 2020 report details a wide array of the latest security solutions, in fact, it’s hard to think of a technology solution they haven’t outlined as a viable option for secure application development. It seems comprehensive, and it seems like good advice. Sadly, though, there isn’t one mention of the human factor at play in secure application development, nor the immensely beneficial role that trained, security-aware developers can play in reducing common software vulnerabilities. It is by far the most economical solution for recurring software bugs, and one which would free up tools and security experts to work out the more complex problems.
Perhaps we need to end with a question, rather than a prediction. Will 2021 be the year that industry analysts keep humans front-of-mind in the race to ramp up secure software development?
Table of contents
Chief Executive Officer, Chairman, and Co-Founder
Secure Code Warrior is here for your organization to help you secure code across the entire software development lifecycle and create a culture in which cybersecurity is top of mind. Whether you’re an AppSec Manager, Developer, CISO, or anyone involved in security, we can help your organization reduce risks associated with insecure code.
Book a demoDownloadResources to get you started
Benchmarking Security Skills: Streamlining Secure-by-Design in the Enterprise
The Secure-by-Design movement is the future of secure software development. Learn about the key elements companies need to keep in mind when they think about a Secure-by-Design initiative.
DigitalOcean Decreases Security Debt with Secure Code Warrior
DigitalOcean's use of Secure Code Warrior training has significantly reduced security debt, allowing teams to focus more on innovation and productivity. The improved security has strengthened their product quality and competitive edge. Looking ahead, the SCW Trust Score will help them further enhance security practices and continue driving innovation.
Resources to get you started
Trust Score Reveals the Value of Secure-by-Design Upskilling Initiatives
Our research has shown that secure code training works. Trust Score, using an algorithm drawing on more than 20 million learning data points from work by more than 250,000 learners at over 600 organizations, reveals its effectiveness in driving down vulnerabilities and how to make the initiative even more effective.
Reactive Versus Preventive Security: Prevention Is a Better Cure
The idea of bringing preventive security to legacy code and systems at the same time as newer applications can seem daunting, but a Secure-by-Design approach, enforced by upskilling developers, can apply security best practices to those systems. It’s the best chance many organizations have of improving their security postures.
The Benefits of Benchmarking Security Skills for Developers
The growing focus on secure code and Secure-by-Design principles requires developers to be trained in cybersecurity from the start of the SDLC, with tools like Secure Code Warrior’s Trust Score helping measure and improve their progress.
Driving Meaningful Success for Enterprise Secure-by-Design Initiatives
Our latest research paper, Benchmarking Security Skills: Streamlining Secure-by-Design in the Enterprise is the result of deep analysis of real Secure-by-Design initiatives at the enterprise level, and deriving best practice approaches based on data-driven findings.