Menu DaniWeb
Log In Sign Up
  • Read
  • Contribute
  • Meet
  1. Forums
  2. Hardware and Software
  3. Information Security
  4. News Stories
  5. News Story

Infosec trends for 2013 (part three)

13 Years Ago Updated 13 Years Ago happygeek 0 Tallied Votes 263 Views Share

Continuing our round up of 2013 IT security vendor predictions, we've got the thoughts of three of the big Infosecurity Europe exhibitors: Palo Alto Networks, SafeNet and Kaspersky Lab.

dweb-infoseceurope Brian Tokuyoshi from Palo Alto Networks predicts that social media, data decryption and virtualised network security will be high on the agenda in the year to come.

"Increasingly, social media platforms and webmail are becoming de facto communication platforms for personal use, bypassing enterprise security products in the process. Encryption makes more of this traffic invisible to existing security controls. In 2013, enterprises need to find ways to make sure Internet personal use policies do not conflict with the policies (or bypass the technologies) needed to protect the enterprise."

"Enterprises need to start thinking about decryption not just for data loss, but to check for policy violations and malicious content. CISOs will need to work together closely with HR and legal teams to respect personal privacy while maintaining corporate security, and to make sure that the cure isn’t worse than the ailment."

"When one virtual machine talks to another on the same host, the traffic may never cross the network. As a result, virtualisation network traffic may bypass all the physical network security protections in place for intrusion prevention, malware detection and policy enforcement. In 2013, organisations will be looking closely at their virtualisation strategy to see if it is in line with the network security best practices."

Meanwhile, Jason Hart from SafeNet, thinks education and mobility will be key:

"2012 suggested that despite everything we still don’t seem to be learning the lessons of data protection. Too much of the damage and frequency of data breaches and hacktivist attacks can be attributed to flawed approaches to how critical data is secured. This can’t continue and the channel can play a pivotal role in turning around data breach prevention strategies that are failing. Quite simply 2013 should be the year that more organisations embrace the concept of the secure breach. This means having processes and technologies in place that kill the data and make it useless if it falls into the wrong hands. In essence, security is embedded in every piece of data that’s valuable to you."

"Mobility is going to continue to become a greater part of how people access and use their business data and applications. This is opening up a new range of security threats arising from the use of personal devices on otherwise protected systems. To take a simple example, if someone needs to charge their phone using a USB connector, this could introduce a key logger onto a computer within the corporate development systems. The requirement of many large organisations to extend their authentication infrastructure presents the channel with a challenge as well as a huge opportunity in 2013. Multi-factor authentication is well understood as a key part of a data protection strategy but its wide scale proliferation has been held back by high management overheads and operational pressures."

Which just leaves us with what David Emm, the senior security researcher at Kaspersky Lab, has to say about 2013:

"The most notable predictions for the next year include the continued rise of targeted attacks, cyber-espionage and nation-state cyber-attacks, the evolving role of hacktivism, the development of controversial ‘legal’ surveillance tools and the increase in cybercriminal attacks targeting cloud-based services. Targeted attacks on businesses have only become a prevalent threat within the last two years. Kaspersky Lab expects the amount of targeted attacks, with the purpose of cyber-espionage, to continue in 2013 and beyond, becoming the most significant threat for businesses. Another trend that will likely impact companies and governments is the continued rise of ‘hacktivism’ and politically-motivated cyber-attacks. State-sponsored cyber warfare is also expected to continue in 2013. In fact, during 2012, Kaspersky Lab discovered three new major malicious programs that were used in cyber warfare operations: Flame, Gauss and miniFlame. Experts at Kaspersky Lab expect more countries to develop their own cyber programs for the purposes of cyber-espionage and cyber-sabotage. These attacks will affect not only government institutions, but also businesses and critical infrastructure facilities."

cybersecurity encryption storage:data-protection
About the Author
Member Avatar for happygeek
happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

A freelance technology journalist for 30 years, I have been a Contributing Editor at PC Pro (one of the best selling computer magazines in the UK) for most of them. As well as currently contributing to Forbes.com, The Times and Sunday Times via Raconteur…

Dani AI

Generated 8 Months Ago

A short expert addendum to 's vendor roundup: several practical themes keep recurring — limited visibility into encrypted channels, intra-host/virtualization traffic bypassing network controls, data-centric defenses that assume compromise, BYOD/USB risks, and targeted (often state-orchestrated) attacks. These are not just forecasts; they are shifts in where defenders need to apply controls.

Visibility and lawful privacy: full TLS interception carries legal, privacy and operational costs. Prefer policy-driven, selective decryption for high-risk traffic only, with documented HR/legal signoff and audit logging. Where decryption is unacceptable, rely on endpoint DLP/EDR, metadata and behavioral analytics (DNS, SNI/handshake patterns, anomalous flow volumes) to detect abuse without reading payloads.

Host, cloud and mobile controls: virtual environments require host-based sensors, virtual-tap/mirror solutions or hypervisor-aware inspection, plus microsegmentation to control east-west traffic. Data protection should be data-centric: client-side or tokenization-style encryption, customer-held keys, strong key rotation and tested key-recovery procedures so data remains useless if exfiltrated. For mobility and the simple-but-real USB threat, enforce MDM/MAM, require MFA, forbid untrusted peripherals and use charge-only adapters where appropriate.

Clarifying terms for : cyber-espionage is covert data theft; cyber-sabotage aims to disrupt or destroy systems or data. Attacks often mix both. For 's lock-in concern, plan for portability: insist on exportable formats, customer key control, clear contractual exit clauses and periodic export tests. Across all this, prioritize by mapping crown-jewel assets, run tabletop exercises, reduce attacker dwell time with detection controls, and validate recovery with immutable backups and segmented restore paths.

Member Avatar for Seten
Seten -1 Junior Poster
13 Years Ago

All the companies will try to lure people to upload all their private data to their cloud. Because they know that people will not migrate to other company/device/vendor, as it will be difficult for them to adjust to the new environment. Then as next phase they will change the agreements from "we can give statistic data to 3rd party" to "we own all your data". Basically Android user will not be able to move so easy to WP/apple, as there will not be any easy way to do it. See activesync fight. As social(any) networks will try to be as mass as possible, they will try to make user_access easy for you and also for 3rd rogue party. Of course, they will secure everything with cheap payed people. In the end it will be useless against skilled 3rd rogue party.

Edited 13 Years Ago by Seten because: grammar
Member Avatar for Member #949455
Member #949455
13 Years Ago

"The most notable predictions for the next year include the continued rise of targeted attacks, cyber-espionage and nation-state cyber-attacks, the evolving role of hacktivism, the development of controversial ‘legal’ surveillance tools and the increase in cybercriminal attacks targeting cloud-based services.

cyber-espionage or cyber-sabotage, I don't read that often or recognized those phrases.

But cyber-armegeddon, yes I do fear that the most.

Reply to this topic
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.

Sign Up — It's Free!
Recommended Topics
  • Member Avatar Dating disaster: eHarmony confirms passwords exposed by LinkedIn hacker 6
  • Member Avatar Data Baby: the secret life of your smartphone 2
  • Member Avatar Safe mode will not start at all 9
  • Member Avatar Education sector trails badly in mobile device security stakes 0
  • Member Avatar Browser being redirected 12
  • Member Avatar Ripples still expanding from NoSQL Database host MongoHQ hack 1
  • Member Avatar Quicktime Buffer Overrun Error 7
  • Member Avatar Data Privacy Day sucks elephants through a straw, and here's why... 3
  • Member Avatar Spam 2
  • Member Avatar 2013: Year of the Salami Attack! 5
  • Member Avatar I thought I would let you guess what was wrong 1
  • Member Avatar Breaking: Acronis blames 'technical issue' for customer data leak 1
  • Member Avatar Google redirect rootkit? 3
  • Member Avatar TechRadar closes forums following data breach 1
  • Member Avatar GoDaddy Target of Major Attack by Hacker 2
  • Member Avatar DataTraveler Vault Privacy USB 3.0 with hardware encryption and ESET AV 0
  • Member Avatar Windows XP Internet Issue 3
  • Member Avatar Wildcard searching of encrypted data in a MySQL database? 1
  • Member Avatar Vundo and maybe other issues 3
  • Member Avatar Trust in digital certificates cannot be taken at face value 1
Not what you need?

Reach out to all the awesome people in our information security community by starting your own topic. We equally welcome both specific questions as well as open-ended discussions.

Start New Topic
Topics Feed
Reply to this Topic
Edit Preview

Share Post

Insert Code Block

  • Forums
  • Forum Index
  • Hardware & Software
  • Programming
  • Digital Media
  • Community Center
  • Recent
  • Recommended Topics
  • Newest Topics
  • Latest Topics
  • Latest Posts
  • Latest Comments
  • Top Tags
  • Tools
  • Writing
    • Start New Topic
    • Markdown Syntax
    • Newsletter Archive
  • Social
    • Top Members
    • Meet People
  • APIs
    • Connect API
    • Forum API Docs
    • Topics Feed
  • Resources
  • Community Rules
  • DaniWeb Premium
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Legal
  • Terms of Service
  • Privacy Policy
© 2026 DaniWeb® LLC
© 2026 DaniWeb® LLC
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Terms of Service
  • Privacy Policy