In 2019, million-record data breaches barely made headlines while ransomware attacks crippled city governments and artificial intelligence (AI) became a tool for both attackers and defenders. We looked back at hundreds of news stories from the past 12 months and found four trends that defined this year in cybersecurity. With an election coming up for the U.S. in 2020, there will no doubt be more fireworks to come next year.

1. Big Breaches Get Bigger

It wasn’t long ago when mega-breaches were big news. Today, such incidents are commonplace.

Risk Based Security reported this summer that 2019 was on track to be the worst year on record for breach activity, with 4.1 billion records compromised in the first six months alone. At least 10 data breaches in 2019 involved the theft or exposure of databases containing at least 100 million records, including several instances where data was left exposed on unsecured servers.

Many cybersecurity experts now say it’s virtually certain that every U.S. citizen has had at least some personal information exposed due to a cyberattack. The silver lining, if there is one, is that the value of individual records has fallen to literally a dime a dozen on the dark web, forcing criminals to look elsewhere for profits.

2. Sometimes, the Enemy Is Us

Cloud platforms can support world-class protection against attacks on their infrastructure — too bad the same can’t always be said for their customers. Misconfigured cloud storage instances, unpatched applications and lax access controls were frequent culprits in cases of unintentional exposure of sensitive data this year.

In many cases, sensitive data was left out in the open for anyone to access, and the guilty parties included some of the largest hyperscale companies. Often, the culprits in these instances weren’t infrastructure-as-a-service (IaaS) providers, but rather customers who didn’t understand the standard shared responsibility model, under which cloud providers secure their infrastructure but customers are responsible for applications and data.

This is apparently news to many customers. A recent survey of IT and security professionals by Enterprise Management Associates (EMA) found that 53 percent believed IaaS providers were accountable for most or all security measures.

The vulnerabilities aren’t limited to misconfigured storage. Palo Alto Networks last summer said it uncovered 34 million vulnerabilities across the major cloud service providers over an 18-month period, and almost all were the result of customer errors. Outdated Apache servers and vulnerable jQuery packages topped the list. The group also estimated that 65 percent of the cloud-related data breaches it tracked in 2019 were the result of misconfiguration — and new strains of malware have already emerged that target misconfigured storage instances specifically.

Cloud providers are working to make their storage configuration settings simpler, but none will take the risk of protecting their customers from themselves.

3. Ransomware Gets Smarter

The volume of ransomware attacks had been declining for nearly two years, but that may be because criminals are focusing more strategically on their targets.

IBM X-Force Incident Response and Intelligence Services (IRIS) reported a 200 percent increase in destructive attacks over the first half of this year compared to 2018, with organized criminals taking over from nation-states as the principal growth drivers. In particular, attackers are going after small businesses and municipalities, which are typically not as well-protected as enterprises.

This year also saw notable attacks on several hospital networks and local governments. In some cases, government services were still offline weeks after attacks were discovered. Some small healthcare providers were forced to shut down completely, and there were reports of new attacks using the TRITON malware, which aims to take physical equipment offline in industrial settings.

4. Cryptocurrencies Struggle for Legitimacy

This should have been cryptocurrencies’ year to shine. Big name financial institutions finally bought into the allure of lower costs and faster transactions based on the blockchain protocol, led by JP Morgan’s launch of JPM Coin for institutional clients and a $63 million investment in the utility settlement coin project by a consortium of big banks.

Unfortunately, cryptocurrency exchanges are only lightly regulated in some countries and are proving vulnerable to compromise. Prominent data breaches in 2019 included the mysterious disappearance of $150 million from one exchange and the third hack of another in just a year’s time. Early in the year, we also learned that the supposedly unbreakable blockchain algorithm had been hacked.

The endorsement by governments and big institutions of so-called “safecoins” will no doubt shore up confidence in branded virtual payments, but the fact remains that anyone can create a cryptocurrency. Until regulations and business models mature, this will continue to be a market for investors with an appetite for adventure.

More from Data Protection

Cybersecurity 101: What is Attack Surface Management?

There were over 4,100 publicly disclosed data breaches in 2022, exposing about 22 billion records. Criminals can use stolen data for identity theft, financial fraud or to launch ransomware attacks. While these threats loom large on the horizon, attack surface management (ASM) seeks to combat them.ASM is a cybersecurity approach that continuously monitors an organization’s IT infrastructure to identify and remediate potential points of attack. Here’s how it can give your organization an edge.Understanding Attack Surface ManagementHere are some key…

Six Ways to Secure Your Organization on a Smaller Budget

My LinkedIn feed has been filled with connections announcing they have been laid off and are looking for work. While it seems that no industry has been spared from uncertainty, my feed suggests tech has been hit the hardest. Headlines confirm my anecdotal experience. Many companies must now protect their systems from more sophisticated threats with fewer resources — both human and technical. Cobalt’s 2022 The State of Pentesting Report found that 90% of short-staffed teams are struggling to monitor for…

The Importance of Modern-Day Data Security Platforms

Data is the backbone of businesses and companies everywhere. Data can range from intellectual property to critical business plans to personal health information or even money itself. At the end of the day, businesses are looking to grow revenue, innovate, and operationalize but to do that, they must ensure that they leverage their data first because of how important and valuable it is to their organization. No matter the industry, the need to protect sensitive and personal data should be…

Meeting Today’s Complex Data Privacy Challenges

Pop quiz: Who is responsible for compliance and data privacy in an organization? Is it a) the security department, b) the IT department, c) the legal department, d) the compliance group or e) all of the above? If you answered "all of the above," you are well-versed in the complex world of compliance and data privacy! While compliance is a complex topic, the patchwork of regulations imposed by countries, regions, states and industries further compounds it. This complexity has turned…