Finally, after two years, I’m back to blogging. After being inconsistent this year, I’ve decided to publish at least 24 posts — two each month. I don’t have a fixed vision for the blog yet, but I’ll try to cover as many topics, technologies, and product reviews around cyber security as I can.
2019 was something of a turning point for me, as I got the opportunity to move to Ireland to serve Irish clients. It was a tough decision to leave behind a project where I’d done so much upscaling, innovation, POCs, and implementations. Overall, 2019 was good — I stepped into the role of security architect / pre-sales solutions. The journey wasn’t easy, but I had enough support from mentors and seniors, and I’m hoping to turn that experience into personal and professional growth for my team.
Ransomware
Ransomware was the single biggest reason cyber security teams stayed engaged throughout 2019. Interestingly, the first half of the year saw no major ransomware impact — but the second half more than made up for it. A few stats from the year:
- Two-thirds of ransomware attacks targeted state and local governments.
- 55% of SMBs in the US said they would pay hackers to recover stolen data.
- Over 500 US schools were affected by ransomware attacks.
- Almost 70 US government organizations were infected since January 2019.
- 140 US local governments, police stations, and hospitals were infected with ransomware.
- In Q3 2019, the average ransomware payout rose to $41,000.
- Riviera Beach City, Florida, paid the highest ransom of the year — around $600,000 (65 Bitcoin) — to attackers. Other cities that chose to ignore the ransom and recover on their own ended up spending more than what the attackers had demanded.
Security Researchers
Security researchers played a major role in 2019, identifying and responsibly disclosing multiple data breaches. Many came forward with notifications about millions of breached user accounts — whether up for sale on the dark web or simply left exposed on public cloud storage without adequate protection. Millions of customer and personal records were found sitting on non-standard cloud databases like Elasticsearch and MongoDB. This trend is likely to drive increased demand for cloud security expertise and cloud security leads. A few notable breaches from the year: Orvibo, TrueDialog, and the BinaryEdge search engine — Capital One remains my personal top pick.
Microsoft Patches and Zero-Days
Microsoft didn’t disappoint on the patching front in 2019 — over 180 security patches were released, of which 10 were zero-days and more than 130 were rated critical, several of them actively exploited or targeted at users.
The pattern from 2018 continued into Patch Tuesday releases throughout the year, with a number of frustrated security researchers publishing proof-of-concept exploits on Twitter due to the nature of, and response from, Microsoft’s security team.
Bounty Hunters and Responsible Disclosure
Responsible disclosure and bug bounty hunters played a major role in 2019, with combined bounty platforms paying out an average of $62 million. A total of 120,000 responsible disclosures were reported across more than 2,000 vendors, including Google, Microsoft, Facebook, and Twitter.
Facebook alone paid around $2.3 million across 1,300 disclosure reports, with an average bounty of $1,500 — most of it going to researchers in India, Tunisia, and the USA.
HackerOne’s 2019 Bug Bounty report included a few notable highlights:
- The average bounty for critical vulnerabilities rose to $3,384 — a 48% increase over 2018’s average of $2,281, and a 71% increase over the 2016 average of $1,977. Bounties for less severe vulnerabilities also rose, with the average platform-wide bounty up 65%.
- Government programs saw the strongest year-over-year growth at 214%, with the first municipal-level programs launching this year. Strong adoption also came from Automotive (113%), Telecommunications (91%), Consumer Goods (64%), and Cryptocurrency & Blockchain (64%).
- 79% of bug bounty programs remain private, largely unchanged from prior years. Public programs engage roughly six times as many hackers.
- Six of the top ten North American banks now run hacker-powered security programs on HackerOne. Financial services organizations running such programs grew 41% this year.
- Six hackers surpassed $1 million in lifetime earnings, seven more crossed $500,000, and more than 50 earned $100,000 or more in the past year alone — a sign that skilled, dedicated researchers can build a genuine career in hacker-powered security.
Overall, 2019 wasn’t a bad year for the cyber security industry — if anything, these incidents pushed demand for security professionals even higher. In my next post, I’ll share my cyber security predictions for 2020.
References
- Heimdal Security — Ransomware Payouts Report
- Ivanti — Patch Tuesday Archive
- HackerOne — The 2019 Hacker Report
Leave a comment