---
title: What to expect in 2023
description: Looking back at recent trends in cyber-criminal behavior, we can get some idea of what they may get up to in the coming year. 
image: https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Blog%2019%20What%20to%20expect%20in%202023%20-%20780x438.png
---

[![cybergym_logo-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/cybergym_logo-1.svg "cybergym_logo-1")](https://www.cybergymiec.com/)

[request a Demo ](https://blog.cybergymiec.com/blog/what-to-expect-in-2023#popupBox)

[request a Demo ](https://blog.cybergymiec.com/blog/what-to-expect-in-2023#popupBox)

#### Sophic Defense Solutions

![ZONE](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/ZONE.svg)

[Zone ](https://cybergymiec.dooble.us/product/sophic-defense-solutions/zone/)

![ACCESS-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/ACCESS-1.svg)

[Access ](https://cybergymiec.dooble.us/product/sophic-defense-solutions/access/)

![path829-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/path829-1.svg)

[INFO ](https://cybergymiec.dooble.us/product/sophic-defense-solutions/info/)

#### Cybergym Training Solutions

![CyberFrame-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/CyberFrame-1.svg)

[Cyber Arenas ](https://cybergymiec.dooble.us/product/cybergym-training-solutions/second-opinion-assessment/)

![VirtualCloudArena-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/VirtualCloudArena-1.svg)

[Virtual Cloud Arena ](https://cybergymiec.dooble.us/product/cybergym-training-solutions/virtual-cloud-arena/)

![TrainingPrograms-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/TrainingPrograms-1.svg)

[Training Programs ](https://cybergymiec.dooble.us/product/cybergym-training-solutions/training-programs/)

![Enabling-Tech-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Enabling-Tech-1.svg)

[Enabling Tech ](https://cybergymiec.dooble.us/product/cybergym-training-solutions/enabling-tech/)

#### VAS

![flash-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/flash-1.svg)

[Crisis management ](https://cybergymiec.dooble.us/product/vas/crisis-management/)

![gauge-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/gauge-1.svg)

[Penetration Test ](https://cybergymiec.dooble.us/product/vas/penetration-test/)

![shield-bug-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/shield-bug-1.svg)

[Vulnerability Assessment ](https://cybergymiec.dooble.us/product/vas/vulnerability-assessment/)

![presentation-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/presentation-1.svg)

[Intro ](https://cybergymiec.dooble.us/product/vas/intro/)

![toolbox-outline-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/toolbox-outline-1.svg)

[SOC-as-a-Service ](https://cybergymiec.dooble.us/product/vas/soc-as-a-service/)

![shield-account-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/shield-account-1.svg)

[RCMA ](https://cybergymiec.dooble.us/product/vas/rcma/)

![account-group-outline](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/account-group-outline.svg)

[Workshops ](https://cybergymiec.dooble.us/product/vas/workshops/)

![lightbulb-multiple-outline-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/lightbulb-multiple-outline-1.svg)

[Second opinion ](https://cybergymiec.dooble.us/product/vas/second-opinion/)

![domain](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/domain.svg)

[About Us ](https://cybergymiec.dooble.us/about-us/)

![dresser-outline-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/dresser-outline-1.svg)

[Resources ](https://cybergymiec.dooble.us/events-webinars/)

![newspaper-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/newspaper-1.svg)

[Blog ](https://blog.cybergymiec.com/blog)

![briefcase-variant-outline-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/briefcase-variant-outline-1.svg)

[Career ](https://blog.cybergymiec.com/jobss?hsLang=en)

![req-demo-1-1](https://9397565.fs1.hubspotusercontent-na1.net/hub/9397565/hubfs/req-demo-1-1.jpg?width=392&height=583&name=req-demo-1-1.jpg)

![sophic_title-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/sophic_title-1.svg) ![access_title](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/access_title.svg)

Securing the most sensitive file transfer Secure File Sanitation and Transfer for worldwide SCADA Critical Infrastructure operators

![req-demo-2](https://9397565.fs1.hubspotusercontent-na1.net/hub/9397565/hubfs/req-demo-2.jpg?width=392&height=583&name=req-demo-2.jpg)

![sophic_title-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/sophic_title-1.svg) ![zone_title](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/zone_title.svg)

Cyber Validation Environment Emulate, simulate, test and validated cyber-attack in a near-real-time environment

![req-demo-3](https://9397565.fs1.hubspotusercontent-na1.net/hub/9397565/hubfs/req-demo-3.jpg?width=392&height=583&name=req-demo-3.jpg)

![sophic_title](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/sophic_title.svg) ![info_title](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/info_title.svg)

Securing the most sensitive file transfer Secure File Sanitation and Transfer for worldwide SCADA Critical Infrastructure operators

### Request a Demo

# What to expect in 2023

[Ofir Hason](https://blog.cybergymiec.com/blog/author/ofir-hason)

<https://www.linkedin.com/in/ofir-hason-a802b229/> January 17, 2023  3 min read

![](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Blog%2019%20What%20to%20expect%20in%202023%20-%20780x438.png)

Nobody can say for sure what the future holds - as Eugène Ionesco said: You can only predict things after they have happened. However, looking back at [recent trends](https://blog.cybergymiec.com/blog/2022-in-review?hsLang=en) in cyber-criminal behavior, we can get some idea of what they may get up to in the coming year. 

## **The continued rise of ransomware**

A firm hacker favorite in 2022 was ransomware, in which hackers infiltrate an organization’s system, encrypt their files and demand a ransom for their safe return to the owner. According to leading cybercrime analytics company, SpyCloud, in 2022, 90% of businesses surveyed reported having been affected by ransomware. The [average cost](https://ermetic.com/blog/cloud/ibm-cost-of-a-data-breach-2022-highlights-for-cloud-security-professionals/#:~:text=IBM%20found%20that%20the%20global,the%20cost%20was%20%243.86M.) of such a breach was USD 4.54 million – and that’s before the ransom itself was paid. 

Fueled by their success, cyber criminals continue to hone their ransomware skills, even going so far as to offer ransomware as a service – a lucrative business proposal with low barriers to entry, even for attackers with no technical skills of their own. As part of this phenomenon, experts expect that social engineering techniques, such as phishing, in which emails, websites and SMS messages are used to trick people into giving up personal information - will become increasingly sophisticated and successful. 

## **The vulnerability of connectivity**

As the number of Internet of Things (IoT) devices continues to grow, this increased connectivity makes our data more accessible to hackers. Since devices such as smart wearables, cars and industrial machines do not themselves store sensitive data, they are often overlooked when it comes to securing them. But, hackers can actually use these ‘always-on’ devices to get into other devices in the same network to steal credentials and passwords, obtain company data, carry out reconnaissance, or deliver malware. In the coming year, regulators are set to put in place certain measures to enhance security around connected devices. In the US, for example, [cybersecurity labelling standards](https://www.secureworld.io/industry-news/cybersecurity-labeling-iot-devices-2023) are due to come into force in the first quarter of 2023, explaining to consumers the risks of using such devices. 

## **Cloud concerns**

[Gartner](https://www.gartner.com/en/newsroom/press-releases/2021-11-10-gartner-says-cloud-will-be-the-centerpiece-of-new-digital-experiences) has estimated that 95% of assignments will be deployed to the cloud by 2025, making it a safe bet that cyberattacks on cloud services, infrastructure and applications will continue to rise – especially as encryption, authentication, and audit logging are not commonly offered by cloud providers. Assisted by ongoing remote working practices that rely on cloud storage and collaboration tools to keep team members connected, hackers are also using cloud technology to their advantage, exploiting it to spread malware and other malicious content. 

## **State-sponsored attacks**

As political tension increases between Russia and Ukraine, China and the West, and Iran - both internally and beyond its own borders - state actors are expected to continue using cyberwarfare as a weapon of war. This may take the form of disseminating disinformation and attacking digital infrastructure in parallel to the battle waged on the ground, intellectual property theft, or disruption of critical infrastructure. Governmental elections are another attractive target for hacktivists, seeking to influence the outcome to their own benefit. With around [60 elections](https://en.wikipedia.org/wiki/List_of_elections_in_2023) due to take place in 2023, there will be plenty of opportunity. 

## **Targeting critical infrastructure**

In the coming year, the threats mentioned until now will all be major risk factors for the critical infrastructure sector, including energy, healthcare and transportation. At one end of the scale, we’ll likely continue to see the kind of [scams](https://www.malwarebytes.com/blog/news/2022/09/energy-scammers-send-fake-energy-bills-support-scheme-texts) in which fake emails and text messages are sent to energy customers to steal their personal information. At the other end, there’s large-scale disruption of energy networks by state actors, of the kind seen in the recent Russian attacks on [Colonial Pipeline](https://www.techtarget.com/whatis/feature/Colonial-Pipeline-hack-explained-Everything-you-need-to-know) and [Solar Winds](https://www.techtarget.com/whatis/feature/SolarWinds-hack-explained-Everything-you-need-to-know); and in between there is likely to be exploitation of IoT and OT vulnerabilities by cyber criminals, espionage into green technology and energy policies, and more…

## **Fighting back**

Looking ahead, there is plenty that organizations can do to keep up with the evolving cyber threat landscape – especially if business leaders and cyber experts work together. 

Advances in Artificial Intelligence and Machine Learning have made it possible to automatically detect and prevent threats, by analyzing huge sets of data quickly, and accurately. These technologies enable security teams to pick up on unusual activity, such as increased traffic from a certain source, or user behavior patterns, so that they can take pre-emptive action to anticipated threats.

[Gartner](https://www.gartner.com/en/newsroom/press-releases/2022-10-13-gartner-identifies-three-factors-influencing-growth-i) reports that zero-trust network access is the fastest growing segment in network security, forecast to grow 31% in 2023. Based on a principle of ‘guilty until proven innocent’, every user, from the newest, most junior recruit to the CEO, is required to be approved to access the network, which contributes to a more robust and resilient security environment. 

Ultimately, according to [Forbes](https://www.forbes.com/sites/bernardmarr/2022/11/11/the-top-five-cybersecurity-trends-in-2023/?sh=308c3b561785), creating a culture of cyber-awareness is one of the most important steps an organization can take to protect itself from cyberattack. Teaching people at all levels, in all roles, how to take basic precautions, rather than thinking of cybersecurity as an issue for the IT department to deal with, can go a long way to preventing the [88% ](https://businessinsights.bitdefender.com/workers-confess-security-mistakes-stanford-professor)of cyber events caused by human error. 

 

##### Share

- <http://www.facebook.com/share.php?u=https://blog.cybergymiec.com/blog/what-to-expect-in-2023&utm_medium=social&utm_source=facebook>
- <https://twitter.com/intent/tweet?original_referer=https://blog.cybergymiec.com/blog/what-to-expect-in-2023&utm_medium=social&utm_source=twitter&url=https://blog.cybergymiec.com/blog/what-to-expect-in-2023&utm_medium=social&utm_source=twitter&source=tweetbutton&text=>
- <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.cybergymiec.com/blog/what-to-expect-in-2023&utm_medium=social&utm_source=linkedin>
- [mailto:?subject=Check%20out%20https://blog.cybergymiec.com/blog/what-to-expect-in-2023&utm_medium=social&utm_source=email%20&body=Check%20out%20https://blog.cybergymiec.com/blog/what-to-expect-in-2023&utm_medium=social&utm_source=email](mailto:?subject=Check%20out%20https://blog.cybergymiec.com/blog/what-to-expect-in-2023&utm_medium=social&utm_source=email%20&body=Check%20out%20https://blog.cybergymiec.com/blog/what-to-expect-in-2023&utm_medium=social&utm_source=email)

## Subscribe to our newsletter

### Get the latest posts in your email

## Subscribe to our newsletter

## Related Articles

[![](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Blog%2018%20Year%20in%20Review%20-Blog-553x277.jpg) ](https://blog.cybergymiec.com/blog/2022-in-review?hsLang=en)

## [The Year of the Hacker: 2022 in Review](https://blog.cybergymiec.com/blog/2022-in-review?hsLang=en)

Frankly, 2022 could have been dubbed ‘the Year of the Hacker’. In the first six months, there was [a...](https://www.globenewswire.com/en/news-release/2022/08/03/2491085/0/en/Check-Point-Software-s-Mid-Year-Security-Report-Reveals-42-Global-Increase-in-Cyber-Attacks-with-Ransomware-the-Number-One-Threat.html)

[Read More](https://blog.cybergymiec.com/blog/2022-in-review?hsLang=en)

December 26, 2022 Ofir Hason

 3 min read

[![](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Blog%20%2317%20Don%E2%80%99t%20Wait%20for%20the%20Regulator-Blog-553x277.png) ](https://blog.cybergymiec.com/blog/dont-wait-for-the-regulator?hsLang=en)

## [Don’t Wait for the Regulator!](https://blog.cybergymiec.com/blog/dont-wait-for-the-regulator?hsLang=en)

As the number and severity of cyberattacks happening around the world continues to increase, many...

[Read More](https://blog.cybergymiec.com/blog/dont-wait-for-the-regulator?hsLang=en)

November 28, 2022 Barak Davidovich, IEC

 3 min read

[![](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Cyber%20Range%20and%20Cyber%20Arena%20%E2%80%93%20Pros%2c%20Cons%20and%20Key%20Differences-Blog-553x277.png) ](https://blog.cybergymiec.com/blog/cyber-range-and-cyber-arena?hsLang=en)

## [Cyber Range and Cyber Arena – Pros, Cons and Key Differences](https://blog.cybergymiec.com/blog/cyber-range-and-cyber-arena?hsLang=en)

Cyber Range and Cyber Arena are both terms that refer to the training facilities used by...

[Read More](https://blog.cybergymiec.com/blog/cyber-range-and-cyber-arena?hsLang=en)

October 3, 2022 Ofir Hason

 3 min read

###### Home

###### About us

###### Resources

###### Solutions

[![Cybergym-logo-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Cybergym-logo-1.svg "Cybergym-logo-1")](https://www.cybergymiec.com/)

- <https://www.facebook.com/CybergymIEC>
- <https://www.linkedin.com/company/cybergymiec/>
- <https://twitter.com/CybergymIEC>
- <https://www.youtube.com/channel/UCCA70u4ld1U0FbqA8WjIDsg>

© 2022 CybergymIEC. All rights reserved