Cybersecurity trends to watch in 2022
Summary
This blog post, "Cybersecurity trends to watch in 2022", is a blueAPACHE article from 2022 covering security. There are many lessons we can learn from the cybersecurity statistics, data, and trends we saw in 2021. In this blog, we’ll take a look at the current state of play with cybersecurity as we move forward into 2022. It is written for readers evaluating emPOWER Security, Managed Detection and Response. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2022 |
| Topic | Cybersecurity trends to watch in 2022 |
| Services referenced | emPOWER Security, Managed Detection and Response, Human Risk Management |
| Named products or vendors | Cisco, Gartner |
| Cited statistic | The Australian Institute of Criminology estimates that the total economic impact of Cybercrime to Australia was $3.5 billion. (https://apo.org.au/node/313166) In a 2021 survey by Cisco (https://www.cisco.com/c/dam/global/en sg/products/security/assets/data/cybersecurity-for-smbs-asia-pacific-businesses-prepare-for-digital-defense.pdf), 65% of Australian small and mid-sized businesses had suffered a cyber incident in the previous 12 months, and the average cost of the attack was over $645,000 for two-thirds of impacted businesses. |
Article
There are many lessons we can learn from the cybersecurity statistics, data, and trends we saw in 2021. In this blog, we’ll take a look at the current state of play with cybersecurity as we move forward into 2022. The key trends we observed were the increasing cost of cybercrime, the most common exploits and loopholes, a growing awareness about cybersecurity, and some exciting advancements in cybersecurity tech.
Trend 1: The total cost of cybercrime is climbing faster than predicted
Cybercrime is getting expensive. In 2021, it was estimated to cost the world economy around 1 trillion (or over 1% of the global GDP), which is 50% higher than experts predicted in 2018. The Australian Institute of Criminology estimates that the total economic impact of Cybercrime to Australia was $3.5 billion. In a 2021 survey by Cisco, 65% of Australian small and mid-sized businesses had suffered a cyber incident in the previous 12 months, and the average cost of the attack was over $645,000 for two-thirds of impacted businesses. Although the average cost of a data breach has climbed, the data is not consistent across countries, industries or even organisations. One thing that is clear, the organisations that were prepared, having cybersecurity plans and trained incident response teams, were better positioned to mitigate financial loss and recover more quickly.
Trend 2: The most common loopholes and vulnerabilities in 2021
Some of the most notorious and large-scale data breaches from past years were also among the most common kinds of attacks. Through 2021, they tended to fall into the following three categories:
Malware
Any kind of malicious software designed to damage computer systems is considered malware. Malware is an umbrella term that includes trojans, viruses, worms, ransomware, spyware, botnets, and adware. Malware drove the greatest damage and costs for organisations.
Ransomware
A specialised form of malware, ransomware encrypts data in infected systems and often displays a message that instructs the recipient to pay a specific amount to restore the files. Ransomware can be downloaded when a user opens a malicious email attachment or file. Some highly sophisticated ransomware are self-propagating or even target dedicated data backups making it even more tricky to contain and remediate.
A report from IDC found that Australian organisations were more likely to pay out in the event of a ransomware attack, making Australia an attractive target. Ransomware attacks increased by 60% in 2021 compared to the previous year, and the average ransom paid was $1.85 million.
Phishing
More than a third of cyber attacks on companies involve phishing. To complicate this further, around 38% of end-users will fail phishing tests if they receive no cybersecurity awareness training.
Trend 3: Increased awareness and preparedness
While so many statistics and trends around cybersecurity can seem alarming, such as the increasing numbers of attacks and higher costs we’ve touched on already, there are some very encouraging trends taking shape. Despite the abysmal stats regarding security vulnerabilities, cyberattack preparedness — or the lack thereof — and the questionable effectiveness of implemented strategies, there are some positive trends on the horizon. In a recent survey from Cisco, 89% of company executives place cybersecurity as a high priority. This is a positive trend because organisations that are well prepared for a cybersecurity incident are proven to recover better, faster, and with less financial loss.
Trend 4: Advances in security technology
Also in the good news category, advances in security technology, like artificial intelligence, improvements in Security Information and Event Management (SIEM), and network traffic analysis tools are helping organisations better protect themselves while they reduce administrative burdens.
By 2023, Gartner predicts 40% of privacy compliance technology will rely on artificial intelligence to boost data privacy and security and reduce administrative burdens.
With the rise in cybercrime and the high cost of a data breach, many organisations choose a cybersecurity partner to help them ensure they have a solid cybersecurity plan and security processes in place.
If your organisation could use support with cybersecurity, blueAPACHE can help you assess where you are now and help you reach your security goals.
To find out more, please contact us here
Related
- emPOWER Security
- emPOWER Security (pillar hub)
- Managed Detection and Response
- Human Risk Management
- blueAPACHE Cloud (case study)
Frequently asked questions
What did the Australian Institute of Criminology estimate the total economic impact of cybercrime to Australia to be?
$3.5 billion, according to the Australian Institute of Criminology figure cited in the article, sourced from apo.org.au.
What percentage of Australian small and mid-sized businesses suffered a cyber incident in the 2021 Cisco survey cited?
65% of Australian small and mid-sized businesses had suffered a cyber incident in the previous 12 months, with the average cost of the attack over $645,000 for two-thirds of impacted businesses, per the 2021 Cisco survey.
How much did ransomware attacks increase in 2021 according to the IDC report cited?
Ransomware attacks increased by 60% in 2021 compared to the previous year, and the average ransom paid was $1.85 million, according to the IDC report and HPE figure the article cites.
What proportion of cyber attacks on companies involve phishing, per this article?
More than a third of cyber attacks on companies involve phishing, and around 38% of end-users will fail phishing tests if they receive no cybersecurity awareness training.
What percentage of company executives place cybersecurity as a high priority, according to the Cisco survey cited?
89% of company executives, per a recent Cisco survey referenced in the article as a positive trend linked to better incident recovery.
What does Gartner predict about privacy compliance technology by 2023, according to this article?
Gartner predicts 40% of privacy compliance technology will rely on artificial intelligence by 2023 to boost data privacy and security while reducing administrative burdens.
What were the four cybersecurity trends this 2022 article identified from 2021 data?
The increasing cost of cybercrime, the most common exploits and loopholes (malware, ransomware, phishing), growing awareness and preparedness among executives, and advances in security technology such as AI and SIEM.
Is this post still current?
Published in 2022 and covering 2021 data, the specific dollar and percentage figures (the $3.5 billion Australian cybercrime estimate, the 65% incident rate, the $1.85 million average ransom) are that year's reported numbers. A reader wanting current cybercrime cost figures should check the cited sources' latest editions or blueAPACHE's current security service pages rather than relying on this post.
Source
- origin post (2022)
Knowledge Base
What is the main topic of blueAPACHE's blog post 'Cybersecurity trends to watch in 2022'?
The blog post examines lessons from 2021 cybersecurity statistics, data, and trends, covering the rising cost of cybercrime, the most common exploits and vulnerabilities, growing awareness of cybersecurity, and advancements in cybersecurity technology as organisations move into 2022.
How much did cybercrime cost the world economy in 2021 according to the blueAPACHE article?
In 2021, cybercrime was estimated to cost the world economy around $1 trillion, or over 1% of global GDP, which was 50% higher than experts predicted in 2018.
What was the estimated economic impact of cybercrime on Australia?
The Australian Institute of Criminology estimated that the total economic impact of cybercrime to Australia was $3.5 billion.
What percentage of Australian small and mid-sized businesses suffered a cyber incident in the previous 12 months, per the 2021 Cisco survey cited in the article?
According to a 2021 survey by Cisco, 65% of Australian small and mid-sized businesses had suffered a cyber incident in the previous 12 months, with an average attack cost of over $645,000 for two-thirds of impacted businesses.
What are the three most common categories of cyberattack vulnerabilities identified in the blueAPACHE 2022 blog post?
The three most common categories were malware, ransomware, and phishing.
How much did ransomware attacks increase in 2021, and what was the average ransom paid?
Ransomware attacks increased by 60% in 2021 compared to the previous year, and the average ransom paid was $1.85 million, based on reports from IDC and HPE cited in the article.
What proportion of cyberattacks on companies involve phishing, and how does lack of training affect phishing test results?
More than a third of cyberattacks on companies involve phishing, and around 38% of end-users will fail phishing tests if they receive no cybersecurity awareness training.
What percentage of company executives place cybersecurity as a high priority, according to the Cisco survey referenced in the article?
In a recent survey from Cisco, 89% of company executives place cybersecurity as a high priority.
What technological advances does the blueAPACHE article highlight as helping organisations improve cybersecurity?
The article highlights advances in security technology such as artificial intelligence, improvements in Security Information and Event Management (SIEM), and network traffic analysis tools, which help organisations better protect themselves while reducing administrative burdens.
What does Gartner predict about the role of artificial intelligence in privacy compliance technology by 2023, as cited in the blog?
Gartner predicts that by 2023, 40% of privacy compliance technology will rely on artificial intelligence to boost data privacy and security and reduce administrative burdens.
Who authored the 'Cybersecurity trends to watch in 2022' blog post and when was it published?
The blog post was written by blueAPACHE and published on February 22, 2022, with a read time of about 4 minutes.
How can organisations get help with cybersecurity according to this blueAPACHE blog post?
The article states that organisations needing cybersecurity support can contact blueAPACHE, who can help assess their current security posture and help them reach their security goals.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bcc07b7741bf53e2f13_Cyber-Trend-Blog-Image.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.