- Insights This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
5 threats to website security in 2016

Website security has always been one of the more controversial aspects of the industry as there’s always a trade-off between the convenience and efficiency of a service and the amount of risk it holds. With cloud services taking over the market and replacing local physical servers, new and renewed threats have become part of the discussion. Hackers are becoming smarter by the minute, and potential threats such as backdoor Trojan apps, online fraud and data leaks need to be addressed.
For the hi-tech industry in Asia-Pacific countries, this is hardly news. Mergers, company purchases and state-level decisions all point to the fact that they’re all putting much effort into preparing for cyber crimes to come.
What types of threats should they be preparing themselves for in 2016?
#1 Data breaches
Private individual data, from email addresses to social security details to credit card numbers, are always at risk of getting into the wrong hands. Virtual machine operations open up whole new venues of hacking. In the last few years we’ve witnessed some huge hacks, from Yahoo Japan’s 2013 breach, exposing over 20 million accounts, to the Ashley Madison hack earlier this year, in which a group of hackers released the account details of some 32 million users. Since little or no personal information exists anymore that isn’t backed up on one server or another, this is bound to be the biggest concern.
One way to improve protection against data breaches is end-to-end encryption, which is incorporated in the upcoming HTTP/2 protocol, the next generation web protocol. Current browsers that support the protocol enforce encrypted connections over HTTP/2, thus ensuring a secure connection from client to server. In addition, HTTP/2 also comes with added performance benefits from browser multiplexing and reduced bandwidth load.
#2 DDoS attacks
Distributed denial of service attacks grew by 180% in 2015, becoming the most popular type of cyber attack this year. Just a few months ago several Thai government websites were attacked and were impossible to access for a full night.
In the Asia Pacific, the threat of DDoS is so severe that Baidu, one of the region’s largest social media services, beefed up its infrastructure security, by acquiring online security startup Anquanbao, which specializes in protecting against precisely these kinds of attacks.
#3 Backdoor Trojans
These sorts of software often pose as legitimate downloads, while granting remote access to a third party, making them privy to personal information on devices, as well as giving the ability to manage the computer or network in question. Coolpad, a Chinese mobile phone manufacturer, was grabbing headlines one year ago when it was discovered that many of its phones had a major security flaw that allowed its software to download apps, send and receive calls and messages and upload user data to Coolpad serves.
#4 Ransomware
Ransomware is another major concern for web security specialists. Like DDos attacks, its popularity has grown significantly over time. With this threat, an attacker locks or freezes digital assets or devices, only releasing them when the user pays a significant ransom.
India, for instance, became the “ransomware capital of APAC” after a Symantec report named it the 9th most impacted region by ransomware, topping the chart alongside the US, UK, Italy, Japan and more. The biggest name in the field this year has been TeslaCrypt, which started out targeting gamers but quickly moved on to businesses.
#5 Internet fraud
Possibly the oldest trick in the book, internet-based frauds are some of the more difficult attacks to protect against, due to the human factor involved. China has come up with one interesting solution: the state’s media service announced it will station police officers in the offices of China’s biggest internet firms. This controversial move, adding more fuel to the already-heated discussion of Chinese Internet censorship, is said to be a protective measure against cyber crimes, which pose a threat to social stability.
Judging by current trends, website security in 2016 will receive a lot of attention. From hacktivists to online extortion and from cloud hacks to data theft, businesses and governments alike will need to find a way to protect themselves and their users. At least one side stands to gain from this – the cyber insurance market. According to a PwC report from September this year, the global cyber insurance market is expected to grow to $5 billion in premiums by 2018 and reach $7.5 billion by 2020. Legislators the world over are also doing their part. In the US, for instance, cyber security looks like it’s about to receive its own line in the federal spending bill.
Now add to the security mix two more factors. First is the Internet of Things, where an ever-increasing demand, particularly in the Asia-Pacific, puts a lot of pressure on developers to start sending out products before proper testing is done. Second is big data, an essential part of many organizations’ work around the world, and practically an open invitation for hackers. Cyber security will continue to be on top of everyone’s minds in 2016 and it remains to be seen who will get the upper hand in this round: clever hackers or clever defense.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




