Tired of ads? Enjoy an ad-free experience by signing up.
  • Insights
    This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
Dennis Mitzner · · 4 min read

5 threats to website security in 2016

padlock security

Website security has always been one of the more controversial aspects of the industry as there’s always a trade-off between the convenience and efficiency of a service and the amount of risk it holds. With cloud services taking over the market and replacing local physical servers, new and renewed threats have become part of the discussion. Hackers are becoming smarter by the minute, and potential threats such as backdoor Trojan apps, online fraud and data leaks need to be addressed.

For the hi-tech industry in Asia-Pacific countries, this is hardly news. Mergers, company purchases and state-level decisions all point to the fact that they’re all putting much effort into preparing for cyber crimes to come.

What types of threats should they be preparing themselves for in 2016?

#1 Data breaches

Private individual data, from email addresses to social security details to credit card numbers, are always at risk of getting into the wrong hands. Virtual machine operations open up whole new venues of hacking. In the last few years we’ve witnessed some huge hacks, from Yahoo Japan’s 2013 breach, exposing over 20 million accounts, to the Ashley Madison hack earlier this year, in which a group of hackers released the account details of some 32 million users. Since little or no personal information exists anymore that isn’t backed up on one server or another, this is bound to be the biggest concern.

One way to improve protection against data breaches is end-to-end encryption, which is incorporated in the upcoming HTTP/2 protocol, the next generation web protocol. Current browsers that support the protocol enforce encrypted connections over HTTP/2, thus ensuring a secure connection from client to server. In addition, HTTP/2 also comes with added performance benefits from browser multiplexing and reduced bandwidth load.

#2 DDoS attacks

Distributed denial of service attacks grew by 180% in 2015, becoming the most popular type of cyber attack this year. Just a few months ago several Thai government websites were attacked and were impossible to access for a full night.

In the Asia Pacific, the threat of DDoS is so severe that Baidu, one of the region’s largest social media services, beefed up its infrastructure security, by acquiring online security startup Anquanbao, which specializes in protecting against precisely these kinds of attacks.

Downtime is caused by more than just DDoS attacks, though, as server crashes can happen due to simple overload. One way to protect your infrastructure is to incorporate load balancing and failover solutions, which distributes traffic across several machines and bypasses downed servers.
Such a solution is an effective way to ensure business continuity at all times – during DDoS attacks, accidents or regular traffic spikes. For example, Incapsula, known for its DDoS mitigation services, also provides failover and load balancing services, recognizing the fact that not all downtimes are DDoS related
This way, the high availability of major websites around the globe is ensured, including BitStamp and BTC China – the world’s two largest bitcoin exchanges.

#3 Backdoor Trojans

These sorts of software often pose as legitimate downloads, while granting remote access to a third party, making them privy to personal information on devices, as well as giving the ability to manage the computer or network in question. Coolpad, a Chinese mobile phone manufacturer, was grabbing headlines one year ago when it was discovered that many of its phones had a major security flaw that allowed its software to download apps, send and receive calls and messages and upload user data to Coolpad serves.

#4 Ransomware

Ransomware is another major concern for web security specialists. Like DDos attacks, its popularity has grown significantly over time. With this threat, an attacker locks or freezes digital assets or devices, only releasing them when the user pays a significant ransom.

India, for instance, became the “ransomware capital of APAC” after a Symantec report named it the 9th most impacted region by ransomware, topping the chart alongside the US, UK, Italy, Japan and more. The biggest name in the field this year has been TeslaCrypt, which started out targeting gamers but quickly moved on to businesses.

#5 Internet fraud

Possibly the oldest trick in the book, internet-based frauds are some of the more difficult attacks to protect against, due to the human factor involved. China has come up with one interesting solution: the state’s media service announced it will station police officers in the offices of China’s biggest internet firms. This controversial move, adding more fuel to the already-heated discussion of Chinese Internet censorship, is said to be a protective measure against cyber crimes, which pose a threat to social stability.

Judging by current trends, website security in 2016 will receive a lot of attention. From hacktivists to online extortion and from cloud hacks to data theft, businesses and governments alike will need to find a way to protect themselves and their users. At least one side stands to gain from this – the cyber insurance market. According to a PwC report from September this year, the global cyber insurance market is expected to grow to $5 billion in premiums by 2018 and reach $7.5 billion by 2020. Legislators the world over are also doing their part. In the US, for instance, cyber security looks like it’s about to receive its own line in the federal spending bill.

Now add to the security mix two more factors. First is the Internet of Things, where an ever-increasing demand, particularly in the Asia-Pacific, puts a lot of pressure on developers to start sending out products before proper testing is done. Second is big data, an essential part of many organizations’ work around the world, and practically an open invitation for hackers. Cyber security will continue to be on top of everyone’s minds in 2016 and it remains to be seen who will get the upper hand in this round: clever hackers or clever defense.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Dennis Mitzner

Dennis writes about start-ups, technology trends, crowdfunding/sourcing and politics. He is based in Tel Aviv.