Cybercrime is a lucrative industry. According to Atlas VPN’s latest research, it pulls in $1.5 trillion in revenue annually. For comparison: that’s three times more than Walmart’s annual income, and it’s even more than Tesla, Facebook, Microsoft, Apple, Amazon, and Walmart’s annual revenue combined, which totals a paltry $1.28 trillion.

As many defenders experienced firsthand, 2020 was a boon for cybercriminals, with the pandemic broadening the attack surface and the SolarWinds hack closing out the year. And 2021 is already off to a roaring start, thanks to the Accellion breach, linked to the Clops ransomware gang, and the more recent Microsoft Exchange hack, which Microsoft attributed to the Chinese hacking group Hafnium.

“It’s a wild and tough time in security,” said Rick McElroy, principal cybersecurity strategist for VMware’s Security Business Unit. “The future for defenders is going to be tough. I don’t believe that SolarWinds is fully triaged yet. Especially on the government side, we still don’t understand the scope, impact, what data was exfiltrated, and how is that going to be leveraged? Investigations are continuing [into SolarWinds], and then right into Hafnium that’s essentially doing business email compromise.”

In January, VMware conducted an online survey about evolving cybersecurity threats and trends ahead in 2021 with 180 incident responders, cybersecurity and IT professionals from around the world participating. It released the survey results this week, and they paint a bleak picture of what to expect from attackers this year — but also shed light on what defenders can do to prepare and fight back against cybercrime.

Cybercrime Tactics Turned Nastier in 2020

About 40% of the survey respondents said double-extortion ransomware was the most observed new ransomware attack technique in 2020. Additionally, more responders said attackers are fighting back, with 63% experiencing counter incident response since the start of the pandemic. The top techniques observed included: security tool disablement (33%), distributed denial-of-service (DDoS) attacks (26%), security tool bypass (15%), destruction of logs (11%).

Additionally, VMware found that almost half (44%) of respondents witnessed island hopping — this is what happened with the SolarWinds attack, where attackers “hop” from one network to another along the supply chain.

“Cybercriminal rings have gotten so sophisticated in what they’re doing that the nation states are now adopting their tactics,” McElroy said.

Defenders, however, have the tools to fight back.

“What I hear everyone talking about, and I think it’s the right direction, is a focus on identities, and then adopting a zero-trust model,” McElroy said. “If you tear apart all of these attacks, at some point, usually in the beginning of the attack, they’re stealing that identity and taking those credentials. So the focus on identity is going to be the right focus.”

Additionally, the pandemic increased the speed at which companies moved to cloud environments, “and visibility waned as a result,” he added. “So folks are trying to get that context back, that full picture of what’s occurring, whether it’s in the cloud environment or on prem.”

Defenders Become Proactive With Threat Hunting

Because of these increasingly destructive cybercrime attacks, 81% of security teams surveyed said they have adopted a more proactive mindset and developed a threat-hunting program. Organizations are investing in other security tools and services as well.

Companies’ top priorities include security for trusted third parties/supply chain (24%), remote access security (24%), network and endpoint security (22%), identity and access controls (21%), and hardware/physical device security (9%). When asked how they plan to invest in security this year, network security (27%) topped the spending list, followed by cloud security (20%), endpoint security (17%), data protection (16%) and managed security services (12%).

Despite all of the challenges facing defenders, McElroy remains positive. “We were super happy to see that 81% of the teams have threat-hunting programs in place and are being proactive,” he said.

Even the SolarWinds breach, which FireEye CEO Kevin Mandia, who discovered the attack, described as one of the most sophisticated that he had seen in his 25 years in cybersecurity, indicates that the industry is improving its defensive posture, McElroy said. “I credit an increase in better technology that’s been deployed, and also things like the MITRE ATT&CK framework, which gives us all a common language and a way to test our tools continually on the defender side. It still looks bad, but I do believe that we’ve raised the bar for these attackers to attack us. And hopefully, we start breaking up this $1.5 trillion cybercriminal market.”