Editor's note, October 2026: This review was published in November 2021 and reflects our view at that time; the outlook for 2022 is kept as written. One prediction has since become concrete: in August 2024, NIST published its first three finalized post-quantum encryption standards, FIPS 203, 204 and 205. Read what that means for you in Time to Get Post-Quantum Ready. The previous review is 2020: A Year in Review, and Looking Forward to 2021; the following ones are 2022: The Year in Review and Looking Forward to 2023 and Cybersecurity in the Enterprise Landscape: 2024 Year in Review.
After an unconventional year like 2020, with a pandemic putting the whole world on hold, 2021 was widely expected to bring a return to "business as usual", with employees returning to the office as vaccines became available and the threat of COVID dwindled. Of course, nothing has proven that simple.
Progress is being made, and everything indicates that we are getting closer to "normal", but we are not there yet and may never be back exactly where we were before. We are more likely heading towards a new normal. The pandemic has challenged us all personally, and it has challenged enterprises, which had to adapt to new and sometimes unexpected scenarios.
Before the pandemic, many companies did not consider remote work or implemented it only to a limited extent. Then it became the main option for keeping employees working and the business running. What was once a temporary workaround has gradually become the standard process and toolset for many businesses, especially those that rely on technology for day-to-day work and can handle business tasks remotely.
This new paradigm has big benefits for employees and companies alike: convenience, lower greenhouse gas emissions, better work-life balance and flexibility, and smaller offices (or none at all), which means lower office expenses for rent, heating and electricity. It also opens the door to talented people who do not want to move to a specific city.
It is no surprise that most businesses, whatever their size, are moving from local, on-premises architecture to cloud-based services to ease day-to-day administration, reduce total cost of ownership (TCO), and offer services to their users consistently and securely across all their devices, wherever they are.
Some businesses adopt certain cloud services while keeping part of their on-premises architecture, a hybrid environment. This is typical for valuable, private internal or customer data that data privacy standards and regulations do not yet allow, or do not recommend, storing in the cloud. But the move to the cloud is now a one-way journey.
The move to the cloud brings challenges that enterprises need to take seriously to keep the same level of productivity and security wherever employees are: protect data, secure devices and secure the connection. From small offices and SMEs to large international enterprises, many businesses are reviewing their security posture and adapting it to their business and to the new challenges of the digital workplace, including cybersecurity threats.
Many businesses are also reviewing the costs of their enterprise mobility. Best practices include reviewing current service subscriptions and bundling as many services as possible with the same provider or providers to reduce cost, simplify integration and lower day-to-day administration. Businesses are also limiting the number of devices each employee can use for work and doing regular "house cleaning" to make sure unused devices and unnecessary subscriptions are disabled.
In a large infrastructure this sounds like a lot of work, but a lifecycle management solution can handle these tasks dynamically by connecting the systems involved (UEM, TEM and others) to optimize enterprise mobility expenses. Our endpoint lifecycle management service covers exactly this.
We strongly recommend our articles Security Maturity Model, Part 1 and Security Maturity Model, Part 2, which describe best practices for improving your security posture step by step as your business grows.
Today, a Virtual Private Network (VPN) remains one of the best options for exchanging sensitive, private data securely over unsecured, unmanaged public networks such as the internet, safe from attacks or intrusions. However, given the progress in quantum computing over the last few years, this technology could one day be used to break that protection. We are not there yet, but many vendors are already working on alternatives designed to withstand quantum-powered attacks, such as Verizon with its quantum-safe VPN trial.
With the dawn of 2022 and employees still working remotely or in hybrid setups, we can expect enterprises to continue their migration to a fully digital workplace and cloud-based services. That shift brings the need to keep the same level of security and protect data for employees wherever they are. Whatever the size or reach of your ecosystem, understanding your business and the operational needs of your cybersecurity solution is essential to address your specific vulnerabilities, for example with a Zero Trust approach.
The ISEC7 team can provide an objective assessment of what your organization needs and which risk mitigation would strengthen your current solution, and our endpoint security services support the implementation. Contact us for a consultation or with any questions as your organization heads into 2022.