Skip to content
October 10, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • Gartner issues Top six Security and Risk Management Trends For 2018
  • Technology

Gartner issues Top six Security and Risk Management Trends For 2018

Do Son July 10, 2018 4 minutes read
Global Risks Report 2018
Add Daily CyberSecurity as a preferred source on Google

The 2018 Gartner Security and Risk Management London Summit will be held from September 10th to 11th. Analysts will explore the trends facing security administrators and vendor risk assessment frameworks at the summit.

Gartner believes that business leaders are paying more attention to the impact of cybersecurity on corporate output. Security managers should use this support and six new trends to improve the resiliency of their businesses while enhancing their position.

Trend 1: Executives will eventually realise that cybersecurity will affect the achievement of corporate goals and will also affect corporate reputation.

IT security is an extensive topic and a necessary component of any e-commerce strategy.Β Business managers have been reluctant to accept this, but recent events have changed their perceptions.Β Such as:

  • The Equifax data breach has caused the company’s CEO, CIO and CSO to lose their jobs;
  • The WannaCry attack caused a global loss of $1.5 billion to $4 billion;
  • After Yahoo’s data breach, Verizon received a $350 million discount for Yahoo’s acquisition.

Peter FirstBrook, vice president of research at Gartner, said “Business leaders and senior stakeholders, at last, appreciate security as much more than just tactical, technical stuff done by overly serious, unsmiling types in the company basement, research vice president at Gartner. “Security organizations must capitalize on this trend by working closer with business leadership and clearly linking security issues with business initiatives that could be affected.”

Trend 2: Regulatory, mandatory data protection policies are affecting the plans of the e-commerce industry and place more demands on data reliability.

Customer data is the lifeblood of the e-commerce industry.Β Recent β€œCambridge Analytical Data Disclosure Incidents” and Equifax data breaches have shown that companies face significant risks when processing such data.Β Moreover, the relevant laws are becoming more and more complicated. For example, on May 25, 2018, theΒ EU’s General Data Protection Regulations GDPRΒ came into effect.Β At the same time, if companies do not adequately protect data, there are a lot of more massive penalties waiting for them.

In the United States, the number of organisations experiencing data breaches has grown from less than 100 in 2008 to more than 600 in 2016.

Firstbrook believes that “It’s no surprise that, as the value of data has increased, the number of breaches has risen too. In this new reality, full data management programs β€” not just compliance β€” are essential, as is fully understanding the potential liabilities involved in handling data.”

Trend 3: Security products are rapidly leveraging cloud services to provide more flexible solutions.

The new detection technology, activity and verification models require a significant amount of data that can quickly crash an internal security solution.Β This situation has spawned the need for cloud security products.Β Cloud security services are better able to provide more flexible and adaptable solutions with near real-time data.

Firstbrook recommends that “Avoid making outdated investment decisions. Seek out providers that propose cloud-first services, that have solid data management andΒ machine learning (ML)competency, and that can protect your data at least as well as you can.”

Trend 4: Machine learning is bringing value to simple tasks and can also assess suspicious matters in the human analysis.

Switching to cloud services creates opportunities for companies to use machine learning to solve security problems (e.g., adaptive verification, internal threats, malicious advanced attackers, etc.).Β Gartner predicts that machine learning will become a standard part of security solutions by 2025 and will make up for the shortage of technology and personnel.

FirstBrook believes that “Look at how ML can address narrow and well-defined problem sets, such as classifying executable files, and be careful not to be suckered by hype. Unless a vendor can explain in clear terms how its ML implementation enables its product to outperform competitors or previous approaches, it’s very difficult to unpack marketing from good ML.”

Trend 5: Security procurement decisions are increasingly dependent on geopolitical factors.

Cyber warfare has intensified, and cyber political interference and government demands left backdoors for accessing software and services, all of which have led to new geopolitical threats in software and infrastructure procurement.Β Recently, the ban imposed by the US government on Russia (Kaspersky) and Chinese companies (Huawei) is the best example.Β Recent

Firstbrook believes that “It’s vital to account for the geopolitical considerations of partners, suppliers and jurisdictions that are important to your organisation. Include supply chain source questions in RFIs, RFPs and contracts.”

Trend 6: Over-reliance on the threat posed by electronic technology is driving the decentralization of the entire ecosystem.

The Internet is driving a wave of centralisation, and cloud computing is an obvious example.Β While there are many benefits to doing so, a good security team should also consider the risks.

Firstbrook believes that “Evaluate the security implications of centralization on the availability, confidentiality and resiliency of digital business plans. Then, if the risks of centralization could seriously threaten organizational goals, explore an alternative, decentralized architecture.”

Related coverage

  • Beyond the Screen: Samsung’s Galaxy S26 Ultra Debuts “Magic Flex” Privacy and Agentic AI
  • Intel link with Microsoft, Dell, HP, and Lenovo to make 5G laptops
  • Epic Games Victory: Supreme Court Denies Google’s Appeal, Forcing Play Store Policy Overhaul by Oct 22
  • You’re In Control: Instagram Launches “Your Algorithm” Feature for Reels
  • The Anonymity Myth: How the FBI Unmasked a β€œHide My Email” User in Under 48 Hours
  • Google Announces Collaboration with Unity Engine Team
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS Β· Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Risk Management Trends

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2026-105133CVSS 6.9
    A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2023-22894CVSS 4.9
    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2016-3081CVSS 8.1
    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-3306CVSS 10.0
    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-5477CVSS 7.5
    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2021-3199CVSS 9.8
    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-93945CVSS 9.8
    Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93936CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93937CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93938CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93940CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93941CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93942CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93943CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a...
    📅 Updated: Oct 10, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.