SecurityWeek’s January 4, 2022 cybersecurity outlook was a set of forecasts about what might dominate that year—not a report on what ultimately happened. Its contributors anticipated changes in ransomware, software supply-chain attacks, industrial security, geopolitics, privacy, and emerging technology. The predictions below are attributed to their authors and should be read in that historical context.
What SecurityWeek’s contributors expected in 2022
The outlook brought together forecasts by Ryan Naraine, Eduard Kovacs, Kevin Townsend, and Ionut Arghire. Their subjects ranged from cybercrime and nation-state activity to industry deal-making and the risks posed by connected devices. The two numerical predictions in the article were:
| Contributor | 2022 forecast | How to read the figure |
|---|---|---|
| Eduard Kovacs | Roughly 400 cybersecurity-related mergers and acquisitions | A forecast for 2022 reported in SecurityWeek’s January 4 article, not a confirmed total. |
| Eduard Kovacs | More than 1,000 discovered industrial control system (ICS) vulnerabilities | A forecast for 2022 reported in SecurityWeek’s January 4 article, not a verified count. |
Ryan Naraine: ransomware, supply chains, and offensive actors
Ransomware and state-linked data theft
Naraine expected major ransomware outbreaks to subside gradually as organizations improved their defenses and law enforcement disrupted prominent gangs. He did not expect the underlying threat to disappear: in his view, ransomware and state-linked theft or espionage could increasingly overlap, making it harder to separate financially motivated crime from operations serving a government’s interests.
His defensive emphasis was on tested backups, timely patching, multifactor authentication, and secure cloud deployments. These were general organizational priorities, not endorsements of particular products.
#1 Best Overall
Software supply-chain attacks
Naraine predicted more “SolarWinds-type” attacks that exploit trust in software suppliers or shared components. He expected financially motivated criminals to join nation-state advanced persistent threat (APT) operators in targeting open-source software ecosystems. He described the work needed to address supply-chain weaknesses as “a long, painful slog.”
Hackers-for-hire and other state-linked activity
He anticipated greater public scrutiny of private-sector offensive actors—companies that supply governments with exploits and hacking tools. Technology-company research and possible U.S. sanctions were among the responses he expected to feature.
Other forecasts in his section included financial malware linked to Iranian and North Korean government-backed hackers, Chinese zero-day capabilities and disclosure rules, and malware operating below the operating system. He singled out UEFI firmware rootkits and bootkits as threats to watch. He also predicted that exhausted cybersecurity practitioners would leave the workforce.
Eduard Kovacs: industry activity and industrial security
Investment, mergers, and acquisitions
Kovacs expected cybersecurity venture funding to have another record year and mergers and acquisitions to remain brisk. His forecast of roughly 400 cybersecurity-related deals is a prediction made in the January 2022 article, not evidence of how many deals closed during the year.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Rank #3
Operational technology and ICS vulnerabilities
For operational technology (OT), Kovacs anticipated continued targeting of electric utilities and expected some manufacturers to publicly disclose production disruption after breaches of OT networks. He also forecast more than 1,000 newly discovered ICS vulnerabilities in 2022. That figure was his forecast, not a measured total supplied by the article.
Kevin Townsend: geopolitics, privacy, and emerging technology
Geopolitical cyber activity
Townsend framed cyber operations as part of continuing geopolitical positioning. He pointed to election interference, mapping critical infrastructure, and stealing state or trade secrets as activities to watch, alongside the risk that tensions could escalate.
Rank #4
Connected vehicles and mobile IoT
He predicted that connected vehicles and other mobile Internet of Things (IoT) devices could become attractive targets. Possible motives included extortion, while a successful attack on a vehicle could have catastrophic consequences. These were risk scenarios in a forecast, not reports of incidents that the article said had occurred.
Privacy and tokenization
Townsend anticipated friction between governments’ privacy laws and weak enforcement. He also argued that cloud economics might make tokenization—a way of substituting a token for sensitive data—more practical. The unresolved challenge, as he presented it, was whether newer providers could overcome the established views and investments that favor encryption.
Best Value
Quantum risk and adversarial AI
Townsend considered practical quantum computing unlikely to arrive during 2022, while warning that the prospect of future decryption could already motivate the theft of secrets and personal information. He also predicted more criminal use of artificial intelligence in business-email-compromise attacks and attempts to confuse machine-learning defenses.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Ionut Arghire: persistent cybercrime and quieter APT activity
Ransomware and extortion
Arghire expected ransomware to remain a menace to private and public organizations, including critical infrastructure, and predicted that extortion would continue. His forecast emphasized persistence rather than a decline in the threat.
APT visibility and exploit adoption
He expected Russian- and Chinese-backed groups to become less visible as their operations grew more sophisticated. At the same time, he anticipated that lesser-known APTs would adopt new exploits quickly and that at least one long-running APT campaign would be uncovered.
IoT, supply chains, and disruption of cybercrime
Arghire foresaw continued vulnerabilities in IoT devices and software supply chains, with researchers devoting more attention to supply-chain security after major attacks in 2021. He also expected security firms and law enforcement to disrupt cybercrime rings more often, but warned that adversaries might restore operations relatively quickly.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →How to interpret this 2022 outlook
The article records what its contributors expected when the year was beginning. It does not establish which forecasts came true, provide a retrospective accuracy assessment, or serve as a present-day threat assessment. Its value is as a snapshot of the risks and industry questions SecurityWeek’s contributors identified at the start of 2022.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

