# Atlantic Council experts review 2022 cyber year

Published: 2022-12-14 · Severity: low · Sectors: government-national, education, telecommunications
Canonical: https://vorant.io/reports/e22062cb-cfac-5aa7-a00a-3a8b8ce9a7b1/atlantic-council-experts-review-2022-cyber-year

> A panel of policy experts reflects on 2022's cybersecurity trends, from record ransomware attacks to Russian state ties and key US policy initiatives.

This is a year-in-review policy discussion from the Atlantic Council's Cyber Statecraft Initiative, featuring commentary from congressional, industry, and academic experts on the state of cybersecurity in 2022. Key themes include the continued surge of ransomware (up 80 percent over 2021), with roughly three-quarters of ransomware revenue reportedly flowing to Russia-linked hacking groups, and evidence that Russian intelligence services have tolerated or directed some ransomware operations. The piece also highlights the cybersecurity dimensions of Russia's invasion of Ukraine, including Ukraine's SSSCIP defensive efforts and a DOJ Rule 41 operation to disrupt a GRU-orchestrated botnet.

Beyond nation-state activity, panelists discuss policy developments such as CISA's Joint Cyber Defense Collaborative, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), the EU's proposed Cyber Resilience Act, SBOM standardization, and IEC 62443 industrial security standards. Notable incidents referenced include the Log4Shell vulnerability response, the ransomware attack on Costa Rica's government, the Twilio breach, and the Vice Society ransomware attack on the Los Angeles Unified School District. The Uber CISO's criminal prosecution is cited as a watershed moment prompting industry debate on executive liability.

This article is primarily a policy retrospective and forward-looking discussion rather than a technical threat report; it contains no specific indicators of compromise, exploited vulnerabilities with CVE identifiers, or detailed TTPs, but names Vice Society as the ransomware group behind the LAUSD attack and references a GRU-linked botnet disrupted by the DOJ.

## Mentioned in this report

- Threat actors: GRU, Vice Society

Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-the-cyber-year-in-review

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e22062cb-cfac-5aa7-a00a-3a8b8ce9a7b1/atlantic-council-experts-review-2022-cyber-year.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
