2021 Cyber Year in Review: Experts Weigh In
Atlantic Council experts reflect on SolarWinds, Log4Shell, and ransomware's dominance of 2021 and forecast continued ransomware risk in 2022.
This is a retrospective policy piece from the Atlantic Council's Cyber Statecraft Initiative, gathering expert commentary on the defining cybersecurity events and policies of 2021. It highlights the SolarWinds/Sunburst supply-chain espionage campaign disclosed in late 2020, the Log4Shell vulnerability disclosed in late 2021, and the surge of ransomware attacks affecting critical infrastructure (Colonial Pipeline) and food supply (JBS meat processing), which drove unprecedented public concern about cyberattacks.
Experts discuss the most impactful organizations and policies of the year, including a 17-country INTERPOL-coordinated ransomware law enforcement operation, the US Executive Order on Improving the Nation's Cybersecurity, and the Infrastructure Investment and Jobs Act's cybersecurity funding. Under-covered incidents mentioned include the Oldsmar water treatment plant intrusion attempt, NOBELIUM's exploitation of trusted cloud relationships for lateral movement (following the SolarWinds campaign), and the Howard University ransomware attack. The piece is largely a policy and trends discussion rather than a technical threat report, with consensus that ransomware will remain the dominant cybersecurity issue into 2022.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-hindsight-2021-cybersecurity-is-hard
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free