Ethical Hacking: The future between challenges and emerging solutions

Ethical Hacking per contrastare gli attacchi informatici

Information and Communication Technology (ICT) is the pillar upon which crucial sectors like finance rest, amplifying the efficiency of the internal market. However, increasing digitalization and interconnection lead to an increase in ICT risk. This is where ethical hacking comes into play.

The rise of artificial intelligence in hacking

Among the emerging trends in the cybercrime landscape, the integration of artificial intelligence (AI) into attack methodologies stands out in a worrying way. The future of cybercrime will likely see more targeted, personalized, and difficult-to-predict attacks, orchestrated by constantly evolving artificial intelligence.

Artificial intelligence is revolutionizing cybercrime, offering attackers increasingly sophisticated tools:

  • Machine learning algorithms can be employed to analyze large volumes of data in order to identify vulnerabilities with unprecedented speed.
  • AI-generated phishing emails and deepfakes make it harder to distinguish attacks.
  • AI-based malware bypasses traditional detection systems more easily; polymorphic malware could be developed that is capable of evading traditional security solutions.

The increasing accessibility of these technologies means that not only nation-states, but also less organized criminals can exploit AI for malicious purposes.

The growing threat of supply chain attacks

Another critical frontier is represented by the escalation of supply chain attacks. A single point of compromise can affect multiple organizations simultaneously, creating systemic risks. Modern organizations operate within complex ecosystems, interconnected with numerous ICT service providers, often considered critical ICT third-party service providers.

This interdependence creates a wide attack surface: by compromising a single supplier, attackers can potentially access a vast network of customers. The concentration of ICT services among a limited number of critical third-party providers further amplifies systemic risk, making national mechanisms insufficient to quantify, qualify, and repair the consequences of an ICT incident.

The future will in all likelihood see an increase in sophisticated attacks that aim to exploit vulnerabilities present in this intricate supply chain.

The integration between the physical and digital worlds

The Internet of Things (IoT), industrial control systems (ICS), and critical infrastructure are becoming attractive targets, with potential consequences that go far beyond data loss, potentially causing significant physical damage and large-scale disruption.

These systems, often less protected than traditional IT environments, are prime targets for:

  • Disruption of essential services (energy, transport, healthcare).
  • Cyber-espionage and theft of sensitive data.
  • Attacks with physical impact (e.g., sabotage of industrial plants).

Ethical Hacking: countering future risks for organizations

Emerging trends in cybercrime outline a future fraught with unprecedented risks for organizations of all sizes and sectors. The increase in ICT risk, amplified by digitalization and interconnection, makes the financial system particularly vulnerable. Financial stability and market integrity depend intrinsically on the digital operational resilience of financial entities.

The growing dependence on ICT services provided by third parties, including intra-group ones, introduces further layers of complexity and vulnerability. Although the provision of ICT services within a financial group may present specific advantages and risks, it should not automatically be considered less risky than that provided by external entities and, therefore, should be subject to the same regulatory framework. The concentration of ICT among critical third-party providers poses significant challenges for financial supervisors, who often lack adequate tools to assess and mitigate the risks arising from incidents affecting such providers.

Resilience and ICT risk management

In the context of the financial sector, cyber-attack propagators tend to pursue direct financial gains at the source, exposing entities to significant consequences. Preventing such events requires a holistic approach that integrates ICT risk management with overall business strategies.

The top management of organizations must take a central and active role in guiding and adapting the ICT risk management framework and the overall digital operational resilience strategy. The approach of top management must not be limited to ensuring the resilience of ICT systems, but must extend to people and processes, through policies that promote strong awareness of cyber risks and a commitment to rigorous cyber hygiene at all corporate levels. The ultimate responsibility for an entity’s ICT risk management lies with its management body.

To effectively address future threats, organizations must develop a solid, comprehensive, and well-documented ICT risk management framework as an integral part of their overall risk management system. It must include the ICT strategies, policies, procedures, protocols, and tools necessary to adequately protect all information and ICT assets, including software, hardware, servers, as well as relevant physical components and infrastructure.

Furthermore, financial entities should be encouraged to exchange information and intelligence on cyber threats among themselves, collectively leveraging their knowledge and practical experience at the strategic, tactical, and operational levels. The creation of mechanisms at the Union level for voluntary information-sharing agreements, conducted in trusted environments, would help the financial sector community to collectively prevent and respond to cyber threats.

The role of Ethical Hacking in the future of security

Ethical hacking conducted by a specialized team emerges as an indispensable component of a proactive security strategy. By simulating real-world cyberattacks in a controlled environment, ethical hackers can identify vulnerabilities and weaknesses in an organization’s defenses before malicious actors can exploit them.

Ethical Hacking: Beyond traditional Penetration Testing

Although traditional penetration testing remains a valuable technique for security assessment, the evolution of the threat landscape requires the adoption of more advanced methodologies such as Threat-Led Penetration Testing (TLPT). TLPT goes beyond simple vulnerability identification; it leverages threat intelligence to create realistic attack scenarios based on the tactics, techniques, and procedures (TTPs) of known threat actors. This approach allows organizations to test their resilience against the specific threats they are most likely to face in the future.

As highlighted in the article on TLPT, this advanced form of ethical hacking uses threat intelligence to simulate realistic attacks, focusing on credibility and maximizing the effectiveness of the tests. Ethical hacking, particularly with TLPT, often involves deeper analysis and exploration of potential attack vectors, including zero-day vulnerabilities and custom exploits.

The importance of Threat Intelligence in Ethical Hacking

Threat intelligence plays a crucial role in modern ethical hacking practices. It provides the context and realism necessary to make security tests truly effective. By understanding the motivations, capabilities, and TTPs of potential adversaries, ethical hackers can:

  • Develop realistic attack scenarios.
  • Improve reconnaissance activities: threat intelligence offers valuable information on potential targets, attack vectors, and publicly available data (OSINT) that malicious actors might use.
  • Improve vulnerability assessment: understanding current attack trends can help ethical hackers prioritize the research and exploitation of the most relevant vulnerabilities.
  • Share actionable information: the results of threat intelligence-based ethical hacking exercises provide valuable information for internal security teams to strengthen defenses and improve incident response capabilities.

Shared information and continuous learning in ethical hacking

The future of cybersecurity depends heavily on collaboration and the sharing of threat information. Financial entities are encouraged to exchange threat intelligence to improve their collective defense capabilities. Ethical hackers can contribute to this information sharing by documenting their findings, including TTPs observed during simulations, and sharing anonymized insights with the wider security community.

Furthermore, the rapidly evolving nature of cyber threats requires continuous learning and adaptation for ethical hackers. Staying up-to-date on the latest attack techniques, vulnerabilities, and security trends is crucial for conducting effective and realistic security assessments. Investing in ethical hacking training is vital to equip security teams with the skills and knowledge necessary to defend against future threats.

Audit and continuous monitoring

Regular internal audits of the ICT risk management framework are essential to ensure its effectiveness. These should be conducted by professionals with sufficient knowledge and experience in ICT risk. The conclusions of these audits should guide a formal follow-up process, including the timely verification and remediation of critical findings.

Continuous monitoring of systems and networks is equally crucial for detecting and responding to cyber threats. Insights gained from ethical hacking exercises can inform the development of more effective monitoring rules and alerting mechanisms. Integrating audit log analysis with other security information, such as vulnerability scan data and system monitoring information, can further improve the ability to identify suspicious activity. To learn more about how these activities translate into more effective ICT incident management, it is useful to examine cases where ethical hacking and operational response are concretely integrated.

Threat Hunting

Threat hunting represents a proactive approach to cyber defense that complements traditional security measures: it involves actively searching organizational systems for indicators of compromise and detecting threats that have evaded existing controls. Knowledge of attacker TTPs gained through ethical hacking simulations is invaluable for developing effective threat hunting strategies. Threat hunting teams can leverage threat intelligence and even create new intelligence based on their findings, which can then be shared with the wider security community.


To navigate this challenging horizon, a paradigm shift from reactive security measures to a proactive, resilience-focused approach is essential. Ethical hacking, in its advanced forms such as Threat-Led Penetration Testing, represents a cornerstone of this proactive strategy. By simulating realistic attacks based on threat intelligence and adversary TTPs, ethical hackers provide valuable insights into an organization’s vulnerabilities and its ability to withstand future cyber threats.

Moving forward, organizations must recognize that investing in ethical hacking capabilities is not merely an expense, but a crucial investment for their future security and operational continuity. By embracing a proactive security mindset and leveraging the expertise of ethical hackers, organizations can better prepare for the cyber threats of tomorrow and build a more secure and resilient digital future for all.

Frequently asked questions about ethical hacking and future threats

  • What is the difference between a traditional penetration test and Threat-Led Penetration Testing (TLPT)?
  • A traditional penetration test checks for known vulnerabilities following a predefined perimeter. TLPT, on the other hand, starts from real threat intelligence to build attack scenarios modeled on the tactics of specific adversaries, testing the organization’s ability to detect and respond to concrete, not just theoretical, threats.
  • Which organizations should use ethical hacking?
  • Any organization that handles sensitive data, critical infrastructure, or digital services aimed at third parties should consider ethical hacking as part of its security program. The financial sector, in particular, is subject to regulatory requirements that make these tests not only advisable but often mandatory.
  • How often should ethical hacking exercises be conducted?
  • There is no universal frequency: it depends on the complexity of the infrastructure, the speed at which it evolves, and the organization’s risk profile. In general, at least an annual cycle is advisable, supplemented by targeted tests whenever significant changes are introduced to systems, applications, or third-party suppliers.

Protect your organisation with Ethical Hacking.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert