Entering 2020, cybersecurity experts expected ransomware to remain the dominant threat, cloud misconfigurations to widen the attack surface, and the November election to face state-sponsored interference. What they did not predict: a pandemic forcing millions of employees home within weeks, the Maze group pioneering data theft before encryption, and a state-sponsored supply chain compromise at SolarWinds that went undetected for more than a year. By December, the pre-pandemic threat landscape had been upended. The year's defining attacks came from vectors that mainstream forecasts had not put front and center.
The World Health Organization declared COVID-19 a global health emergency on March 11, 2020. That declaration triggered the largest remote work experiment in history, expanding the enterprise attack surface far beyond anything early threat models had accounted for. Ransomware evolved into double extortion: Maze stole data before encrypting it, a method that became the dominant playbook. The SolarWinds attack began as early as September 2019 but was discovered only in December 2020, proving that software supply chain compromises could be vastly more pervasive than the industry had imagined. The US election proceeded without vote-tally attacks, though disinformation campaigns remained active.

Ransomware Tactics and Targeted Industries
Heading into 2020, experts warned that ransomware would keep hitting municipal governments, healthcare institutions, and schools: sectors with lean security budgets and punishing uptime requirements. The prediction held.
The mechanism shifted.
In late 2019, the Maze group began stealing data before encrypting it, turning a disruption event into a breach. Victims who restored from backups still faced leaked sensitive information. By mid-2020, double extortion had been adopted by multiple variants, including REvil and DoppelPaymer. Healthcare, already strained by the pandemic, became a frequent target. The move from encryption-only to data-theft-plus-extortion was not a headline item in early 2020 expert roundups. It became the defining ransomware trend of the year.
Cloud Security Misconfigurations
The shared responsibility trap
Cloud experts had long warned that misconfigured storage buckets and databases were a leading cause of data exposure. The shared responsibility model, under which the provider secures the foundation and the customer secures data and access controls, was widely discussed but poorly implemented. Teams that had little cloud security experience rushed to stand up remote access solutions, often leaving storage buckets publicly accessible or skipping multi-factor authentication. The number of cloud-related breaches reported in 2020 exceeded the 2019 total. The root issue had not changed: organizations still did not grasp that the provider secures only the platform, not the customer's data.
Remote work accelerates the mess
The pandemic's rapid migration to cloud services worsened the problem. Organizations that had relied on on-premises infrastructure suddenly found themselves dependent on cloud configurations they barely understood. Misconfigurations multiplied under the pressure of keeping operations running.
5G, IoT, and the Expanding Attack Surface
Analysts had predicted that 5G rollouts and the spread of IoT devices would expand the enterprise attack surface in 2020. The prediction was accurate in direction but underestimated the magnitude.
5G promised faster speeds and lower latency, enabling more connected devices. The safety implications were not matched by corresponding defenses. Many IoT devices shipped with hardcoded credentials, unpatched firmware, and no mechanism for automatic updates. The pandemic accelerated IoT adoption in healthcare, manufacturing, and logistics, putting more devices on networks that were not segmented for protection. The result was a larger pool of potential entry points. The threat was not new, but the scale at which it materialized exceeded early 2020 warnings.
The Cybersecurity Skills Gap and AI Defense Tools
A persistent 4-million-person hole
The (ISC)² 2019 Workforce Study estimated the global cybersecurity workforce gap at 4.07 million professionals. Experts entering 2020 expected that gap to persist and organizations to turn to AI and automation to compensate.
Between promise and deployment
AI-driven tools for threat detection, user behavior analytics, and automated incident response had been maturing, but adoption was uneven. Large enterprises with dedicated operations centers deployed AI to triage alerts and reduce false positives. Smaller organizations, the ones most squeezed by the workforce shortage, could not afford or lacked the expertise to configure these tools. The gap between the promise of AI defense and its practical deployment widened over the year. The pandemic made hiring harder, not easier: budgets froze while security teams supported a remote workforce with no additional headcount.
Key Facts
- CCPA enforcement began: July 1, 2020
- COVID-19 pandemic declared: March 11, 2020
- Global cybersecurity workforce gap (2019): 4.07 million professionals (ISC)²
- 2020 US presidential election: November 3, 2020
- 2020 RSA Conference: San Francisco, February 24-28, 2020
- Maze double extortion ransomware emerged: Late 2019
- SolarWinds attack discovered: December 2020 (activity since September 2019)
Phishing, Social Engineering, and Deepfake Concerns
The old standby gets new lures
Phishing was expected to remain the most common initial access vector in 2020, and it did. The pandemic gave attackers fresh bait: fake CDC emails, fraudulent stimulus payment sites, and COVID-19 tracking apps delivering malware. Credential phishing grew in volume as remote workers accessed corporate resources from personal devices and home networks. The shift to remote work eliminated the physical controls of the office (locked doors, supervised visitors) and replaced them with reliance on passwords and VPNs, themselves targets of phishing campaigns.
Deepfakes: noise, not signal
Experts had raised early concerns about deepfake technology, where AI-generated audio or video could impersonate executives and authorize fraudulent transfers. In 2020, deepfake attacks remained more discussed than observed. The immediate threat was the credential phish, not the deepfake call.
Regulatory Outlook After CCPA and GDPR
The California Consumer Privacy Act took effect on January 1, 2020, with enforcement beginning July 1. It followed the European Union's GDPR, in force since May 2018. Experts predicted 2020 would bring increased regulatory pressure on data collection, with more states considering similar laws and federal legislation a possibility.
The pandemic did not halt that trend, but it shifted enforcement priorities. Regulators focused on health data and contact-tracing privacy, while businesses struggled to meet CCPA's requirements for data inventory, consumer access requests, and opt-out mechanisms. By year-end, CCPA had resulted in several enforcement actions, though the full impact on business practices was not yet clear. The regulatory landscape was tilting toward tighter controls. Enforcement remained uneven and under-resourced.
Election Safety and Disinformation
The November 3, 2020, US presidential vote was expected to face cyberattacks aimed at voter registration databases, electoral infrastructure, and tallying mechanisms. Experts also warned that disinformation campaigns would intensify, using social media to spread false narratives about the electoral process.
The outcome was mixed. No significant cyberattack altered vote tallies, and electoral safeguards withstood direct interference. However, disinformation campaigns ran rampant, with false claims of fraud and hacking circulating widely before and after the vote. The threat environment experts had forecast for electoral safety was real, but the most damaging attacks were informational, not technical.
The distinction between infrastructure protection and information integrity became a central lesson of the 2020 cycle.
Critical National Infrastructure and State-Sponsored Threats
Experts had rated critical national infrastructure as inadequately prepared for state-sponsored attacks. Power grids, water utilities, and pipelines ran aging industrial control mechanisms that were not designed for connectivity, let alone active defense. In 2020, the SolarWinds attack demonstrated that state actors had shifted their focus to the software supply chain. By compromising SolarWinds' Orion monitoring software, attackers gained access to networks across government agencies, technology companies, and infrastructure operators. This was not a direct strike on control mechanisms, but it gave attackers a foothold from which such targets could be reached. The preparedness of critical infrastructure remained a concern, but the nature of the threat had changed from direct intrusion to supply chain infiltration, a vector that had not been a primary focus of expert predictions at the start of the year.
Key Events and Outcomes in Cybersecurity, 2020
| Event | Date | Impact on Threat Landscape |
|---|---|---|
| Maze ransomware adopts double extortion | Late 2019 | Data theft plus encryption became the dominant ransomware model |
| COVID-19 pandemic declared | March 11, 2020 | Mass remote work expanded attack surface beyond enterprise perimeters |
| CCPA enforcement begins | July 1, 2020 | Increased compliance burden for data collection and privacy practices |
| 2020 US presidential election | November 3, 2020 | No vote tally alteration, but disinformation campaigns persisted |
| SolarWinds attack discovered | December 2020 | Exposed widespread software supply chain compromise by state actors |
Frequently Asked Questions
Did ransomware evolve in 2020 as experts predicted?
Partially. Experts expected ransomware to remain a top threat, but the double extortion model pioneered by Maze in late 2019 became the defining tactic, which had not been widely predicted.
How did the pandemic change cybersecurity in 2020?
The pandemic forced a sudden shift to remote work, invalidating perimeter-based safety models and dramatically expanding the attack surface. This was not a scenario that pre-2020 forecasts had accounted for.
Was the SolarWinds attack predicted by experts?
No. The SolarWinds supply chain attack, discovered in December 2020, represented a level of software supply chain compromise that was not a primary focus of mainstream expert predictions for the year.
Did the 2020 US election suffer a major cyberattack?
No significant cyberattack altered vote tallies. However, disinformation campaigns about the electoral process remained active throughout the cycle.




