Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
The Evolution of Cybersecurity in 2024: A Shift Towards Human-Centric Defense
By Tom Marsland
In the fast-paced realm of cybersecurity, every year brings new challenges, innovations, and trends that shape the industry’s landscape. As we peer into the not-so-distant future of 2024, it is evident that the cybersecurity field is undergoing a transformation. While technology and tools have been the central focus of the industry for many years, I predict the the coming year will herald a notable shift in perspective and will highlight the growing recognition of people being a crucial component of cyber defense, the maturation of secure software development practices, and the increasing prevalence of software bill of materials (SBOMs) and automation.
1. People as a Vital Component of Cyber Defense
In 2024, I anticipate a substantial shift in the cybersecurity industry towards recognizing that people are just as integral to effective defense as the latest technological solutions. With the increasing sophistication of cyber threats, human error and lack of training remains a significant vulnerability. Consequently, organizations are expected to invest more in training, awareness, and behavioral analytics to strengthen their security posture. Building a cyber-aware culture within an organization will be paramount in preventing breaches and data leaks.
Moreover, the importance of hands-on, practical, team-based training will take center stage. One of the key ways to develop and enhance the human element of cybersecurity will be through immersive experiences provided by TRUE cyber range networks. These networks offer a realistic, controlled environment for cybersecurity professionals to hone their skills, respond to dynamic simulated cyberattacks, and work collaboratively to strengthen their incident response strategies.
Crucially, TRUE cyber range networks will prioritize having live subject matter experts to facilitate these trainings. These experts will not only provide guidance but also help participants understand the real-world implications of their actions. This hands-on, mentorship-driven approach will bridge the gap between theoretical knowledge and practical application.
2. Maturation of Secure Software Development Practices
As cyberattacks become more frequent and sophisticated, the importance of secure software development practices will reach a new level of recognition in 2024. The industry will place greater emphasis on proactive security measures, ensuring that security is baked into the software development process from the outset. This will involve integrating security into DevOps and Agile methodologies, incorporating threat modeling, code reviews, and continuous vulnerability assessments.
By maturing these practices, organizations will be better equipped to prevent security vulnerabilities from creeping into their software, significantly reducing the attack surface for cybercriminals. This shift towards proactive security measures will ultimately save time, resources, and reputational damage in the long run.
Organizations like the Linux Foundation, and more specifically, the OpenSSF, have made strides in this area around secure software development in the open source community, and I look to them as leaders in that space as the industry rapidly grows to embrace AI-based tools as well.
3. The Rise of Software Bill of Materials and Automation
In 2024, we predict a surge in the adoption of Software Bills of Materials (SBOMs) and automation in the cybersecurity landscape. An SBOM is a comprehensive list of all software components and dependencies within an application. This transparency allows organizations to understand potential vulnerabilities and respond swiftly to emerging threats.
Automation, particularly in the context of threat detection and response, will become a game-changer. Cybersecurity tools leveraging AI and machine learning will be instrumental in identifying and mitigating threats in real-time, ensuring that cybersecurity professionals can focus on strategic decision-making rather than routine tasks.
Closing Thoughts
As we step into 2024, the cybersecurity industry is poised for significant changes. The shift towards recognizing the human element in cybersecurity, the maturation of secure software development practices, and the proliferation of SBOMs and automation will redefine the way we defend against cyber threats. While technology remains crucial, the industry is acknowledging that effective cybersecurity is a synergy between people, processes, and tools. The coming year promises to be an exciting and transformative one for the cybersecurity world as it adapts to the evolving threat landscape, embraces a more holistic approach to safeguarding our digital assets, and focuses more on the human aspect of cybersecurity.
##
ABOUT THE AUTHOR
Tom Marsland
Tom Marsland is a cybersecurity professional with over 20 years of experience in the information technology and nuclear power industry. He’s served over 20 years in the US Navy and earned his bachelor’s in IT security and his master’s in cybersecurity. As the VP of Technology and Technical Services for Cloud Range, he is responsible for all aspects of the Cloud Range technology stack and product offerings from a technical perspective and oversees training operations. He also serves as the Board Chairman of VetSec, a 501c3 not-for-profit organization that seeks to help veterans find meaningful employment in cybersecurity.






