Opens in a new tab
vmblog logo 2024 wht (updated)

Spera Security 2024 Predictions: "CISO" will stand for Chief Identity Security Officer

Share: 

David Marshall | Published: November 16, 2023
VMblog Predictions 2024

 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

“CISO” will stand for Chief Identity Security Officer

By Dor Fledel, CEO of Spera Security

Over the past several years, following the digital revolution, rampant cloud use and remote work environments, identity-based attacks have become the leading attack vectors for malicious actors. Recent analysis from the CrowdStrike Overwatch team indicates that eight out of ten (80%) breaches leverage stolen or compromised identities, underlining the fact that a shift must take place within security teams and executive decision-makers regarding their preparedness for such attacks. In 2024, we foresee that identity will remain the top attack vector and that organizations will put more effort into solving the identity security issue.

Traditionally, identity security was one of several tasks placed under the responsibility of the IT or Information Security teams, along with infrastructure security (GCP, AWS and others), application security (O365, Salesforce and others) and many other duties and functions. This understandable overload of tasks, threats and risks led to growing gaps in the top attack vector today – identity.

Many organizations using traditional security methods that are not specifically focused on the identity threat may rely on outdated metrics that are acutely incompatible with the needs, size and agility of modern enterprises – not to mention their level of risk. These metrics, derived from manual audits and including rigid password rotation policies and others, have done little to stem identity-based breaches and attacks, leaving enterprises vulnerable to this constantly growing risk. In 2024, we expect to see security leaders and business executives requiring cross-organizational collaboration in mitigating these risks, including joint processes involving security, IT and business owners to continuously validate the organization’s identity security status and remediate as needed.

Instead of laborious, time-consuming and outdated manual processes, organizations will begin adopting quantitative approaches to measuring risk and ensuring compliance in identity security with well-defined metrics. These will ultimately become the expected norm as auditors, company boards and insurers come to terms with the unique and all-encompassing characteristics of the identity threat and will begin assessing organizations accordingly. 

High-profile identity-based cyber attacks from the past year, such as the MGM, Okta and 23andMe recent breaches, have drawn attention to the gaps in identity security. Looking ahead, we foresee that enterprises will build dedicated identity security teams that will specifically focus on metrics directly related to the reduction of identity-based cyberattacks and breaches. These will most likely include the quantifiable reduction of attack surfaces, overprovisioned accounts and MFA coverage, which will allow enterprises to accurately gauge their cybersecurity risks. In the future, organizations that have not yet measured their identity attack surface or embedded specific processes in their security strategy to do so will see an uptick in these metrics and will gain an alarming view of their identity security status. Those who will set an actionable visibility and risk reduction plan and begin implementing it will most likely see significant improvement in their security metrics, especially with gaps that are considered ‘low-hanging fruit’ that were neglected over time. Existing security tools will try to adapt and provide a partial solution to identity gaps. However, these tools were not originally designed to do so or to be identity-focused, and may only provide a false sense of security that might lead to even more breaches and organizational complexities.

Identity-first vendors such as Spera Security will continue providing tailored identity security solutions to these teams. We have seen the Identity and Access Management space grow significantly in the past five years in terms of the number of security professionals and in the number and size of funding rounds of new startups in this space. We believe that this trend will continue in the near future, with identity teams collaborating more closely with security teams to find the appropriate solution based on the organization’s maturity. We foresee a rapid evolution in the market as organizations become increasingly more educated on their identity needs and the available approaches for the prevention and remediation of identity threats. Most importantly, enterprises will raise the bar on vendor identity security hygiene, requiring the entire market to address the growing vendor risks in access and identity. 

##

ABOUT THE AUTHOR

Dor Fledel 

Dor Fledel, CEO and co-founder of Spera Security, the industry leader in Identity Security, is a seasoned identity security veteran with over 12 years of experience in Unit 8200, Israel’s elite military intelligence unit, and at Google Cloud Security. He also holds an MBA from the University of Chicago, and an M.Sc in Cryptography from Tel Aviv University. At Spera, Dor leads a remarkable team of experts who have built the first Identity Security solution helping security professionals detect, prioritize, and remediate identity-driven breaches and take control of their identity and access sprawl.