Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
Accountability and Liability Will Influence Cybersecurity Planning
By James Mignacca, CEO of Cavelo, an attack surface management technology company
IT and security predictions used to be (and still can be) driven by sensationalism. But they can also serve a greater practical purpose by providing IT and security leaders with insights and observations that support better decision making when it comes to cybersecurity programs. The big theme affecting all companies and security teams this year was economic instability. In terms of predictions, expect next year’s trends to hone in on operational planning that minimizes spend while maximizing value.
1. MSPs will continue to consolidate – Shifting liability trends and the continued skills shortage is driving more companies to MSP support. There is a fine line between MSP and MDR providers. Ultimately, MSPs are leveling up in terms of their sophistication and the capabilities they provide to meet growing customer demand.
2. Compliance will drive technology purchases – Compliance is an ongoing challenge and compliance stakeholders are looking for tools to help them manage it. Today’s market offers lots of compliance visualization platforms. While many of the platforms available are helping stakeholders set up policies and align to various frameworks, they don’t provide real-time prompts (or any prompts) to direct team efforts and help companies execute compliance activities – there’s still more manual lift involved than stakeholders would like. Regulatory compliance is not going away, nor will it become leaner. Compliance is non-negotiable for all companies. All companies need to move beyond just checking a box, to demonstrating how they’re checking the box. It’s the difference between doing nothing and doing something. Compliance capabilities will drive technology purchases, but it’s a buyer beware situation: compliance shops are popping up everywhere, but many offer policy management and don’t do remediation. We expect that compliance platforms will become a hub to serve accountability, with spokes and prompts that trigger time-sensitive requirements like security audits and awareness training.
3. Accountability will become a key InfoSec buying driving – Compliance has created accountability cause and effect. If there’s a breach and it’s proven that there’s non-compliance, regulators will pursue individual accountability, as we’ve seen in recent and well publicized cases. I predict that fiduciary duty will evolve to where a CISO’s fiduciary and criminally liable duty will set precedence for what happens later, altering breach liability. Downstream we’ll see this shift reflected in things like cyber insurance and third-party audits. CISOs will double down on these initiatives purely to support accountability and the idea of available evidence in a potential court scenario. This will radically change the risk landscape and what company perception of risk management looks like.
4. Cyber insurance requirements will force companies to get creative – Increasing payouts have pushed providers to revise issuance and renewal policies, making it harder for companies to secure a policy in the first place. Expect to see many providers develop different tiers of insurance based on company sizes. We may also see the introduction of captive groups specifically in specialized verticals like financial services that form based on very little or a no claims approach. Cyber insurance is like a parachute, a last defense in a remediation or recovery scenario – there’s no guarantee a provider will pay out a claim in the event of a breach. Like compliance, policy issuance can come down to a company’s ability to check the box versus demonstrating preventative controls to mitigate breach risk.
##
ABOUT THE AUTHOR
James is a serial entrepreneur and life-long technology enthusiast with more than 20 years’ experience in the cybersecurity industry. He’s a champion of data protection and data privacy, and supports businesses as they navigate digital transformation, cybersecurity and regulatory compliance requirements.






