Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
Data Security Is Key to a Strong Cyber Defense
By Rodman Ramezanian, Global Cloud Threat Lead at Skyhigh Security
For those immersed in the cybersecurity landscape, it won’t come as news that threats are rapidly evolving and it’s becoming increasingly difficult to build impenetrable defenses. This is especially true as more hackers deploy emerging technology and use innovative tactics to exploit vulnerabilities. So how can security teams stay agile in 2024 to tackle growing challenges head-on and better protect their organizations?
First, they’ll need to understand which attack vectors are on the rise and how to strengthen their data security practices accordingly.
Secure AI to prevent data loss
As individuals and enterprises adopt artificial intelligence (AI), especially generative AI, at an unprecedented rate and its capabilities grow more sophisticated, brand-new data security challenges are coming to light. One such challenge is that it’s being leveraged on both sides of the cybersecurity fence.
Security teams are harnessing AI’s capabilities for their own defense programs – for everything from automated threat detection to faster incident response – but hackers are using it in parallel to plan and execute attacks with ease. Cybercriminals are finding seemingly endless opportunities to use AI for harm, whether to aid in social engineering attacks, like phishing campaigns or deepfakes, or to create cost-efficient malware. It’s even being used to create dossiers on organizations’ security weaknesses and generate malicious code. Unfortunately, AI is not only amplifying the impact of these attacks, but it’s making it possible for even the least technical-savvy hackers to get in on the action. Similarly, Ransomware-as-a-Service (RaaS) platforms are also contributing to a higher volume of “entry-level” attacks. To combat these external threats, security teams need to double down on data security to keep credentials and other sensitive data from being exfiltrated and make these attack vectors less effective.
While hackers are intentionally posing threats by using AI, there are less overt risks as well. For instance, more data is being transacted with these services than ever before, particularly in corporate settings. While most employees use AI in the workplace to boost efficiency, productivity, and creativity, unintentional data leaks are common. More rarely, employees purposefully misuse these tools to carry out insider threats. In 2024 and beyond, we’re likely to see more organizations rely on security platforms to gain greater visibility into the AI services being used within the enterprise, and their corresponding risk levels, so they can apply security controls and policies to prevent data loss.
Customize data protection for high-risk industries
While all organizations will face a growing number of cyber threats in 2024, industries like healthcare and financial services will remain the most exposed. These industries store and transact highly sensitive data that’s prized by cybercriminals, such as confidential patient data or financial records. Another layer of complexity is that these industries are slowly but surely embracing the cloud, AI, and hybrid work, giving hackers new opportunities to exploit security gaps amid these transitions. Other top targets in 2024 will be the perceived “weak links” along supply chains, as well as critical infrastructure domains like energy, water, and transportation.
Organizations in these sectors will need to customize their data security programs to match the threats they face, especially along their digital transformation journeys. They’ll need to prioritize gaining visibility and control over data wherever it lives, understanding the security risks associated with their applications in use, simplifying their security management, building a strong pipeline of security talent, and more.
Implement a zero trust security strategy
Finally, the movement toward zero trust architectures, built around the framework of “never trust, always verify,” will gain even more steam in 2024. Following zero trust principles requires all individuals and devices seeking access to systems to be verified irrespective of their location within or outside corporate networks. As attackers steal or intercept valid credentials on a more frequent basis to enter networks without raising alarm bells, continuous authentication will play a crucial role in ensuring hackers can’t stay undetected for long.
2024 is guaranteed to introduce a host of new security challenges. Organizations with stronger data security programs will have more success in preventing AI-powered attacks, AI misuse, and threats targeting supply chain vendors or highly vulnerable sectors like healthcare, financial services, and critical infrastructure domains. They’ll also be better prepared to comply with ever-changing data regulations and frameworks and protect their employees, data, and reputations.
##
ABOUT THE AUTHOR
Rodman Ramezanian, global cloud threat lead at Skyhigh Security, has 11+ years of extensive cybersecurity experience. Rodman specializes in the areas of Adversarial Threat Intelligence, Cyber Crime, Data Protection, and Cloud Security. He is an Australian Signals Directorate (ASD)-endorsed IRAP Assessor – currently holding CISSP, CCSP, CISA, CDPSE, Microsoft Azure, and MITRE ATT&CK CTI certifications.





