Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
Past mistakes can save the future: Where security leaders should invest in 2024
By Katie Teitler-Santullo, Senior Cybersecurity Strategist at Axonius
Security teams are under tremendous pressure to protect against and mitigate cyberthreats, which are only growing in number and sophistication. One of the most common stressors security teams face is managing new technology in their organization and understanding how it affects their attack surface.
Managing the attack surface is multifaceted, but a foundational step is learning everything that comprises the attack surface, including deployed technology and the vulnerabilities related to them. While it’s unrealistic to expect security teams to triage every vulnerability that crosses into their business’ landscape, it is possible to quickly react to and mitigate a breach. Doing so means that security teams mustunderstand what vulnerabilities exist in the ecosystem, which assets have been or might be affected by a vulnerability, and the potential impact to business should a vulnerability be exploited.
2024 will be a year where companies are defined by their ability to react to a breach, rather than prevent it. As the new SEC cybersecurity regulations have shown, companies will be under a microscope and must be diligent in the way they report a breach and its repercussions. Companies that can confidently demonstrate that they are prepared to handle a cyber incident will be in the best position to survive, especially in the eyes of investors and key stakeholders.
So how do businesses do this and where should CIOs and CISOs focus in 2024?
See the full picture with observability and visibility tools
In a perfect world, security teams could prevent cyber incidents rather than having to react and respond to them. Because full prevention is an unattainable goal, organizations should at least be able to quickly identify any compromise and prioritize remediation. A major element of this effort is investing in observability and visibility strategies and tools that help security teams quickly pinpoint the root cause of an incident.
Doing so effectively starts with knowing the full extent of the organization’s tech landscape – knowing all technology assets present in the organization’s attack surface (both active and dormant), what software each device is running, how devices are interconnected, if known vulnerabilities exist, who/what is authorized to access devices/systems, and much more. Teams must be able to quickly identify the weakest points of a system, the most critical devices to protect, and any downstream business impacts of an attack.
From there, teams can learn from mistakes and oversights, allowing them to write rules for earlier detection or for preventing a repeat attack altogether in the future.
Cyber resiliency is key
Many organizations mistakenly believe that having prevention structures and response plans in place are all they need to be prepared for when threat actors strike. However, no one knows how they’ll fare during the stress and chaos of a cyber incident unless they’ve built a good response plan and tested it repeatedly.
Shutting down the business due to a cyber attack is a catastrophic event. And it should therefore be avoided whenever possible. So, while observability and visibility tools are critical, CISOs and CIOs must also invest time into cyber resiliency exercises focused on business continuity and disaster recovery. This ensures the whole organization is ready to keep operations moving and restore IT infrastructure during and following an incident. Regularly scheduled tabletop exercises give organizations the ability to refine their response time and remediate compromised infrastructure, thus reducing operational downtime. These exercises are also a valuable way to practice how teams should react to the emotion and stress of cyber incidents.
Past mistakes can save the future
2024 will be a period of emphasis on response more than prevention. Knowing this, companies must prioritize observability and visibility to understand their attack surface, including the entirety of the tech stack and how assets work together. Once that baseline knowledge is set, they can then engage in cyber resiliency protocols and training to ensure attacks are handled well and quickly to minimize both technological and reputational damage. Ultimately, CISOs and CIOs should set their teams up to learn from past mistakes and prepare for the future as we enter into 2024.
##
ABOUT THE AUTHOR
Katie Teitler is a Senior Cybersecurity Strategist at Axonius, working on platform and product messaging for the product marketing team. She is also a co-host on the popular podcast, Enterprise Security Weekly.





