Opens in a new tab
vmblog logo 2024 wht (updated)

BigID 2024 Predictions: Cybersecurity Threats to Expect in 2024 And How to Prepare for It

Share: 

David Marshall | Published: December 5, 2023
VMblog Predictions 2024

 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

Cybersecurity Threats to Expect in 2024 And How to Prepare for It

By Tyler Young, CISO of BigID

Hard to believe that 2024 is right around the corner. As we wrap up 2023, here are my predictions for the top security challenges we will face across any industries in 2024 and the top things IT leaders can do in any field to prepare for those challenges.

2024 & Beyond

There isn’t any bigger impact to our society than the advent of AI and that is no different in cybersecurity.  In 2024 and beyond, we can anticipate there will be a rise in polymorphic malware, a sophisticated form of malware developed using AI. This type of malware is particularly concerning because it has the ability to learn and adapt to the security systems it encounters. After analyzing and understanding these security defenses, the malware can then discreetly infiltrate and spread within these systems, often evading detection by standard security measures.

The second biggest cybersecurity challenge IT leaders will continue to face is the increase in data breaches caused by employees’ negligent behavior. This often involves the improper handling or sharing of sensitive and confidential business information. Without realizing it, employees might inadvertently expose these confidential data through various means, such as mishandling emails, utilizing unsecured networks, or falling prey to phishing scams. This kind of data breach can be especially damaging as it involves internal access and may lead to the unauthorized disclosure of critical business secrets or personal data of customers and employees.

Both of these trends underscore the need for more robust cybersecurity strategies.

However, there are important steps IT leaders can take now to be better prepared for tomorrow’s threats.

Leverage Threat Intelligence

The most important thing security leaders can do- regardless of the industry-  is leverage Threat Intelligence data to deeply understand upcoming geopolitics and cyber related chatter and how this may impact them. Cyber criminals and nation state attackers begin to make moves (spinning up infrastructure, registering domains, 5 year plans, etc.) that may be correlated and detected by leveraging the right amount of threat research and data.

As the age old saying goes,  you can’t protect what you don’t know.  If you are able to leverage threat intelligence data and understand what these bad actors are chatting about on the Dark web, trends on attacking a specific industry, OR identify domains being registered similar to yours that may be used for phishing, you will be more likely to protect your organization.

Most Data Breaches Lead Back to Human Vulnerabilities

Another critical thing security leaders can do is understand their current security posture gaps and make plans to incrementally solve for them.  Oftentimes security leaders make elaborate plans to implement new technologies vs. taking a security posture (risks) approach and doing the little things like patching or upgrading systems that lead to compromises.

Typically attackers will leverage compromised passwords (usually stolen by human risk factors) or vulnerabilities in the technologies organizations deploy.  If you can decouple passwords (passwordless) or force strict password policies you can lessen the probability of this being the source of compromise.  Same with vulnerability and patching, we have seen time and time again unpatched systems be the source of compromise.  My biggest advice to IT leaders is to patch your systems, set a policy to drive updates, and get all of your organization onboard! 

Get the Little Things Right!

While the laundry list of what IT leaders need to prioritize to keep their organization safe varies and changes from organization to organization, it’s so important to do the little things right.  Time and time again breaches happen because of simple mistakes.

Correctly managing these fundamental aspects can significantly help IT leaders mitigate the risk of security breaches and establish a more secure and resilient organizational environment. This approach underscores the notion that in the complex and constantly evolving field of cybersecurity, the basics are not just foundational but are also critically important.

##

ABOUT THE AUTHOR

tyler young 

As Chief Information Security Officer at BigID, Tyler is responsible for the development and implementation of BigID’s security strategy (Cyber and Product Security), as well as developing security use cases for BigID’s products. He also serves as a Board Member on CDO Magazine, Glilot Capital, GTM Capital, Blumberg Capital, Merlin Capital and Team 8’s Security Advisory Boards, as well as an advisor for several early-stage Security startups (Axiom, Cider Security, Cyclops, & Tencyle).  Before joining BigID, Tyler served as the Head of Security at Relativity, building out Relativity’s security program, Calder7. He also held positions as Global Forensics Manager, Digital Forensics Incident Response consultant, as well as leading internal incident response investigations. He gained a variety of cybersecurity and strategy experience from Relativity, Zurich Insurance, RSM, Arete IR, and a government agency.