Opens in a new tab
vmblog logo 2024 wht (updated)

Cribl 2024 Predictions: APIs, the SEC and Data as an Asset

Share: 

David Marshall | Published: November 23, 2023
VMblog Predictions 2024

 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

APIs, the SEC and Data as an Asset

By Jackie McGuire, Senior Security Strategist at Cribl

The world of information technology (IT) and cybersecurity is constantly evolving, and 2024 is sure to be no different. With new threats and technologies emerging all the time, it can be difficult to predict what the future holds, but we’ve made a few educated guesses, based on current trends and emerging data. 

All Eyes on APIs as Volume and Complexity Explode

APIs, or Application Programming Interfaces, are a way for software applications to communicate with each other. They act as a middleman, allowing two or more applications to share data, functionality and almost everything cloud-based – from banking, to wearable medical devices, to self-driving vehicles – relies on APIs. In 2024, APIs will be both the cause of, as well as a potential answer to, several security problems, as API-associated data volume doubles.

Attacks on APIs have steadily increased this year, requiring more robust logging and analytics for monitoring and security, as well as to prevent potential abuse. I predict the data volume being produced by API transactions and management will at least double in 2024, compounding the problem many teams are already facing. Establishing and maintaining data quality and standardization will be imperative, resulting in an allocation of more budget and labor to data engineering. 

On the protection side, APIs will be an indispensable tool in helping organizations to identify gaps in their programs and visibility, establish and maintain more effective log management for their cloud-based tools, and achieve and maintain compliance with data privacy and retention standards and regulations. While this will require its own data engineering lift, we think it will ultimately make enterprises safer and look forward to seeing how the creative use of APIs shapes 2024.

The SEC Shines a Spotlight on Systemic Risk

2024 may very well become the year of dirty laundry, as a new SEC requirement that registered companies disclose material cybersecurity events within four business days lays bare just how interconnected and systemic risk in cybersecurity can be. In the few months since its passing, we have already seen several high-profile disclosures from Clorox, Johnson Controls, MGM, and Okta rile the securities markets and send teams scrambling. While breaches are nothing new, the level of disclosure the SEC is now requiring ensures that enterprises feel a level of financial pain as punishment for their security misdeeds. It also makes far more public the common threads among various breaches, be they threat actors or vendors. 

The good news here is that the SEC and cyber risk providers will likely succeed where guidelines and best practices have failed; financial punishment and shareholder angst cause changes in businesses’ security investment and behavior – fast. The reason we have seatbelt laws is because of the auto insurance industry, and security incident disclosures will likely have the same impact. As much as it shouldn’t be the case, hitting companies in the wallet is typically the best way to influence behavior, and in 2024, we think the SEC will do just that.

Data as an Asset 

In many senses, data is the new oil. It’s a finite resource that needs to be mined and managed strategically, and its value is highly dependent on your ability to refine and manipulate it for specific applications. For this reason, we see 2024 as being a critical year in the transition of data from being 1s and 0s on a screen to an actual asset to be managed, tracked, and optimized within an enterprise. 

If we look past data as the space it takes up and consider each data point (IP, port number, customer name, city name, temperature reading) as an asset in and of itself, it becomes clearer that the way we are mining and storing data is incredibly wasteful. The same data points are often collected repeatedly, stored more redundantly than necessary, and contain no single source of truth. With the increasing use of AI and machine learning, as well as more stringent regulatory requirements that both require you to hold some data longer, as well as delete some data sooner, it will become crucial that data is managed as an asset. 

To accomplish this, the accurate identification and categorization of data will be essential. We see an entire industry dedicated to data identification developing over the next few years, and companies becoming increasingly more focused on what the sole source is for any piece of information. This will ensure changes to data propagate, unexpected output from data science models can be traced to the training source, and ensure that any data that a company no longer has the right or desire to hold is actually deleted.

##

ABOUT THE AUTHOR

Jackie McGuire 

Jackie McGuire is a Senior Security Strategist at Cribl, focused on the security market. Prior to joining Cribl, Jackie was a Research Analyst with S&P Global, writing, speaking, and providing thought leadership on information security and Web3. Jackie has also worked as a data scientist in cybersecurity, developing behavior analysis and anomaly detection models, been co-founder, CEO, and CFO for several startups, and before her work in technology, was a licensed securities broker and SEC Registered Investment Advisor.