Opens in a new tab
vmblog logo 2024 wht (updated)

IDSA 2024 Predictions: Identity in 2024

Share: 

David Marshall | Published: December 13, 2023
VMblog Predictions 2024

 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

Identity in 2024

By Jeff Reich, Executive Director, Identity Defined Security Alliance (IDSA)

In 2024, expect to see more numerous and successful attacks targeting personal information under the control of a third party. The biggest risk for companies and organizations is insufficient protection and control of identity and personal information under their control. Looking at the progression of incidents over the past two years, the leaking or loss of this information is driven primarily by ransomware. Ransomware, although a significant threat, is not our biggest problem. Many organizations don’t even know what data they have across the spectrum, never mind how well they protect it.

Recent judgments by administrative courts have begun to blame issues around this on the CISOs with fines and sentences. In 2024, we will not see a significant improvement in our postures-and this problem will grow. Companies, particularly in the US, need to take stock of all the personal information they have and place appropriate controls over access to it. This will result in the normalization of higher costs for encryption, and access control, and reduced trust over how and when the right people can access this data. When an organization decides to start implementing a Zero Trust architecture, this is the place to start.

On a more positive note, 2024 should be the year that the death of the password is noticed by the masses. Between federation, passwordless functions, and the implementation of Multiple Multi-Factor Authentication, accessing more diverse systems should be easier to navigate and more secure.

It would be remiss to ignore the role that generative Artificial Intelligence (AI) will play in 2024. What started as a novelty and is considered by some to be a threat, demonstrations of beneficial AI used will be the norm and will be accepted just as personal computing, cloud computing, and mobile computing have been in the past.

##

ABOUT THE AUTHOR

Jeff Reich, Executive Director, Identity Defined Security Alliance (IDSA)

Jeff Reich 

Jeff serves as Executive Director of the IDSA. An active participant in the security community for 5 decades, Jeff is a well-known advocate for cybersecurity awareness & education. Previously, he served as VP of Member Success at Cloud Security Alliance (CSA), where he increased the capability of delivering and supporting benefits to members by 44%. The ISSA honored Jeff as a Distinguished Fellow and inducted him into the ISSA Hall of Fame in October 2015. He holds CISSP certification from (ISC)2, CRISC certification from ISACA and was granted a Foundation Certificate in IT Service Management from The Council for Service Management Education and The Information Systems Examination Board.