Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
BYOD and Nation-State Threats Mount, Time to Face Realities of Regulations and ZTNA
By Aaron Kiemele, CISO of Jamf
2023 has been a year characterized by innovation, economic struggles and increasingly complex threats for the cybersecurity community. And while most cyber professionals know at this point to expect the unexpected, as we head into 2024, let’s take a look at which technical threats are most likely to rear their ugly heads as well as some reality checks the new year may have in store.
Prediction 1 – This Year Cybersecurity Becomes Everyone’s Job
In 2024, cybersecurity will increasingly be viewed as an organization-wide responsibility rather than just an IT function. More boards and executive leadership teams will recognize that siloed security programs are ineffective against modern threats.
End user awareness and training will also expand to encompass a broader knowledge of cyber security risks, expanding on our shared security responsibilities by building “human firewalls” and teaching and training employees how to identify and report potential security issues.
Ultimately, a resilient cybersecurity posture in 2024 will require buy-in across departments, not just IT staff. By elevating cyber hygiene as a collective responsibility, organizations can empower employees as a critical last line of defense. And with leadership prioritizing cyber resilience from the top-down, businesses can continue thriving despite the ubiquitous presence of cyber risks.
Prediction 2 – Mobile Security Gets Serious as BYOD Risks Mount
The mobile landscape in 2024 will continue to expand, with more organizations adopting bring-your-own-device (BYOD) policies and employees using their personal smartphones and tablets for work purposes. While convenient, this expanded permitter comes with significant cybersecurity risks if not managed properly.
In 2024, we predict that mobile threats will become even more sophisticated. Cybercriminals will leverage more advanced phishing techniques specially crafted to evade detection on the smaller screens of mobile devices. Social engineering aimed at mobile users will also increase, taking advantage of the casual attitude many have towards security on their personal devices.
Organizations can no longer afford to ignore or minimize mobile security in 2024. Every mobile device accessing business data needs to be secured, whether corporate-issued or personally-owned. Security teams will need to reassess their mobile fleet’s cyber risk and implement controls to protect against network infiltration, data leakage, and device-based threats.
Ultimately, 2024 will be the year where a “mobile-first” mentality must also mean “security-first” when it comes to mobile devices. The consequences of even a single compromised mobile device could result in a major breach impacting the entire organization.
Prediction 3 – Nation State Cyber Threats Cast a Wider Net
In 2024, cybersecurity teams will need to be extra vigilant about nation state threats. Major elections taking place across the world as well as the continued conflict in Ukraine and Israel will drive increased cyber attacks from state-sponsored groups.
Advanced persistent threat (APT) groups linked to foreign governments will expand their targets beyond large organizations in critical infrastructure or sensitive industries. Smaller businesses in the supply chain or partner ecosystem will increasingly be attacked as vectors to the true targets.
Collaboration, management, and cloud tools used by smaller suppliers will be attractive targets for nation state actors. These tools hold sensitive data and access that could provide an easy pathway for lateral movement towards a larger primary target.
Organizations of all sizes will need to ensure they are not the weak link that allows adversaries access to their partners and customers. Cybersecurity teams should expand their protection, detection, and response capabilities with nation state campaigns in mind. Partnering closely with governments and information sharing organizations will also be key to identify and defend against threats early.
Ultimately, the APT landscape in 2024 will be highly complex. But with robust preparation and cooperation, organizations can develop appropriate resilience against even significant nation state capabilities.
Prediction 4 – Navigating the Patchwork of Cybersecurity Regulations in 2024
In 2024, organizations will continue to face a complex and evolving regulatory environment for cybersecurity. Governments worldwide recognize the economic and national security risks of cyber threats and will respond with expanded laws and compliance mandates.
However, the impact will vary by region. In the U.S., industry-specific cybersecurity regulations will continue to be implemented at the state rather than federal level. While not as stringent as some global regulations, threats like ransomware will push more states to follow New York’s model requiring minimum security standards.
In contrast, European and APAC countries are likely to see expanded nationwide cybersecurity compliance requirements. Organizations in those regions will need to commit resources to meet the new regulatory bar for technology, staffing, and reporting.
While compliance does not equal security, it will push more organizations to reduce their cyber risk. Smart security teams in 2024 will view compliance as an opportunity, not just a checkbox. By embracing a compliance-driven culture and using standards as a baseline, they can build cyber resilience while also meeting regulatory obligations.
Prediction 5 – Zero Trust Finally Becomes a Reality
In 2024, organizations will move beyond just talking about zero trust and start implementing concrete zero trust architectures. The threats landscape will continue to rapidly evolve, making legacy trust models ineffective. Zero trust principles of least privilege access, continuous authentication, and strict inspection will become critical.
Technological advances will make actual zero trust deployments more feasible across complex environments. Capabilities like passkey authentication and granular user activity monitoring will address key zero trust pillars around identity and behavior. Cloud-based zero trust access brokers will simplify the secure access model.
The zero trust journey will still remain a multi-year process for most in 2024. But organizations will recognize they can no longer wait years before beginning. Starting with high-risk users or systems, they will operationalize zero trust to gain real-time visibility and control. With standards and best practices maturing, zero trust implementations will accelerate across the industry.
##
ABOUT THE AUTHOR
Aaron Kiemele, CISSP, CDPSE, PMP has an MBA in Technology Management and is the Chief Information Security Officer (CISO) at Jamf. With 20 years of experience his background spans a number of industries, with a focus on operational security, risk governance, and compliance.






