Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
IT Security Predictions for 2024: Navigating the Evolving Threat Landscape
By Greg Armanini, VP of Product Management at open directory platform provider JumpCloud
There’s no question that IT security continues to evolve at an ever-increasing rate. Small and medium-sized enterprises (SMEs), who could once count themselves as a lesser target for hackers, now face nearly the same frequency and sophistication of attacks as their better-funded enterprise counterparts. All IT teams, from the single IT person to those with deep domain experts are evaluating how to bolster their security posture and prepare their organizations to repel the newest kinds of attacks and prepare for what’s coming. Here are six things to keep your eye on for the coming year.
1. The Rise of Cyber Attacks and Phishing Sophistication
AI is increasingly being used by cybercriminals to enhance their attacks, and IT circles are understandably experiencing security-induced panic. Machine learning algorithms can craft more convincing phishing emails, be used to guess passwords or crack CAPTCHA, generate deepfakes, and more. The upside comes in all the ways that organizations can also deploy AI to build better cyber defenses, especially in areas of attack simulations, patch and vulnerability management, and threat and anomaly detection. Generally, given the investment in AI, I think there’s reason to be cautiously optimistic. Companies are approaching it with the right level of alarm; recent industry research suggests that the AI in the cybersecurity market is already at $22.4B in 2023, and will grow to over $60B by 2028.
2. Cybersecurity Skill Gap Crisis
Glaring skill gaps within IT teams will cause organizations to panic, as many realize they are understaffed (or not staffed at all) with people who have deep background knowledge or necessary certifications. As the threat landscape evolves, the demand for cybersecurity experts with relevant experience and knowhow will outpace the supply. This shift will force organizations to take a proactive stance in addressing these gaps, driving investment in training and talent acquisition.
3. Demand for MFA Will Explode
IT teams, especially within SMEs, will turn to external partners and vendors for help in implementing robust security measures. One area where improvement is sorely needed is Multi-Factor Authentication (MFA). Despite its promise, MFA adoption has lagged, leaving organizations exposed. Microsoft acknowledged that 99.9% of compromised user accounts don’t have MFA authorized, and only 28% of Microsoft users were using MFA as of December 2022. The MGM hack was just the most recent example of the consequences of lagging security, and no doubt drive countless security teams to figure out how to adopt MFA ASAP.
4. Passwordless Solutions in the Mainstream
Due to both low MFA adoption and inherent human weakness in the security chain, 2024 will be the year where we’ll see real movement toward passwordless solutions. The balance between security and convenience is finally at close to parity, which will accelerate consumer and business adoption. We just launched JumpCloud Go, our passwordless authentication solution in large part because we recognized that the demand side for passwordless is growing at a far faster rate than before. Expect to see that passwordless authentication methods such as biometrics and secure tokens will become both normalized and expected, and 2024 will mark a significant step towards a more secure digital environment.
5. Google’s Passkey Move and Enterprise Implications
The adoption of passkeys by Google on the consumer side has been widely lauded by IT professionals. However, there are many more discussions to be had around the broader implications for the enterprise and the industry as a whole. Organizations will need to evaluate whether integrating passkeys into their security strategies makes sense as enterprises may find they’re not ready for prime time. Irrespective of whether passkeys are enterprise ready, the industry conversation around them is another one that underscores the need for MFA, and the need for standardization and best practices.
6. Momentum in Continuous Authentication for Identity and Device Management
In 2024, traditional static methods of authentication and authorization will be supplemented by dynamic, real-time evaluation of users and devices. This approach will enhance security by constantly assessing the trustworthiness of identities and devices accessing a network or application. As cyber threats evolve, so too must our security measures, and continuous evaluation will play a pivotal role in adapting to the changing landscape.
As is always the case in security, in 2024 there will be both challenges and innovations. The increase in cyber attacks and phishing sophistication will necessitate a collective effort to bolster defenses. Acknowledging skill gaps, forming strategic partnerships, and embracing passwordless solutions will be key strategies to mitigate risks. And the shift towards passkeys and continuous evaluation will contribute to a more secure digital future and identity for all. As the threat landscape evolves, so must our security strategies, and 2024 will be a pivotal year in this ongoing battle for a safer digital world.
##
ABOUT THE AUTHOR
Greg Armanini is the VP of Product Management at open directory platform provider JumpCloud, where he leads product management for user lifecycle, device, and resource management and security. Prior to JumpCloud, Greg led identity and access management at VMWare, and product development at Yahoo!.






