Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
Generative AI changed the game in 2023, how will organizations respond in 2024?
By Robin Moore of Mimecast
2023 went by in the blink of an eye, the world of cybersecurity is never slow or dull, but even by our industry’s standards – it was quite a busy year! Cybercriminals are evolving their techniques to become more prolific and specific, but cybersecurity innovation has never been stronger, and I feel good about our ability to stay one step ahead as we head into the new year.
This past year you couldn’t walk down the street without someone talking about generative artificial intelligence (AI) tools, specifically ChatGPT, and it seemed everyone had their take or question related to the story. One thing that isn’t in question – the technology is here to stay.
I predict that in 2024 we will see generative AI tools being used to launch higher volume and more sophisticated automated attacks against organizations and individuals. The benefit of these tools for criminals is that they can save attackers time in staging attacks by producing higher quality, individualized initial contact attempts with less human effort, i.e. texts and emails sent out with a message that will resonate with the recipient.
Responses and ongoing engagement with the victims can then be handled at a much higher volume. By removing the human element and replacing it with generative AI-supported chat agents, cybercriminals are not only more prolific, but specific too. By producing a human-like interaction, the victim stays engaged for a longer period of time, and the chat bot will stay at it until the victim drops the conversation or produces the required information or action desired by the attacker, the latter could have devastating results. Threat actors often look at cybercrime as a numbers game, the more possible targets, the better the win rate. Generative AI just made things a lot easier for them to aim at a bigger target.
Another thing I am looking out for in 2024 is the industry’s response to President Biden’s executive order on safe, secure and trustworthy AI and EU’s AI Act. These are vital legislative acts and show us how far reaching this technology goes – lightyears beyond just cybersecurity. That said, cybersecurity’s role in all of this is paramount.
I predict in 2024 we will see a large surge in tools and products being announced aimed to address many of the points in the order and act. I expect that this will emerge as a stand-alone area of the security market focusing on the secure usage of machine learning and AI with some companies such as Harmonic Security, Lakera, and a few others getting a jump start.
In addition to thoughts of my own, below is a sampling of thought leadership predictions from a few of my colleagues across the Mimecast global team.
James Lee, VP, Partners EMEA
Is 2024 the year of ICES?
As the market continues to consolidate into and around the Hyperscalers, threat actors become more focused around that infrastructure. Recently examples of record-breaking DDoS-attacks against Azure and others highlight that the “bundled” in security features from many of those vendors may not be enough. 2024 is the year that integrated cloud email security (ICES) solutions mature as an additional layer of security into software suites such as Microsoft 365, in reaction to that threat.
Jonathan Miles, Principal Threat Response Analyst
Another technology game changer – Quantum Computing
Organizations should consider the advent of quantum computing as a significant game changer. Large-scale quantum computing offers great opportunities but is coupled with a significant threat to the current global information infrastructure. While quantum computing promises unprecedented speed and power in computing, it also poses new risks.
As this technology advances over the next decade, it is expected to break some encryption methods that are widely used to protect customer data, complete business transactions, and secure communications. Modern encryption methods are specifically designed so that decoding them would take so long that they are practically unbreakable. Quantum computers change this thinking. These machines are far more powerful than classical computers and should be able to break these codes with ease. It will be no longer possible to guarantee the integrity and authenticity of transmitted information, as compromised data could go undetected.
Without quantum-safe cryptography and security, information that is transmitted on public channels now – or in the future – could be vulnerable to eavesdropping. Even encrypted data that is safe against current adversaries can be stored for later decryption once a practical quantum computer becomes available. Many cyber threat actors are now operating under the concept – “harvest now, decrypt later” – making the need to protect our data NOW all the more important.
Peter Bauer, CEO
Voice impersonation attacks?
My cybersecurity prediction for 2024 is that business email compromise attacks, which are often an interactive sequence of communications between an attacker and an unwitting employee at your company will become even more dangerous and convincing in their deception using both voice and video impersonations of people that you otherwise trust.
##
ABOUT THE AUTHOR
Robin Moore is a cybersecurity product leader passionate about innovation. He has previously held roles at the threat intelligence company Digital Shadows, as Director of Product Management, and BT where he launched their first AWS hosted B2B service platform, BT Security Cloud SIEM. He continues this trend at Mimecast where, as Principal Product Manager for AI and Machine Learning, he is helping advance the practical application of cutting edge technologies.





