Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
What to Expect in 2024: Cybersecurity Predictions from Extortion from Historical Data Breaches to Deep Fakes in the Presidential Election
By Claude Mandy, Chief Evangelist – Symmetry Systems
Looking back on this past year, the cybersecurity industry experienced a series of highs and lows. The innovation and hype from generative AI brought forth unprecedented increase in use of AI and hopes for superpowered productivity, but raised significant concerns around data security and AI-powered cyberattacks. There was also an alarming increase in the volume and sophistication of ransom attacks, but modern data security tools to proactively prevent these attacks also became more sophisticated.
As we look ahead into the new year, it is clear some of these trends will not be slowing down any time soon. AI innovation is still on the rise, and extortion attacks will likely still increase, while more cybersecurity teams will implement AI powered “co-pilots” to enable on-demand security input at scale. This coming year also brings about security concerns around the presidential election, with the looming threat of deep fakes spreading disinformation and targeted social engineering attacks. Here we explore some of these topics further and what we expect to see in the cyber industry in 2024.
Through 2024, there will be a significant increase in attempted extortion attempts that are proven to utilize aggregated data from previous breaches.
It is well known that cybercriminals have collected and are selling vast amounts of data aggregated from previous data breaches. It is seemingly inevitable that cybercriminals will look at other ways to monetize this collection of data, and we expect to see more and more attempts to extort money from these historical data breaches. It is hard for organizations without the appropriate data breach investigation and response capabilities to quickly determine the veracity of compromised data, when confronted with an extortion attempt.
On the surface, the data may appear to originate from the organization and is indicative of a breach, but the data may not necessarily be from a current event, but patched together from multiple prior breaches. With imminent SEC rules putting greater pressure on organizations to disclose suspected material breaches quickly, organizations will be under pressure to verify the compromise quickly, to be able to hopefully refute the attacker claims or be forced to disclose suspected material incidents. We’ve already seen attackers attempt to weaponize the SEC rules by whistleblowing on failures to disclose incidents.
By the end of 2024, a Large Language Model will be named in at least one forensic incident response report – due to the LLM’s use in a large-scale cybersecurity incident.
It’s not surprising to predict that generative AI and large language models (LLMs) will be utilized by cybercriminals and nation states to augment their existing attacks and information operations, but we expect that at least on forensic incident responder will go the extra step to determine which LLM was used to make the content and material (including voice and video) appear more legitimate. It seems likely that this will end up in a public disclosure at some point.
By the end of 2024, there will be a concerted effort among vendors to address potential misuse by cybercriminals through identity proofing, threat intelligence capabilities and reduction of free tier capabilities.
Recognizing the overlap of criminal misuse with the benign applications of LLMs, particularly in tasks like drafting emails or generating content, vendors will explore multiple strategies to prevent malicious use by implementing robust identity proofing measures, integration of threat intelligence capabilities and reduction of free tier capabilities. These measures will focus primarily on trying to discern malicious users, rather than malicious usage.
During 2024, Cybersecurity teams will begin to create dedicated roles to curate, mature and constantly improve the response from AI-powered co-pilots.
Cybersecurity teams have already recognized the value that AI powered “co-pilots” can bring to organization’s by enabling on-demand security input at scale. With this comes a critical need for dedicated roles within their cybersecurity teams to curate, mature and constantly improve the responses from these large language models LLM’s. Without this curation, it seems inevitable that a response from an LLM will be blamed for a vulnerability and resultant breach, that “should” have been addressed by a more manual process.
During 2024, the US will see a proliferation of Deep Fakes in the lead-up to the Presidential Elections.
In the run-up to the U.S. elections in 2024, the deployment of deep fake technology by nation-states and threat actors will become increasingly sophisticated, marking a concerning evolution in cyber warfare and disinformation campaigns. Deep fakes will be weaponized not only for influencing public opinion but also for more insidious purposes, including espionage, impersonation, and targeted social engineering attacks. Social Media platforms will be under pressure to control disinformation campaigns better than they have in the past.
As seen in years past, 2024 will likely bring about a lot of changes – both positive and negative. Cybersecurity teams should keep sights on these predictions, and prepare accordingly to ensure the safety of their organizations. A new year provides a great opportunity for organizations to look within their systems and ensure they have the right tools implemented to secure their digital futures.
##
ABOUT THE AUTHOR
Claude Mandy is Chief Evangelist for Data Security at Symmetry Systems, where he focuses on innovation, industry engagement and leads efforts to evolve how modern data security is viewed and used in the industry. Prior to Symmetry, he spent 3 years at Gartner as a senior director, analyst covering a variety of topics across security, risk management and privacy. Prior to Gartner, Mr. Mandy was the global Chief Information Security Officer at QBE Insurance – one of the world’s top 20 general insurance and reinsurance companies. Prior to QBE, Claude held a number of senior risk and security leadership roles at the Commonwealth Bank of Australia and KPMG Namibia and South Africa.






