Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
Trendspotting Cybersecurity for 2024: AI Security and Security Governance
By Or Salom, Analyst at YL Ventures
The cybersecurity market is facing an unprecedented predicament. Though cyberattacks continue to grind enterprise operations to a halt, and regulations tighten around cybersecurity accountability, CISOs are buying less than before. As reported earlier this year, enterprise security budgets have entered into a prolonged period of austerity as CISOs grow increasingly cost- and ROI-conscious. This has compounded another growing trend of consolidation as security teams find themselves overwhelmed with bloated security stacks of overlapping solutions. What, then, does the cybersecurity market have in store this upcoming year?
Gazing into 2024’s cybersecurity market landscape as an early-stage investment analyst, I predict the market dominance of two particular domains. The first, GenAI security, should hardly come as a surprise. Though its risks have been discussed ad-nauseum across the cybersecurity community, current market offerings are limited to point solutions that are often too narrow in their approach. This will change in the upcoming year as security leaders gain a better grasp of the technology and its security impact, and look for more holistic solutions that can accommodate future challenges.
I expect security governance to be the second domain to dominate 2024’s market. While also extensively discussed within the community, it remains severely underserved, and one of the few greenfield cybersecurity categories with the potential to grow into something massive.
Ongoing confusion around AI Security
Since the sensational launch of ChatGPT last year and similar tools, the cybersecurity world has been inundated with speculations over their security implications. The pervasive influence of AI has transformed all facets of enterprise operations thanks to an array of productivity tools that offer direct AI engagement, AI-infused applications that help developers to create their own ML models and the integration of open-source AI models within developers’ code.
Massive adoption of GenAI tools has raised critical questions over data security, intellectual property rights and the technology’s potential for opening corridors to new forms of adversarial attacks. Initially, many enterprises completely banned the use of GenAI tools as they lacked the means to introduce and enforce necessary guardrails to protect against these risks. However, this will not be sustainable for companies looking to obtain the competitive advantage GenAI tools provide.
Security leaders will have no choice but to adopt official policies and solutions for GenAI, and we can expect this to happen relatively soon. In any case, most are tech enthusiasts more interested in embracing new capabilities than hindering enterprise productivity. Though they are still in the early stages of understanding the full extent of risk GenAI can introduce to their environments, and also still learning about the intricacies of the technology itself, their adoption of GenAI security is only a matter of time. Opportunistic entrepreneurs are counting on this, a number of interesting GenAI security startups have already launched over the past year. Many more are sure to come, and we can expect this field to gain a great deal of traction in the upcoming year.
Growing Demand for Robust Security Governance
Enterprise environments are growing ever-more complex, requiring more people and departments, as well as more specialized technologies and processes, to manage resulting gaps. Governing and orchestrating all of these different considerations is an extraordinary task growing more complicated by the day. This is made even more difficult by the need to often involve additional stakeholders, such as R&D, IT, and DevOps.
Additionally, each domain requires a great deal of expertise, which has often led to security solutions that are marketed as full-fledged platforms when they would be better categorized as features. Paired with efforts to keep up with rapidly evolving threat landscapes in an era of rapid digitization, this has contributed to highly complex and bulky security stacks that are difficult to manage and measure. They are also difficult to use effectively. This is why, despite deploying an average of nearly 70 of security tools, enterprise security teams still struggle with basic visibility, remediation and security management across most cyber domains.
When we surveyed CISOs about their biggest priorities, they overwhelmingly selected cybersecurity governance as a domain they are still willing to invest in despite down market conditions. Indeed, at least part of this desire may be informed by the resource constraints imposed by today’s market conditions. Security leaders are looking to make the most of what they already have and rid themselves of redundant solutions, rather than acquire new solutions for old problems. Growing regulatory compliance needs that demand transparency and accountability are further motivating CISOs to adopt new solutions and processes for better governance.
A healthy roster of companies have already made inroads in security governance, but demand for a different approach remains. Earlier this year, our research revealed that GRC tops the list of cybersecurity domains CISOs are still looking to invest in. They have been vocal for some time about their need for a single, overarching solution that can provide visibility and governance over security stacks to help them achieve better operationability.
2024 Will Prove an Interesting Year
This past year, which was challenging for the entire tech sector, gave the cybersecurity industry an opportunity to further prove its resilience and indispensability. Though the market landscape is changing, cyber threats remain omnipresent, and protection against them remains a C-Suite priority. The introduction of new technology and desire for consolidation present exciting opportunities for newcomers in 2024. Like all investors, I will be keeping a very close watch on what’s ahead.
##
ABOUT THE AUTHOR
Or Salom, Analyst at YL Ventures, sources and evaluates new investment opportunities, conducts market-focused analyses on the cybersecurity industry and works with the firm’s early-stage portfolio companies on research and product development. With 10 years of research and analysis experience in the cybersecurity space, Or spearheads strategic research initiatives to identify emerging cybersecurity avenues and monitor macro and micro-level trends in the market. She supports the firm’s portfolio companies in expanding their reach and accelerating their growth through close collaboration and project involvement, including helping with ideation, market validation and lead generation initiatives.
Prior to YL Ventures, Or honed her skills as a Senior Threat Hunting Expert at Syngia, where she performed ongoing forensic and incident response investigations. Previously, she worked as a cybersecurity analyst at PerimeterX (merged with HUMAN) and CloudLock (acquired by Cisco).
Or served as a cyber analyst in Unit 8200, an elite intelligence unit of the Israeli Defense Forces. In her role, she performed research on networks and gained extensive knowledge of cyber operations. She also served as a training commander for cyber analysts.





