Cybersecurity Predictions for 2023: My Reflections
Jane Frankland
Cybersecurity Influencer | Advisor | Author | Speaker | LinkedIn Top Voice | Award-Winning Security Leader | Awards Judge | UN Women UK Delegate to the UN CSW | Recognised by Wiki & UNESCO
It’s that time of year when I begin to look back and reflect. Then, predict and plan. It's the way I like to do things. I beleive like Winston Churchill did that the farther backward you look, the farther forward you are likely to see. It's why I developed the IN Focus journal and planner, which you can buy via Amazon, and works on all aspects of your life, career included.
So, having just written my predictions for cybersecurity for 2024, which will be coming to you shortly, I thought I'd look back at the ones I made for this year (for the International Security Journal (ISJ)) and discover how accurate they were. They're brief, under 600 words.
I believe my predictions were largely accurate bar those made in regard to sustainability. Regretfully, I've not seen as much change as I would have liked.
I’ll leave you to make up your mind.
My Predictions for Cybersecurity in 2023 were...
Technology enables opportunities as fast as it introduces threats. Unsurprisingly, cyberattacks and data breaches show no signs of slowing as companies invest in technology to fuel growth, enhance customer experiences, support remote and hybrid workforces, and meet ESG goals. Here are my predictions for 2023.
Types of attacks. Cyberattacks and data breaches will continue to arise because of credential theft, social engineering (phishing, smishing, vishing etc), vulnerabilities in third party software and supply chain processes, forged or stolen machine identities, and misconfigured cloud computing. Ransomware attacks will surge again, and adversaries will lean on behavioural science and seemingly legitimate ways to trick users. As the quality of these attacks increase, victims will find it increasingly hard to determine whether they are visiting trusted websites that have not been compromised and hold malicious ransomware code.
Digital transformation. Despite contracting world economies due to a few dynamics colliding (Russia’s invasion of Ukraine, high inflation, and shrinking economies), more companies will be investing in digital transformation solutions. However, as traditional company perimeters are replaced by an array of network infrastructures which include cloud technologies, remote machines and their users (employees and third parties), edge computing and Internet-of-Things (IoT) devices, threats will rise due to a larger attack surface. Nonetheless, cloud computing will continue to dominate digital transformation efforts, and many benefits will occur including enhanced data asset protection, fewer compliance failures, cyber resilience, and business productivity.
Sustainability. More companies will be focused on sustainability. As such there will be pressure to simplify technologies, re-architecture environments, and ditch single point products which become costly and as a result can negatively impact the planet. Companies will seek single-vendor cybersecurity solutions that will unify products and services, consolidate vendors, and provide significant operational efficiencies and risk reduction. They will want to see evidence of environmental, social and governance (ESG) commitments from their suppliers as consumers become more conscious when buying.
Approaches. Companies will embrace zero trust, the ‘never trust always verify’ approach. By swapping implicit trust for identity-and context-based risk appropriate trust (users, devices, and services), companies will realise greater safeguards. Early adopter companies will also be implementing a cybersecurity mesh architecture (CSMA) approach which Gartner defines as being a distributed architectural approach to scalable, flexible, and reliable cyber control, and something that will reduce the financial impact of security incidents by an average of 90%.
领英推荐
Automated technologies. As more adversaries are using modern technologies like artificial intelligence, machine learning, and automation to accelerate their attack gains, so are companies. These technologies will reduce labour intensive activities, which will help with the current skills shortage. As employees continue to be a major liability for companies, more will invest in behavioural analysis technologies to bolster their defence strategies. With analytic solutions they can leverage off machine learning, artificial intelligence, big data, and analytics to better enable risk-based authentication and authorisation, identifying uncharacteristic intended or unintended user behaviour or device activity faster, and more concisely organising incident response measures.
Skills. Competition for top talent with sought after skills will intensify. The market will still be candidate driven. Companies will have to work hard to attract and retain cybersecurity professionals especially if they want a team that includes more women. They will need a watchful eye on their mental well-being too as cyberattacks intensify and the “always on” effects of hybrid and remote working.
Now I want to hear from you...
My predictions for cybersecurity in 2024 will be released shortly. I'll have a concise version (around 500 words) coming to you via ISJ again, and a much longer version available here and on my website. In the meantime, let me know how you fared with your predictions by commenting below.
About Jane Frankland
Jane Frankland is an award-winning cybersecurity leader, author, and women’s change agent. Her authority is referenced by Wiki, LinkedIn (Top Voices) and UNESCO. She built her own global penetration testing firm in the late 90s, has worked as a Managing Director at Accenture, and contributed to numerous industry initiatives, including CREST, Cyber Essentials, and Women4Cyber. Through her IN Security Movement, 389 women have received scholarships, a value of over $500,000. She regularly shares her thought leadership and leader-developer skills with forward -thinking companies and governments, and has been featured in the Sunday Times, The Financial Times, The Guardian, Forbes and BBC. To find out more, visit https://jane-frankland.com
Cybersecurity and Data Privacy | Cybersecurity Content Creation and Strategy
1 年Are you sure you aren't Oracle? Seriously, I think the best new thing we have seen in 2023 is that more and more companies invest in human risk management, and this is something that will continue well into 2024. Other than that, I would be interested to realize how climate crisis natural disasters may affect cybersecurity strategies. Looking forward to your 2024 predictions, Jane!
CEO & Founder, e2e-assure | SOC, MDR, XDR
1 年Look pretty accurate to me Jane, looking forward to the 2024 predictions, i wonder if they will include 'AI' by any chance :)
Well said and valid
Founder, Cybersecurity Manager & School Master
1 年Wow - Impressive and very accurate predictions and insights into 2023 Jane Frankland! Especially regarding the move towards unified cybersecurity solutions and zero trust. In 2023, I noticed many companies exploring fancy solutions like Cloud Security and Zero Trust, while still missing the crucial basics though. I am actually pretty curious to see how companies will face those gaps between basic security solutions and needed baselines and advanced (but maybe more "fancy" solutions) such as Zero Trust in 2024. I share your thoughts on the sustainability aspect and hope that 2024 brings more urgency and progress in this area. Last but not least I am looking forward to your predictions regarding the geopolitical factor, which will remain a significant challenge for international companies. It's a dynamic landscape, and navigating it is crucial for a robust cybersecurity strategy. Excited to read your 2024 predictions! Your insights provide such a valuable roadmap in this ever-changing cybersecurity journey. ???? #cybersecurity #lookingahead