I recently hosted and moderated a distinguished panel of Chief Information Security Officers (CISOs) – Nitin Raina, CISO at ThoughtWorks, Mike Wilkes, former CISO at Marvel and Yogesh Badwe, CSO at Druva.
We discussed major trends for 2024 across an array of topics including the evolving threat landscape, recent regulations, data privacy considerations, securing product and critical infrastructure. We also discussed strategy, leadership, resilience, scapegoating CISOs, artificial intelligence(AI) and much more.
Trend #1: CISO Fallout Will Accelerate
Mike highlighted recent legal cases involving CISOs, expressing concern about the unprecedented accountability of security professionals and the potential for them to be scapegoated. He discussed cases like Joe Sullivan at Uber and Tim Brown at SolarWinds, emphasizing the SEC’s issuance of a Wells Notice for a CISO, a first in history. Mike questioned the trend of holding CISOs responsible for issues beyond their control and predicted a continued exodus of CISOs from their roles due to perceived lack of support.
Yogesh offered a contrasting view, suggesting that recent cases may serve as catalysts for elevating the role of CISOs and improving security programs. He sees a shift from viewing security as a technology problem to recognizing its real-world impact, citing examples like the Colonial Pipeline incident. Yogesh anticipates new regulatory actions prompting positive transformations in the industry, offering a silver lining to the challenges faced by CISOs.
Trend #2: Resurgence in Cyber Regulations
Trend #3: Age of Cyber-Kinetic Warfare
Trend #4: Third-Party Risk Management
Yogesh brought up the concept of shared responsibility models inspired by the practices of AWS and Amazon, emphasizing the need for a prioritized and evolving approach to third-party risk management. Mike highlighted the significance of continuous monitoring and the limitations of annual assessments. He underscored the need for default security measures and a shift in perspective towards making systems hard by default. Collectively, the panelists stressed the importance of a proactive and evolving approach to third-party risk management in the dynamic cybersecurity landscape.
Trend #5: Ransomware Continues To Dominate
Yogesh highlighted the alarming increase in ransomware incidents, citing statistics and emphasizing the evolving tactics of threat actors, such as data extortion and the targeting of uncommon areas, including SaaS apps and the cloud. He also pointed out the changing tactics of threat actors, including SEC disclosures and social engineering methods to create additional pressure on organizations.
Mike discussed the recent updates to NY DFS regulations, emphasizing the importance of rapid reporting for both ransomware detection and payment. The panel collectively underscored the severity of the ransomware threat and the evolving challenges organizations face in dealing with its multifaceted nature.
Trend #6: Digital Potato Famine
Mike suggests that the uniformity and locked ecosystem of iPhones make them susceptible to a massive, coordinated attack, resulting in a form of digital depopulation. The prediction is delivered with a mix of seriousness and humor, highlighting potential vulnerabilities in tightly controlled digital ecosystems.
Trend #7: Cyber Security Staff Development
Nitin highlighted the significance of understanding the business and effective communication as critical skills for security professionals. He mentioned a new role, the Business Information Security Officer (BISO), designed to bridge the gap between security and business, allowing security professionals to work closely with business leadership teams. Nitin encouraged organizations to explore innovative ways to mentor and grow their security staff beyond traditional methods.
Trend #8: Critical Infrastructure and Supply Chain
Yogesh reflected that understanding the components of critical infrastructure, especially when it involves OT and IoT, is a complex task due to dependencies on various vendors. President Biden’s cybersecurity memo and the increasing momentum in regulatory efforts to improve software supply chains are being adopted. The discussion touched on the importance of initiatives like Software Bill of Materials (SBOM) and the hope for greater adoption of supply chain security principles to enhance the overall security ecosystem.
Mike brought up the criticality of the maritime sector, stressing its significance in global trade and potential vulnerabilities in ships due to cyber threats. He emphasized the need to pay attention to OT risks and the large number of IoT devices with default passwords and outdated firmware, posing significant security challenges.
Trend #9: Cybersecurity Recovery “Resilience”
He urged organizations to focus on ensuring that their infrastructure is resilient, particularly in the context of remote work and changing security challenges. Closer collaboration between security teams, IT, and business operations leadership in addressing these resilience concerns were emphasized.
Trend #10: AI in Cybersecurity
Yogesh added that the challenges extend to the use of AI in various scenarios, such as remote work environments where AI-generated deep fakes could disrupt typical security processes. He emphasizes the importance of addressing security and safety concerns related to AI systems.
Nitin provided a business lens on the topic, acknowledging that AI is here to stay, and organizations are adopting AI tools and technologies. He encourages security teams to engage with the business early on, create guardrails, and partner with data protection and privacy teams to ensure responsible and secure use of AI.
The consensus among the panelists is that while AI brings significant advancements, it also introduces new challenges and risks, requiring careful consideration, guardrails, and collaboration between security teams and the broader business.
Missed the CISO Roundtable? Watch the On-Demand Recording Now!
If you missed attending the CISO roundtable, you can watch the on-demand recording here.
Let us know if you have any questions or if you need to get in touch to help you with your API Security or Application Security use cases.
Girish Bhat
The post CISO: Top 10 Trends for 2024 appeared first on Wallarm.