A recent report from Forrester Research outlined the top five cybersecurity threats that organizations are expected to face this year, including narrative attacks, deepfakes, artificial intelligence (AI) responses, the AI software supply chain and nation-state espionage.
Based on Forrester’s Security Survey for 2023, 78% of security decision-makers estimated their organization's sensitive data was potentially compromised or breached at least once in the past year, while half of these respondents who experienced a cyber incident estimated the cumulative cost to exceed $1 million.
“Cyberattacks have become so common that when an outage or disruption occurs, many people initially jump to the conclusion that a cyberattack must have been the root cause,” Forrester Principal Analyst Brian Wrozek said in a statement. “It is easy to see why given that the cybersecurity threat landscape has become a volatile mix of threats driven by rising uncertainty and increased complexity.”
Forrester’s Top Cybersecurity Threats In 2024 report listed five top threats creating this volatile threat landscape, including the following:
- Narrative attacks: A new twist on classic approaches to manipulate, undermine, discredit or distort a given story. Forrester noted that narrative attacks make sophisticated misinformation and disinformation campaigns spread easier and faster. It will be especially popular to use for shaping public opinion and influencing behavior as 64 countries will stage elections this year.
- Deepfakes: Since 2007, deepfakes have advanced rapidly, allowing hackers and fraudsters to use generative algorithms to create synthetic identities and audiovisually convincing likenesses of humans.
- AI responses: As generative AI (genAI) goes mainstream, prompt engineering, prompt injection and sensitive data spillage will move to the top of every security team’s threat list. These AI response risks could come from genAI applications like Microsoft Copilot and Anthropic Claude, or internally developed applications with sensitive data sets trained on enterprise data.
- The AI software supply chain: Forrester noted the attack risks targeting the integrity of AI models will remain low, but threat actors are expected to attack and exploit the software supply chain used to develop, deploy, and operate AI-powered applications and systems
- Nation-state espionage: The analyst firm found espionage was the goal of 82% of nation-state cyberattacks in 2023. It also found spy satellites are a key tool in supporting nation-state espionage, warning enterprises of cyberattacks used against satellite technologies and the supply chain surrounding them.
“Uncertainty generated by narrative attacks, deepfakes, and AI responses make it difficult to separate fact from fiction. The AI software supply chain and nation-state espionage risks add additional layers of complexity to an already convoluted threat environment. Organizations need to gain visibility into these top five threats and start taking actions to mitigate the impact of them,” Wrozek said.
Deepfakes causing disruptionForrester pointed out the deepfake surge is driven by easy access to inexpensive computing power, generative algorithms such as generative adversarial networks (GANs) and autoencoders, and the popularity of mobile apps that can transform a user’s image.
It warns that targeted enterprises can suffer harmful outcomes, including fraud, ransomware execution, data and IP loss, stock-price manipulation, reputation and brand damage, decreased employee and customer experience, and amplification of misinformation.
To counter deepfakes, the report recommends using algorithms to detect manipulated images and audio, controlling media sources through authentication, wrapping facial and voice biometrics with additional verification and protection layers, conducting deepfake tabletop exercises, and increasing employee awareness.
Defending the AI supply chainThe analyst firm found 71% of organizations have experimented with genAI to improve their productivity. Open-source models and frameworks can benefit the accelerated feature enhancement and transparency of security controls, but are subject to next-generation software supply chain attacks and exploits of software vulnerabilities, Forrester warns.
The report urges a collaborative approach among representatives from security, IT, architecture, AI/data science, development and the business to gain visibility into current AI usage, integration plans, and potential gaps.
Other recommendations include not solving the AI software supply chain problem solely through mandates or overly restrictive policies, but by using software bills of materials, implementing security best practices such as least privilege access, and adhering to AI security development guidelines from international agencies.
Comments