Gartner unveiled the top cybersecurity trends for 2024, including the impact of generative artificial intelligence (genAI), boardroom communication gaps, human risks, third-party security risks, continuous threat exposure and identity-first approaches to security.
Generative AI: A double-edged sword
Gartner recommends security leaders prepare for the swift evolution of genAI, as large language models (LLMs) applications including ChatGPT and Gemini are only the beginning of its disruption.
“GenAI is occupying significant headspace of security leaders as another challenge to manage, but also offers an opportunity to harness its capabilities to augment security at an operational level,” Gartner Senior Director Analyst Richard Addiscott said in a statement.
The firm emphasizes the need for security leaders to engage proactively with business stakeholders to ensure the ethical, safe, and secure use of genAI technologies.
On the other hand, many leaders are overwhelmed by the various promises of this emerging technology including productivity increases, skills gap reductions and other new benefits for cybersecurity. Addiscott noted the firm has seen many demos of genAI deployment in security operations and application security that show real promise.
“There’s solid long-term hope for the technology, but right now we’re more likely to experience prompt fatigue than two-digit productivity growth Things will improve, so encourage experiments and manage expectations, especially outside of the security team.”
Bridging the boardroom communication gap
The rising frequency and impact of cybersecurity incidents have eroded the confidence of boards and executives in existing cybersecurity strategies, Gartner noted.
That’s why outcome-driven metrics (ODMs) become key to bridge the gap between security teams and the boardroom. More organizations have adopted the metrics to enable stakeholders to draw a straight line between cybersecurity investment and the delivered protection levels it generates.
It also helps create a defensible cybersecurity investment strategy, reflect agreed protection levels with powerful properties and explain security investment and outcomes with non-IT executives in simple language.
“This provides a credible and defensible expression of risk appetite that supports direct investment to change protection levels,” Gartner wrote.
Meanwhile, the new security disclosure rules from the Securities and Exchange Commission also push for narrowing the gap and require public enterprises to describe the board of directors’ oversight of risks from cybersecurity threats and management’s role and expertise in assessing and managing material risks.
Gartner last year predicted by 2026, 70% of boards will include at least one member with cybersecurity expertise.
Prioritizing identity and access management
As organizations increasingly adopt an identity-first security approach, they shift their focus from network security and other traditional controls to identity access management (IAM), Gartner pointed out.
The security practices should evolve to prioritize fundamental hygiene and hardening of systems to improve resilience. Gartner urges security leaders to strengthen their identity fabric and leverage identity threat detection and response to ensure IAM capabilities.
More cybersecurity trends in 2024
Gartner noted that security behavior and culture programs (SBCPs) have gained traction to reduce human risks, as security leaders shift focuses from increasing awareness to fostering behavioral change. The firm expected half of large enterprise chief information security officer (CISO) will adopt human-centric security design practices to minimize cybersecurity-induced friction and maximize control adoption by 2027.
Gartner also acknowledged the trends including the adoption of resilience-driven, resource-efficient third-party cybersecurity risk management and continuous threat exposure management programs gaining momentum.
Comments