In Forrester’s 2024 predictions report on cybersecurity, risk and privacy, analysts forecast the rise of the zero-trust roles, the data breaches caused by flaws in artificial intelligence- (AI-) generated code, the regulatory scrutiny on personally identifiable information (PII) handling and the changes in the cyber insurance market.

"Taking a look at some of the trends that we've seen this year, we believe [they] are going to continue into next [year], which is what fueled those predictions where we see that cyber attacks are much more targeted and much more personalized,” Forrester Senior Analyst Alla Valente told SDxCentral.

“We see a lot of trends in the use of generative AI especially for social engineering and making them much more convincing. And we see that enterprise risk levels … are continuing to increase,” she added.

Zero-trust titles will double in 2024

Currently, Forrester found 81 zero-trust positions posted on LinkedIn in the U.S., six in the U.K. and one in Singapore, and the firm expects the number to double next year.

The analysis noted the zero-trust mandates and executive orders in the U.S., finally going mainstream in Asia–Pacific (APAC) and Europe, the Middle East and Africa (EMEA), and a broader adoption of NIST’s zero-trust architecture framework drive the need for zero-trust roles in architecture, engineering, governance, strategy and leadership.

“As the year developed, we did start to see this rise in zero trust titles across the board. And especially, as we saw the zero trust mandates coming out in Asia and in India, as well as companies operationalizing the executive order in the U.S., we started to see like these titles become much more prevalent,” Valente said.

As organizations comply and operationalize these zero-trust mandates, they are starting to carve out roles that are focused on zero-trust requirements, Valente said.

Forrester recommends reviewing the requirements for a zero-trust role and identifying a cohort of individuals to pursue zero-trust certifications.

“Zero-trust response roles and responsibilities are distinct. The folks that are going to be responsible for managing those zero-trust initiatives [are] really about this balance of both the technical expertise as well as business acumen understanding. And the certifications, or at least the training, helps the transition,” Valente added.

AI-generated code blamed for at least three data breaches

Forrester noted as organizations adopt generative AI technology, governance and accountability will be key to ensuring the ethical use of AI and compliance with regulatory requirements.

“As we see generative AI becomes a bigger part of that software development process, it's not a far stretch to understand that it's going to have a hand in it and how some of those AI-generated codes could be leveraged to expose vulnerabilities but also could be responsible for some security flaws that lead to breaches,” Valente said.

Based on Forrester’s 2023 data, nearly half (49%) of business and technology professionals with knowledge of TuringBots, an AI development assistant that helps generate code and boost productivity, are piloting, implementing or have already implemented them in their organization.

However, without proper guardrails around TuringBot-generated code, the firm predicts there will be at least three data breaches next year publicly blaming insecure AI-generated code, due to security flaws in the generated code itself or vulnerabilities in AI-suggested dependencies.

Forrester suggests development teams should scan all AI-generated code for security issues.

“AI is only good as the day that it's trained on,” Valente said. “AI is going to be trained on the best practices, but it's also going to be trained on some of the practices that are, let's say, not as great.”

Forrester’s predictions on PII handling, cybersecurity insurance and the human element

The apps that use genAI platforms like ChatGPT will be under regulatory scrutiny on how they handle PII, similar to the investigations on OpenAI. Forrester expects some of these apps to bear a greater risk of fines than OpenAI, as they introduce risks via their third-party tech provider but lack the resources and expertise to mitigate them appropriately, so companies should double down on their third-party risk management.

Additionally, the firm predicts cyber insurers becoming more selective and identifying specific security technology vendors as red flags. Forrester also projects about 90% of data breaches will include a human element next year, where people are involved in error, privilege misuse, use of stolen credentials, or social engineering.