Gartner this week released its top cybersecurity predictions for 2023-2024 at the Gartner Security & Risk Management Summit, highlighting the importance of adapting security strategies and chief information security officer (CISO) roles in the face of evolving threats and employee behavior.

The analysts forecast that half of CISOs will adopt human-centric design for their security programs by 2027 to minimize operational friction and maximize control adoption. This approach prioritizes the individual over technology, threat, or location as a recent Gartner research showed that over 90% of employees admitted they knowingly engage in unsecured actions, despite being aware of the risks.

Additionally, Gartner also expects three-quarters of employees to acquire, modify, or create technology beyond IT's visibility by 2027, increasing from 41% in 2022. This trend underscores the need for a shift in the CISO role from control owners to risk-decision facilitators.

Gartner analysts recommended organizations “think beyond technology and automation to deeply engage with employees to influence decision making and ensure they have the appropriate knowledge to do in an informed way.”

The analysis firm also saw zero trust gaining momentum. It predicts 10% of large enterprises will have implemented comprehensive, mature, and measurable zero-trust programs, compared to 1% today.

It noted a successful zero-trust deployment requires integration and configuration of multiple components, presenting technical and complex challenges and highly depending on the translation to business value.

“Starting small, an ever-evolving zero-trust mindset makes it easier to better grasp the benefits of a program and manage some of the complexity one step at a time,” analysts wrote.

Other Gartner’s key predictions include the following:

  • By 2025, nearly half of the cybersecurity leaders will change jobs, with 25% shifting to entirely different roles due to multiple work-related stressors.
  • By 2025, 50% of cybersecurity leaders will have unsuccessfully tried to use cyber risk quantification to drive enterprise decision-making.
  • By 2024, modern privacy regulation will cover the majority of consumer data, but less than 10% of organizations will successfully use privacy as a competitive advantage.
  • By 2026, 70% of boards will include at least one member with cybersecurity expertise.
  • By 2026, over 60% of threat detection, investigation, and response (TDIR) capabilities will use exposure management data to validate and prioritize detected threats, which significantly jumped from less than 5% today.

“There’s no question that CISOs and their teams must be laser-focused on what’s happening today to ensure their organizations are as secure as possible,” Richard Addiscott, senior director analyst, said at the summit. “But they also need to make time to look up from their daily challenges and scan the horizon to see what’s coming down the track that might impact their security programs in the next couple of years.