Intelligent CISO Issue 71 | Page 19

cyber

TRENDS a lot to consider about its cyberdefence capabilities . In fact , 39 % of UK organisations were unable to fend off attackers and suffered a security breach as part of a cyberattack in the past 12 months .
Moreover , it was the year of understanding and establishing GenAI-based capabilities to augment security , technology and other business functions in direct support of company objectives . Yet , AI has proven to be a double-edged sword .
While it can be used to rapidly identify threat anomalies and enhance cyberdefence capabilities , Artificial Intelligence ( AI ) and Machine Learning ( ML ) can also be used by bad actors . Malicious platforms such as WormGPT , FraudGPT and DarkBERT are already being used to streamline malicious attacks with growing simplicity , so much so that nearly anyone with malicious intent can execute cyberattacks with little effort or experience .
Curtis Simpson , CISO at Armis
What ’ s more , organisations ’ overreliance on technology and the Internet of Things has contributed to their attack surface growing in both size and complexity . As the attack surface continues to grow , so does the opportunity for attackers to find a vulnerability and exploit it .
The last 12 months have also shown that prioritising the remediation of vulnerabilities is jeopardised by an absence of automation for the operational and contextual consumption of threat intelligence , leaving once more , an open door for malicious actors . With minimal automation , a lot of the work needed to make use of the intelligence sources is a manual effort , leading to one in four UK cybersecurity teams feeling overwhelmed . and reflecting on the lessons that can be gleaned from the developments of 2023 .
Lessons from the past
Renowned psychologist Dr Bill Crawford stated : “ One key to success is knowing the difference between knowledge and wisdom . One is information from the past while the other is the key to the future .” Put simply , to create a successful cybersecurity blueprint for the year ahead , we must first apply what we ’ ve learned .
And 2023 has been generous . From attacks on critical infrastructure such as the NHS and Royal Mail to retailers like JD Sports and payroll giant SD Worx being targeted , it was a year that gave the UK
To stay ahead of the threat , CISOs must now consider these hard lessons . Knowledge is power , after all .
Strategic priorities for 2024
For a CISO to successfully navigate the digital battlefield in 2024 , there are several key considerations . Firstly , the visibility of an organisation ’ s attack surface must be the top priority . It ’ s crucial to implement a security solution that allows organisations to effectively identify and prioritise emerging threats and the exposures likely to be exploited by such threats with the potential for material business impacts .
Having visibility of the entire attack surface allows organisations to be proactive in how they approach
WWW . INTELLIGENTCISO . COM 19