{"id":2281,"date":"2023-12-29T14:00:00","date_gmt":"2023-12-29T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions"},"modified":"2023-12-29T14:00:00","modified_gmt":"2023-12-29T14:00:00","slug":"i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/12\/29\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions\/","title":{"rendered":"I Securely Resolve: CISOs, IT Security Leaders Share 2024 Resolutions"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltb094fa86dc0c3de7\/65850af0eed7b0040b757863\/newyear-cn0ra-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With the aim of fortifying defenses and navigating changing risks, IT security leaders shared their New Year&#8217;s resolutions, with a focus on their planned initiatives and strategic objectives to bolster organizational security posture.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The New Year&#8217;s resolutions discussed by CISOs and security leaders for 2024 shed light on a multifaceted approach to shoring up cybersecurity practices as the evolving impact from artificial intelligence and generative AI loom over the industry.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An emphasis on the importance of assessing and updating business continuity, disaster recovery, and incident response plans is often coupled with a strong focus on fundamental detection, prevention, and response capabilities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Other resolutions highlighted the need for building a robust security culture amid evolving technologies and regulatory landscapes, emphasizing the risks associated with human error and AI-driven attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These resolutions collectively underscore the imperative for proactive measures, operational enhancements, and reactive capabilities, mirroring a comprehensive approach to cyber resilience as we head into 2024.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Justin Dellportas, CISO, Syniverse<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">My top three New Year&#8217;s resolutions for improving cybersecurity resilience are centered around assessing business continuity, disaster recovery [BC\/DR], and incident response [IR] plans; keeping these plans updated and practiced at their appropriate intervals; and continuing to focus on the detection, prevention, and response fundamentals.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s important to understand the business&#8217; critical products and processes, be able to model out potentially disruptive scenarios, and determine if the organization&#8217;s BC\/DR and IR plans sufficiently mitigate the associated risks. This isn&#8217;t something that can be accomplished in a vacuum by a cyber program alone, so establishing a strong partnership and having a presence with the executive leadership team is crucial to success. Formulating a cross-functional risk committee is a great way to get started. Underpinning all of this is ensuring there is a solid foundation of detective, preventative, and responsive cyber capabilities and processes. Building on top of that, having benchmark configurations, centralized logging, and patching all can help mitigate the impact of a cyberattack.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Rinki Sethi, CISO, Bill<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In 2024, security and IT leaders have an opportunity to be proactive and make significant security improvements, including building a strong culture of security. AI and other new technologies are transforming organizations across the world while the regulatory landscape is changing and driving more scrutiny on cybersecurity programs. The risk of human error, social engineering, and lack of cyber hygiene remain top areas to focus protection efforts, and it is increasingly challenging with AI as a popular attack vector.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations must increase vigilance and diligence of AI being used by threat actors and retrain employees to watch for and report any malicious activities. Human error can be greatly reduced with proactive and preventative controls in place, having the right tools and technologies to monitor and prevent both human errors and malicious activities, whether they are internal or outside of the organization. I&#8217;m excited about the possibilities and opportunities in this space in 2024 because, if we can get it right, it will be a game changer to stop the threat actors.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Katie McCullough, CISO, Panzura<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As we embrace the New Year, organizations should adopt resolutions that not only fortify their defenses but also ensure agility and resilience. A paramount resolution is to establish mechanisms that guarantee minimal impact in the event of a security breach. This involves creating robust incident response plans and recovery strategies that can swiftly restore operations with minimal disruption. By preparing for worst-case scenarios, organizations can maintain their operational integrity and customer trust, even when faced with potentially debilitating cyber threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another critical focus should be the comprehensive identification, assessment, and resolution or acceptance of risks. This proactive approach in risk management requires continuous monitoring and evaluation of the organization&#8217;s security posture to identify potential vulnerabilities. By understanding and addressing these risks early, organizations can prevent them from evolving into serious threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Lastly, it&#8217;s essential to provide secure services that seamlessly integrate with user and business unit operations. This means designing cybersecurity measures that are robust yet user-friendly, ensuring that security protocols do not hinder productivity or user experience. By achieving this balance, organizations can maintain a secure environment that supports, rather than impedes, their business objectives.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Devin Ertel, CISO, Menlo Security<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I would begin the year by conducting a thorough risk assessment, identifying potential vulnerabilities, and strategically allocating resources to address the most pressing concerns. This proactive approach ensures that your cybersecurity strategy is not only reactive but also anticipates emerging threats, providing a solid foundation for resilience.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISOs can effectively prepare for 2024 by aligning cybersecurity strategies with organizational budgets. This involves a judicious allocation of financial resources to implement robust security measures. Striking the right balance between investment in cutting-edge technologies and ensuring the scalability and sustainability of security initiatives is paramount.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Joseph Carson, Advisory CISO, Delinea<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Continue looking at ways to move passwords into the background in the workplace. Many organizations started implementing passwordless authentication to enhance security and improve the user experience. The more we move passwords into the background and the less humans need to interact with them, the better and safer our digital world will become.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In 2024, the landscape of cybersecurity compliance is expected to evolve significantly, driven by emerging technologies, evolving threat landscapes, and changing regulatory frameworks. Privacy regulations like the GDPR and CCPA have set the stage for stricter data protection requirements. We can expect more regions and countries to adopt similar regulations, expanding the scope of compliance requirements for organizations that handle personal data.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Gareth Lindahl-Wise, CISO, Ontinue<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of my chief resolutions would be to focus on anticipating threats. There are very few genuine black swans. Build out a small number of realistic incident scenarios and, at least, do a tabletop exercise covering your ability to prevent them occurring, detect them happening, and respond to minimize impact and recover as quickly as possible.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another top resolution for the new year is a push for more engagement. Security can be an afterthought. Let your peers and leaders know what you could bring to manage security risks in common business scenarios, including acquisitions, new products or service launches, investments, market entry, or downsizing. Be relevant and we are more likely to be there.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I would advise CISOs to focus on measuring success. You probably know what bad looks like. Do you know what good looks like? What are the indicators of security success? It isn&#8217;t just the absence of bad.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It will also be important to push for a &#8220;speak up&#8221; culture. No judgment, confidential where needed, but your employees already know your weaknesses.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">John Bruns, CISO, Anomali<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cyber resilience should focus on three core areas: proactive measures, operational measures, and reactive measures. To be proactive, CISOs should be completing or updating an overall maturity assessment of their organization, updating their risk registers, and ensuring a solid two- to three-year roadmap is established for their organization. Risk register updates should result in mitigation and controls that bolster an organization&#8217;s ability to withstand a cyberattack.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">From an operational standpoint, organizations must focus on the tools, processes, and people needed to build a comprehensive detection and response strategy. My resolution for improving operations begins with continued augmentation to our log management strategy that drives better detection engineering. From basic logging to advanced and enrichment logging, we&#8217;re continuously building and tuning our detection and response processes to ensure incident mean time to respond is decreased.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To bolster reactive measures, my focus is ensuring we have &#8220;boots-on-ground&#8221; capabilities, including incident response experts, forensics capture and analysis, root cause analysis determination, and restoration capabilities such as rebuilding, patching, or deprecating affected systems.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer, AvePoint<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">AI is coming and resistance is futile. While we see the great potential AI can have to help us in our work, we must make sure that we take advantage of these technologies responsibly and securely. Considering this, security and privacy professionals must work with their IT and business counterparts to develop and implement generative AI acceptable-use policies. This should include data privacy and confidentiality, access to gen AI, and responsible use of the technology. Putting these guardrails in place is critical.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition to developing acceptable use policies, ensure that you have ongoing training for employees so that they are aware and can act responsibly. Especially given how quickly applications of AI and machine learning have impacted our work, and how quickly this technology changes, security and privacy teams need to be agile in the new year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Successful adoption of AI in a security- and privacy-centric way will be as good as the basic data governance and lifecycle management program you&#8217;ve implemented in your organization. As we say and have said for many years with regards to migration to the cloud: If you put garbage in, you&#8217;ll get garbage out. So, it&#8217;s important to clean up your data and make sure it&#8217;s properly governed before serving it up to AI on a silver platter. Otherwise, you may end up finding that security by obscurity is no longer a fallback defense.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the aim of fortifying defenses and navigating changing risks,<\/p>\n","protected":false},"author":12,"featured_media":2282,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/i-securely-resolve-cisos-it-security-leaders-share-2024-resolutions.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2281"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2281\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2282"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}