The Cyber Security Review | Wednesday, December 14, 2022
The cybersecurity and risk privacy landscape is changing fast.
FREMONT, CA: The environment of privacy and cybersecurity risks is rapidly evolving. According to several analysts' projections for 2023, firms will need to reconsider their entire approach to cybersecurity and optimise their current procedures to deal with threat actors.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The most alarming predictions: are cybersecurity workers becoming whistleblowers in response to burnout, C-level executives receiving criticism for utilising staff monitoring, and more cyber insurance companies entering the MDR market.
As businesses adopt innovative and digital strategies, they must also deal with previously unheard-of changes in the legal environment, supply networks that are still in disarray, and customer expectations.
The chief risk officer (CRO) position is becoming increasingly important, especially for non-financial companies, as businesses broaden their risk management strategies to incorporate new sources of risk and change their centre of gravity to include non-financial concerns.
However, it is insufficient for modern CROs to defend against risk's negative side, compliance, and insurance. CROs are being charged with identifying development possibilities as risk management receives more attention and becomes more prominent internally.
In this sense, risk management is an opportunity to do more business rather than a cost of doing business. As a result, the reporting structure changes, with more CROs directly reporting to the CEO.
Some organisations are resorting to technologies for electronic employee monitoring as remote and anywhere work possibilities proliferate. Whether using monitoring technology to assess employee productivity, support a return-to-office strategy, or address internal risk concerns, businesses must put privacy rights and employee experience first.
There are many potentials for disaster from a regulatory and personnel viewpoint. Therefore, organisations must be very careful in their design and implementation.
Monitoring activities may violate newly passed New York and Ontario, Canada regulations that are explicitly connected to employee monitoring and data privacy rules like the GDPR. They can anticipate an increased legislative focus on workplace surveillance problems in 2023, such as the California accountability measure that has been put forth.
In response to surveillance activities perceived as intrusive and an overreach by employers, they are also likely to see more employee protests, strikes, and mobilisation by labour unions.
Expect Three Cyber Insurers to Acquire MDR Providers
Cyber insurers will enter the MDR area with vigour, reasoning that it is preferable to offer detection and response services to the clients they insure instead of leaving it up to the clients to handle it themselves. This will carry on the pattern established by Acrisure in 2022.
MDR purchases give insurers the capacity to validate attestations, unmatched access into policyholder environments, and high-value data regarding attacker activity to improve underwriting rules.
Security leaders should consider these things before purchasing MDR from an insurer: whether they believe the insurer will invest in providing cybersecurity services like MDR; whether their insurer can assist them in stopping active attacks in progress; and how the insurer will use telemetry in underwriting, which is probably not in the buyer's favour.
An organization Will Sue an Offensive Security Tool Provider for Causing Their Breach
Post-exploitation kits like Cobalt Strike, Metasploit, Mimikatz, and many others are used by both security experts and attackers. To make sure consumers aren't abusing the technology, some providers publish disclaimers or incorporate a due diligence process into the sales process.
Enterprises and governments will pressure providers as more of these tools emerge to prevent them from falling into the wrong hands, which will change how these tools are developed and distributed.
This will result in litigation against a provider in 2023, setting a precedent that could cause other software products to get caught in the conflict, especially as emotions rise over third-party breaches. Secure the products you offer as part of the cybersecurity approach to reduce vulnerability.
A Global 500 Firm will be Exposed for Burning out its Cybersecurity Employees
Cyber defence vulnerabilities have the potential to have a significant social impact. These defences have teams that are overworked and understaffed. According to a 2022 survey, 66 per cent of security team members report severe work-related stress and 64 per cent report that this stress has negatively impacted their mental health.
Similar results were noted for incident responders, who put in long shifts than 12 hours during the initial week of an incident. The effects of burnout go far beyond mental health; they can include attrition, health hazards and even fatalities.
In significant research on the nation's infrastructure, 57 per cent of security directors listed burnout as their primary reason for quitting their jobs. A WHO study also reveals that people who work 55 hours per week are 35 per cent more likely to suffer a stroke. Additionally, there have been deaths of computer workers in China and Australia in 2022 as a result of burnout.
A security staffer will report unsafe working circumstances in 2023, continuing a long line of tech whistleblowers. Identify and address the causes of burnout, create physically and psychologically secure workplaces, and provide security teams with the resources they need to succeed.
More in News