The Cyber Security Review | Wednesday, November 23, 2022
Deloitte's leading analysts recently spoke with VentureBeat to share their top strategic cybersecurity predictions for 2023.
FREMONT, CA:Cybersecurity is difficult. Uber (NYSE: UBER), Cisco (NASDAQ: CSCO), Twilio (NYSE: TWLO), Rockstar Games (NASDAQ: TTWO), and other companies have all had data breaches as a result of cyberattacks in recent months. Leading Deloitte experts recently shared their top strategic cybersecurity forecasts for 2023 in a conversation with VentureBeat.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The forecasts made by Deloitte's analysts cover a wide range of topics, including how crucial organisational resilience, future-ready preparation, and cybersecurity will be for businesses to effectively manage their exposure to threat actors in the future.
Board Cybersecurity Readiness Will Become Business Imperative
The role board of directors play in cyber risk supervision is becoming more and more crucial as the cyber threat landscape develops and becomes more complex. The board can assist in positioning cyber as a strategic enabler to develop deeper relationships among customers, vendors, employees, and shareholders as firms prioritise consumer trust alongside ongoing growth.
Boards can more efficiently supervise cybersecurity risk management efforts by being aware of the benefit of a strong cybersecurity posture on financial impact. Recent SEC suggestions that strongly emphasise strategy, governance, risk management, and timely investor communication should urge executives to think about reshaping their present and future business models with cyber risk and the board at the forefront of these activities.
Connected Device Visibility and Security
Over the years, most enterprises have adopted IoT-connected devices, but frequently without proper security governance. The attack surface for the networks and ecosystems to which they are connected also expands as the number of connected devices increases, posing exponentially more hazards to security, data, and privacy.
Leading companies will prioritise connected device cyber practises in the upcoming year by establishing or updating pertinent policies and procedures, updating inventories of their IoT-connected devices, monitoring and patching devices, enhancing device procurement and disposal procedures with security in mind, integrating IoT and IT networks, and monitoring connected devices more closely to further secure those endpoints, manage vulnerabilities, and respond to incidents.
Security in Emerging Technologies Will be Critical in their Adoption
As IoT, Blockchain, 5G, quantum, and other technology applications grow more widespread, cybersecurity concerns related to these technologies are also becoming more developed.
The management of an organisation's strategic growth efforts will be greatly aided by adopting these technologies, but the organisation's ability to navigate and implement the necessary technological security measures will determine how successful they are in the long run.
Data-centric Security and Privacy Will Become Imperative to Building Brand and Customer Trust
Nearly 72 per cent of an organisation's customer engagements are digital, making digital engagement between businesses and customers a new way of life. Customers now expect to have more control over their data and enhanced openness regarding firms' policies.
Customers now expect more control over their data and greater transparency about the organisation's data handling rules, frequently in exchange for a greater willingness to contribute more data and become more engaged with the business.
As a result, enterprises have an increasing sense of urgency to facilitate trust and embrace data privacy, security, and compliance as mechanisms to support established techniques for enhancing customer experience and brand perception.
Focus of Future-forward Readiness
The previous few years have demonstrated how quickly things can change, from business priorities to industry dynamics to the geopolitical environment. This underscores the importance of being future-ready. Since change is the only thing that never changes, it gives us a chance to develop and reinvent our approaches to managing cyber risk.
There is a big possibility for enterprises to use cyber to bring additional value and competitive differentiation for their customers while preemptively tackling undiscovered dangers and threats on the horizon as a result of increased technological advancements and often shifting market trends.
Organisations must actively analyse and develop a cohesive cyber strategy to position the business to be agile enough to embrace future opportunities, whether planning for near-term market developments or complying with rising regulatory and reporting obligations.
Organisational Resilience Will Continue to be the Focus
As business continues to be digitised, businesses connect more to the global market, increasing the attack surface and the frequency and severity of disruptions. The numerous supply chain, geopolitical, environmental, and cybersecurity incidents that enterprises are currently dealing with pose a challenge to standard risk management strategies and are attracting more regulatory attention.
Organisations can use new approaches and technology to create situational awareness of emerging threats and improve their ability to respond to disruptions by leading with an integrated picture of scenarios that endanger core business operations.
Complex Supply Chain Security Risks Will Continue to Emerge
The hyperconnected global economy has forced businesses to rely significantly on their supply chains for everything from the parts that make up their physical and digital products to the services they need to carry out their daily operations.
Due to this crucial interconnectedness, supply chain security and risk transformation are essential for today's internationally connected enterprises.
A holistic approach is now needed by organisations, including moving away from point-in-time third-party evaluations and toward real-time monitoring of third-party risks and vulnerabilities in incoming packaged software and firmware components.
This can entail putting into practice cutting-edge methods for ingesting Software Bills of Materials (BOMs) and comparing the results to developing vulnerabilities, identifying risk indicators like the location of the underlying components, and making transitive relationships visible.
As a way to effectively enforce allowed third-party access to systems and data and lessen the effects of a compromised third party, organisations are concentrating on implementing and running identity and access management (IAM) and Zero Trust capabilities.
Organisations must maintain momentum in developing and maturing their supply chain security and risk transformation skills as the risks introduced into the supply chain continue to increase in complexity, scale, and frequency.
More in News