The Cyber Security Review | Saturday, November 26, 2022
As 2022 ends and organisations start planning and prioritising their cybersecurity objectives and budgets for the new year, here are some thoughts on cybersecurity and what organisations can expect in future.
FREMONT, CA: Companies warn about growing threats to healthcare and the energy sector, the consolidation of security teams and technology within enterprises, as well as suggestions for proactive measures like introducing new cybersecurity laws and standards by both businesses and governments.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
As businesses look to lower risk, 2023 will witness an increase in oversight committees expressly for cybersecurity. Committees will examine cybersecurity objectively and define a set of benchmark requirements for which the company is held responsible, much like those in legal and risk management. They will be responsible for keeping an eye out for errors and providing guidance, demonstrating the general acceptance of cybersecurity as one of the top five strategic functions.
Companies will also demand more actionable data on their organisation's cybersecurity posture to guide decision-making, with security teams leveraging new and better ways to quantifiably model threat actors and defences to demonstrate to the board what security looks like.
Preventing breaches from happening won't be a reliable indicator of cyber success anymore. Cyber resilience will become an industry-recognised criterion for all firms to attain and measure against as breaches become more commonplace. In 2023, any downtime will be considered undesirable. Currently, organisations determine the effectiveness of their business continuity strategy based on whether they can recover within their recovery time objective (RTO) to their recovery point objective (RPO). Organisations will be forced to consider their risk appetite and establish an acceptable minimum level of maintainable security to avoid penalties, lost profits, or reputational damage due to stringent testing and the development of industry-wide metrics to help benchmark against peers and understand what success would be.
The present energy crisis, along with economic unpredictability and pressure to cut costs, will raise energy and healthcare to the top of attackers' target lists. Services will face attacks from both nation-state attacks and criminal gangs, as well as activist groups willing to stand up to those who continue to profit despite growing prices since they are more important than ever.
Through the growth of medical technology like pacemakers or monitoring equipment, the expansion of linked gadgets and unsecured Wi-Fi connections in healthcare environments will also allow attackers to launch more precise attacks on people inside hospitals. As a result, businesses will look for fresh approaches to prevent assaults that disrupt operations and maintain the availability of essential services.
Check Out This : Med Tech Business Review
The number of security tools in use and cybersecurity teams will likely be reduced due to the economic impact on budgets and resources. This will be especially true in the field of IT and OT security due to the need to cut the expenses of expensive proprietary OT innovations and include OT into current IT cyber policies.
Organisations will need a more unified and structured approach to cybersecurity as environments grow more interconnected, focusing on boosting visibility and monitoring to lower cyber risk. Separate IT and operational technology security teams will be unnecessary for organisations, leaving them vulnerable to even greater security risks.
With ransomware more prevalent than ever, industry and government will be obliged to address the issue at its heart. The only method to completely remove ransomware is to stop paying for it; otherwise, doing so merely serves to finance the activity. Although it is unlikely that any new legislation will be proposed in the upcoming year, companies will undoubtedly start to see talks about what this may entail and perhaps even the prototype of this produced.
Greater measures to demonstrate resilience will be needed, such as routine stress testing of IT infrastructure and incident response procedures. At the same time, cyber insurance companies will become less willing to continue paying out and will seek to strengthen policy eligibility requirements.
By 2023, the focus will be on breach containment rather than perimeter protection and selecting the most bulletproof IT infrastructure type. The industry will come to terms with the fact that breaches will always happen, and security measures will adapt to account for this. What will matter is retaining visibility throughout the entire estate, regardless of whether it is on-premises, hybrid, cloud-based, or at the edge. Organisations will need to be aware of their environment's vulnerabilities to proactively establish a policy to stop breaches in their tracks and minimise harm. Ultimately, the new resilience paradigm in 2023 will be breach containment.
More in News