Security professionals brace for a new wave of emerging cybersecurity threats

Issue 4 2023 Editor's Choice, Information Security, News & Events

Security professionals have their jobs cut out for them, with 74% saying their organisation’s sensitive data was potentially compromised or breached in the last year, according to Forrester.

New research from Forrester shows the percentage of external attacks remained constant, with a slight (2%) increase in internal incidents. However, the firm says while security and risk leaders, including chief information security officers (CISOs), continue to battle existing threats, the rise of generative AI tools, geopolitical threats, and increased cloud complexity are forcing security teams to change the way they defend against these emerging threats.

Forrester’s recently published report, Top Cybersecurity Threats in 2023, explores the top five established and emerging cybersecurity threats organisations will face in 2023 and offers recommendations for defending against each of them.

“Cybersecurity threats continue to plague organisations, multiplying like Mogwai in the 1984 hit movie ‘Gremlins’ (just don’t feed them after midnight). Forrester data shows that almost three-quarters of organisations reported one or more data breaches in the past 12 months,” writes Brian Wrozek, Forrester Principal Analyst and lead author of the report.

Established and emerging threats vie for CISOs’ attention

Forrester’s report highlights the tug-of-war faced by security professionals, saying security teams have to remain vigilant against known threats while still making sure to carve out time to address new threats stemming from emerging technologies. 

The firm believes the top threats of 2023 will be a combination of old and new ones. The top two established threats include:

1. The continued growth of ransomware. The report points out that ransomware remains a key concern although the company says it has evolved. Today, bad actors are doubly extorting their victims, demanding money to prevent the leaking of the stolen data as well as the ransom to decrypt files.

2. The human elements of BEC remaining unaddressed. Business email compromise (BEC) is the combination of social engineering with email and phishing tactics. Forrester warns that although email security technology continues to advance, technology alone is insufficient. The firm points out that the human element in security has either been dismissed or “limited to compliance-driven, outdated, and confusing security awareness and training programmes.”

When it comes to emerging threats, Forrester says that what used to be considered tomorrow’s threats are quickly becoming today’s headaches for security leaders. It has pegged the top three emerging security threats in 2023 as:

1. AI deployments. The power of applications such as ChatGPT is raising concern that bad actors could poison data to alter the outcomes of algorithms. Forrester says this will undermine AI’s reliability and performance. Since so much of our current cybersecurity relies on machine learning and AI for detection, this poses a real and immediate issue.

2. Cloud computing. The growing reach and complexity of cloud environments, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) computing, means misconfigurations and ineffective security controls will lead to more data compromises.

5. Geopolitical uncertainty. Forrester points out that the war in Ukraine shows no signs of abating. The firm adds that this hybrid war ─ involving both the cyber and physical realms ─ sets the tone for future escalations. As such, public and private organisations should prepare for increased threats.

Security isn’t a cost centre, it’s a revenue necessity

Looking at practical ways to help CISOs address these and other emerging threats, Forrester has suggested the closer examination of three externalities for security leaders to protect their budgets from macroeconomic headwinds. In a new report, CISOs Tactics to Win Every Budget Battle, Forrester’s methodology demonstrates how cybersecurity spending directly impacts revenue.

“CISOs already know that cybersecurity is a core competency of their businesses. Other executive leaders may not. This is often in part because security leaders failed to highlight how many externalities force security spending. Those externalities include customers, cyber insurers, and regulators,” writes Jeff Pollard, Forrester VP and Principal Analyst and co-author of the report.

Forrester experts say that when the externalities have been identified, CISOs can begin collecting the information that will help them to overcome budgetary pressures. CISOs will then be better able to prove that cybersecurity is the cost of doing business. Forrester’s Pollard adds, “Cost of sale (CoS) and cost of goods sold (CoGS) do not factor in cybersecurity costs, and CISOs need to change that.”

The Forrester methodology is aimed at helping deliver hard evidence of how cybersecurity spending directly impacts revenue. More particularly, it can assist security leaders in defending their security budgets to the board, C-suite, and other stakeholders, while also ensuring they are adequately equipped to face the rapid growth of new and emerging cybersecurity threats.


Security leaders looking to better understand the new emerging security threats as well as the methodology to help them secure the budget needed to fight them should contact Joan Osterloh ([email protected]), Forrester’s authorised Research Partner for South and East Africa.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...
Amendments to the Private Security Industry Regulations
Technews Publishing Agriculture (Industry) News & Events Associations
SANSEA, SASA, National Security Forum, CEO, TAPSOSA, and LASA oppose recently published Amendments to the Private Security Industry Regulations regarding firearms.

Read more...
A passport to offline backups
SMART Security Solutions Technews Publishing Editor's Choice Infrastructure Smart Home Automation
SMART Security Solutions tested a 6 TB WD My Passport and found it is much more than simply another portable hard drive when considering the free security software the company includes with the device.

Read more...
Navigating the complexities of privileged access management
Editor's Choice Access Control & Identity Management
Privileged Access Management and Identity Access Management are critical pillars of modern cybersecurity, designed to secure access to sensitive resources, enforce principles like least privilege, and implement just-in-time access controls.

Read more...
The impact of GenAI on cybersecurity
Sophos News & Events Information Security
Sophos survey finds that 89% of IT leaders worry GenAI flaws could negatively impact their organisation’s cybersecurity strategies, with 87% of respondents stating they were concerned about a resulting lack of cybersecurity accountability.

Read more...
Rewriting the rules of reputation
Technews Publishing Editor's Choice Security Services & Risk Management
Public Relations is more crucial than ever in the generative AI and LLMs age. AI-driven search engines no longer just scan social media or reviews, they prioritise authoritative, editorial content.

Read more...
Efficient, future-proof estate security and management
Technews Publishing ElementC Solutions Duxbury Networking Fang Fences & Guards Secutel Technologies OneSpace Technologies DeepAlert SMART Security Solutions Editor's Choice Information Security Security Services & Risk Management Residential Estate (Industry) AI & Data Analytics IoT & Automation
In February this year, SMART Security Solutions travelled to Cape Town to experience the unbelievable experience of a city where potholes are fixed, and traffic lights work; and to host the Cape Town SMART Estate Security Conference 2025.

Read more...
Historic Collaboration cuts ATM Bombings by 30%
Online Intelligence Editor's Choice News & Events Security Services & Risk Management
Project Big-Bang, a collaborative industry-wide task team, has successfully reduced ATM bombings in South Africa by 30,7% during the predetermined measurement period of November, December and January 2024/5.

Read more...
World-first safe K9 training for drug detection
Technews Publishing SMART Security Solutions Editor's Choice News & Events Security Services & Risk Management Government and Parastatal (Industry)
The Braveheart Bio-Dog Academy recently announced the results of its scientific research into training dogs to accurately detect drugs and explosives without harming either the dogs or their handlers.

Read more...