2023 Tech Predictions

In 2023, organizations will continue to digitally transform their businesses, a process accelerated due to the global COVID-19 pandemic requiring workers to work from anywhere and with almost any new application hosted in the cloud. These initiatives will continue to drive the adoption of a software-defined wide-area network approach underpinned by Internet connectivity.

With this proliferation of cloud and applications, the need for higher bandwidths will continue, and technologies like 5G, and eventually 6G, will provide alternatives allowing for optimum business connectivity.

With the evolution of the global workforce and hybrid cloud deployments, end users need to access business applications from anywhere at any time, while IT staff must mitigate the exposure of cyberattacks. Cybercriminals are monitoring updates on company websites as to which offices have closed, matching them to the LinkedIn profiles of employees working from home to target them. This scenario is going to harm companies that have been slow to adopt a Secure Access Service Edge framework, including Zero Trust

Despite these challenges, the coming year will equip IT teams with new tools and strategies to counteract the expanding threat landscape. Here are a few predictions for 2023.

Security Will Move To The Endpoint

A ransomware attack can enter an enterprise through any small crack in your defence and laterally spread everywhere within minutes. A lot of organizations miss that, because they have implemented a Virtual Private Network or an Endpoint Detection & Response solution, and mistakenly believe that alone equates to zero-trust protection.

In response, many organizations will move the security stack up to the application layer to the endpoint – where we anticipate a 10,000% increase in attacks. Enterprises can install 5G adapters right on the laptops, giving them more granular control of the last-mile network to do source-based security policies no matter where the user resides. 

The focus will extend from training employees to policing others with external access to enterprise networks

Previously, providing cybersecurity awareness training to employees meant better equipping them to deal with cyberattacks such as phishing. But a lot of organizations are falling short on dealing with external users such as contractors who aren’t governed under the enterprise’s policies and procedures. These partners often have access to some of the enterprise’s most critical information systems, especially when working with finance teams and legal departments. That increases the risk of data breaches much more than incidents of employees inadvertently clicking a harmful link.

Many organizations will be forced to rethink their approach to external users, starting with a basic understanding of which of their business operations contractors and partners need to access, and which of those operations they should monitor. They should do a data check on every contractor or partner as part of the initial engagement.

AI & Machine Learning Will Become A More Prominent Aspect Of SIEM

Next year will see a huge jump in vendors putting Artificial Intelligence (AI) and machine learning (ML) into Security Information and Event Management (SIEM) platforms. SIEM has proven adept at collecting information and allowing enterprises to filter and focus on the most relevant alerts. If an organization is getting thousands of the same inconsequential alerts every day, they’re going to start ignoring them. Building more AI/ML into log systems will help security leaders to filter out the noise and prioritize the relevant alerts to address. 

We’re never going to be able to fully automate using AI/ML to determine all relevant threats. But tools will begin appearing in the coming year to help limit the involvement of analysts in filtering out SIEM noise, taking us to the next level of managed detection and response.

2023 Will Be Yhe Year Of Enhanced Internet

Enhanced internet services gained popularity in the last few years as an offering that improves the reliability and performance of internet-based traffic. First defined by Gartner, it includes features such as telemetry-based routing and performance optimization. 

Tier 1 internet service providers can formulate algorithms to start looking at traffic flows, providing clients with continuous reports on potentially malicious traffic from certain destinations to their IP ports that require investigation without the need for additional security functionality.

Service providers will also offer clients full vulnerability scans of their IP space on a timely basis to provide visibility into risks. As organizations grow, they often end up with shadow systems with vulnerabilities that aren’t noticed. Scans can easily reveal dozens of vulnerabilities on an organization’s public websites in seconds, just by checking a couple of IP addresses they own. 

As always, the coming year will present both an opportunity and a challenge to IT and security leaders. But by doubling down on zero-trust and leveraging the best solutions coming to the market, they can avoid falling victim to continually expanding cyber threats.

James Karimi is CIO and CISO at GTT

You Might Also Read: 

From AI to ESG: Key Security Technology Trends Of 2023:

 

 

« Meta Pays $725M To Settle Facebook Privacy Suit
Biden Signs Quantum Cyber Security Act »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

High-Tech Bridge

High-Tech Bridge

High-Tech Bridge SA is a Swiss MSSP provider offering security auditing, source code review and computer forensics.

AdNovum Informatik

AdNovum Informatik

AdNovum Informatik provides a full set of IT services, ranging from consulting, the conception and implementation of customized business and security solutions to maintenance and support.

Wotan Monitoring

Wotan Monitoring

Wotan Monitoring is the software solution for fully automatic process monitoring, infrastructure monitoring and end-to-end monitoring.

HumanFirewall

HumanFirewall

HumanFirewall makes it possible for every individual to take part in securing their organisation. With HumanFirewall, achieving security has never been easier.

SixThirty CYBER

SixThirty CYBER

SixThirty is a venture fund that invests in early-stage enterprise technology companies from around the world building FinTech, InsurTech, and Cybersecurity solutions.

River Loop Security

River Loop Security

River Loop Security specialize in solving complex cybersecurity challenges in the IoT and embedded devices space.

Stanley Reid & Company (SRC)

Stanley Reid & Company (SRC)

Stanley Reid & Co is an Executive and Technical Search Firm serving the commercial market and the US Intelligence & Defense community. Our areas of expertise include Cybersecurity.

Hyperwise Ventures

Hyperwise Ventures

Hyperwise Ventures lead seed investments in startups in the cyber security and enterprise software spaces.

Tracepoint

Tracepoint

Tracepoint provide full-service cyber incident response, remediation and recovery solutions for the most time-sensitive situation your company may ever face.

SolCyber

SolCyber

SolCyber, a Forgepoint company, is the first modern MSSP to deliver a curated stack of enterprise strength security tools and services that are accessible and affordable for any organization.

Altospam

Altospam

Altospam is a full service corporate email protection, integrating multiple security levels for your emails.

Vaultinum

Vaultinum

Vaultinum are a trusted independent third party specialized in the protection and audit of digital assets.

RiverSafe

RiverSafe

RiverSafe is a professional services provider specialising in Cyber Security, Data Operations and DevOps, putting security at the heart of everything we do.

L&T Technology Services (LTTS)

L&T Technology Services (LTTS)

L&T Technology Services Limited (LTTS) is a global leader in Engineering and R&D (ER&D) services.

SCS Technology Solutions

SCS Technology Solutions

SCS Technology Solutions has become the preferred partner for top performing organisations across Lincolnshire for IT support and consultancy.

Sinergi Digital

Sinergi Digital

Sinergi Digital is a business unit of the Metrodata Group with a focus on providing ICT solution to help accelerating digital transformation.