These are the security trends to watch in 2023

It's about the attack surface, identity and supply chains, says Gartner's Paul Furtado

Tom Allen
clock • 7 min read

“Business thinks IT has a crystal ball, but the truth is the CISO doesn’t always know what’s going on.”

Image: Paul Furtado / Gartner

#7 Human factors require a reframing of security awareness programmes

Everyone learns differently, so we need to take a multi-modal approach to security training. Some people might learn better by reading a document, others will respond better to video. Still others need something interactive. You need to find out how your employees learn best.

This is especially important when you're trying to change security culture. The best way of doing so? "Don't make it all about the business."

If people have bad cyber habits at home, they'll bring those to work with them - so give them a reason to change their habits at home.

Furtado gave an example of one security leader who had "given up" on MFA. Instead, "He came up with a personal payroll protection programme that basically said, in order for you to make a change to your HR record you're going to get a message on your phone. Only after you authorise it can you go in and change that banking information. So ,we're protecting your payroll."

That programme - really MFA by another name - had an adoption rate of 90%.

"When you make it about the individual, that's going to resonate more… If we want to change the culture, we have to deal with the human animal."

Action plan:

  1. Develop culture change that equips users with cyber judgement skills.
  2. Investigate use of organisational change management best practices and social science principles, such as culture hacks - "It doesn't always have to be about the IT guy."
  3. Collaborate with business leaders on culture-changing activities.
  4. Adopt new training methods like gamification, in-the-moment nudges, real-world phishing simulation and outcome-driven metrics.

The future of defence might be unclear, but bringing in some business focus will make protection easier - for the organisation, the IT team and even the users.

Furtado ended with his advice to security leaders who were still struggling to secure investment from their leadership teams:

"Treat cybersecurity as a business risk that needs business-led investment. We need to be able to defend that investment."

You may also like
'Levelling up cybersecurity is a team effort,' says Jacob DePriest of GitHub

Open Source

But security starts with developers, and AI isn’t going to replace them

clock 09 May 2024 • 5 min read
Cybersecurity Festival 2024: Four ways to cut your cyber insurance premiums

Finance

Certifications mean nothing without action

clock 08 May 2024 • 4 min read
IT Essentials: A cyber staycation

Security

The UK made headlines in security news

clock 07 May 2024 • 3 min read
Most read
03

TikTok sues US government

09 May 2024 • 3 min read
04

LockBit leader unmasked

08 May 2024 • 3 min read

Sign up to our newsletter

The best news, stories, features and photos from the day in one perfectly formed email.

More on Security

IT Essentials: A cyber staycation

IT Essentials: A cyber staycation

The UK made headlines in security news

Tom Allen
clock 07 May 2024 • 3 min read
Microsoft: last year we tracked 200 major threat actors, now it's 300

Microsoft: last year we tracked 200 major threat actors, now it's 300

Microsoft chief security adviser Sarah Armstrong Jones calls for more collaboration on AI and security

John Leonard
clock 07 May 2024 • 2 min read
Microsoft vows to overhaul security, tie executive pay to performance after string of breaches

Microsoft vows to overhaul security, tie executive pay to performance after string of breaches

'We are making security our top priority at Microsoft'

clock 07 May 2024 • 3 min read