These are the security trends to watch in 2023

It's about the attack surface, identity and supply chains, says Gartner's Paul Furtado

Tom Allen
clock • 7 min read
These are the security trends to watch in 2023

“Business thinks IT has a crystal ball, but the truth is the CISO doesn’t always know what’s going on.”

That was the conclusion of Paul Furtado, VP analyst at Gartner, speaking at MES IT Security in Indianapolis this week.

There are some persistent security challenges - the skills gap, shadow IT, hybrid work - but Furtado focused on the newest threats facing security teams in 2023, along with an action plan to address each one.

#1: Expanding perimeter

Image: Paul Furtado / Gartner

While attacks are evolving, one of the biggest threats today is the expanding perimeter/attack surface.

Furtado pointed out that security regulations "don't differentiate between cloud, on-prem or SaaS - they just care about the data."

Action plan

  1. Perform attack surface gap analysis - "A regulator's not going to give you a free pass because you say, 'I didn't know we were using that application.'"
  2. Evaluate attack surface management technologies to visualise external digital footprint.
  3. Consider pen testing, breach simulation, etc to provide regular assessments.
  4. Test your response.

While most people - including Furtado, later in his presentation - recommend bringing business and IT together, he recommended keeping conversations about responses to a security separate.

"As soon as you start talking tech you've lost the board, and once you start talking about cyber insurance and marketing you've lost your tech team.

"It's the same scenario but two different people."

You may also like
CrowdStrike: Thousands of typosquatting domains registered after global outage

Threats and Risks

CrowdStrike says cybercriminals are attempting to install a new infostealer malware through fake fixes

clock 24 July 2024 • 2 min read
Cost of GenAI is a negative for software companies, Gartner

Artificial Intelligence

'Revenue gains from the sale of GenAI add-ons ... flow back to their AI model provider partner'

clock 17 July 2024 • 1 min read
Malicious Python packages found exfiltrating user data to Telegram bot

Threats and Risks

Appears to be part of a wider operation by crime gang based in Iraq, say Checkmarx researchers

clock 15 July 2024 • 2 min read
Most read

Sign up to our newsletter

The best news, stories, features and photos from the day in one perfectly formed email.

More on Security

'Gay furry hackers' breach conservative US think tank behind Project 2025

'Gay furry hackers' breach conservative US think tank behind Project 2025

Heritage Foundation calls group "degenerate perverts"

Tom Allen
clock 11 July 2024 • 2 min read
Why 'change' for the UK must include cybersecurity

Why 'change' for the UK must include cybersecurity

Labour needs to to get ahead and demonstrate a commitment to security from the outset

Rick Jones
clock 11 July 2024 • 4 min read
Mammoth Microsoft Patch Tuesday fixes four zero-days, five critical bugs

Mammoth Microsoft Patch Tuesday fixes four zero-days, five critical bugs

142 holes plugged this month

John Leonard
clock 10 July 2024 • 3 min read