Gartner Unveils Top Eight Cybersecurity Predictions for 2024
Speaking at the Gartner Security & Risk Management Summit in
Gartner recommends that cybersecurity leaders build the following strategic planning assumptions into their security strategies for the next two years.
By 2028, the adoption of GenAI will collapse the skills gap, removing the need for specialized education from 50% of entry-level cybersecurity positions.
GenAI augments will change how organizations hire and teach cybersecurity workers looking for the right aptitude, as much as the right education. Mainstream platforms already offer conversational augments, but will evolve. Gartner recommends cybersecurity teams focus on internal use cases that support users as they work; coordinate with HR partners; and identify adjacent talent for more critical cybersecurity roles.
By 2026, enterprises combining GenAI with an integrated platforms-based architecture in security behavior and culture programs (SBCP) will experience 40% fewer employee-driven cybersecurity incidents.
Organizations are increasingly focused on personalized engagement as an essential component of an effective SBCP. GenAI has the potential to generate hyperpersonalized content and training materials that take into context an employee's unique attributes. According to Gartner, this will increase the likelihood of employees adopting more secure behaviors in their day-to-day work, resulting in fewer cybersecurity incidents.
"Organizations that haven't yet embraced GenAI capabilities should evaluate their current external security awareness partner to understand how it is leveraging GenAI as part of its solution roadmap," said Gopal.
Through 2026, 75% of organizations will exclude unmanaged, legacy, and cyber-physical systems from their zero trust strategies.
Under a zero trust strategy, users and endpoints receive only the access needed to do their jobs and are continuously monitored based on evolving threats. In production or mission-critical environments, these concepts do not universally translate for unmanaged devices, legacy applications and cyber-physical systems (CPS) engineered to perform specific tasks in unique safety and reliability-centric environments.
By 2027, two-thirds of global 100 organizations will extend directors and officers (D&O) insurance to cybersecurity leaders due to personal legal exposure.
New laws and regulations -- such as the
By 2028, enterprise spend on battling malinformation will surpass
The combination of AI, analytics, behavioral science, social media, Internet of Things and other technologies enable bad actors to create and spread highly effective, mass-customized malinformation (or misinformation). Gartner recommends CISOs define the responsibilities for governing, devising and executing enterprise-wide anti-malinformation programs, and invest in tools and techniques that combat the issue using chaos engineering to test resilience.
Through 2026, 40% of identity and access management (IAM) leaders will take over the primary responsibility for detecting and responding to IAM-related breaches.
IAM leaders often struggle to articulate security and business value to drive accurate investment and are not involved in security resourcing and budgeting discussions. As IAM leaders continue to grow in importance, they will evolve in different directions, each with increased responsibility, visibility and influence. Gartner recommends CISOs break traditional IT and security silos by giving stakeholders visibility into the role IAM plays by aligning the IAM program and security initiatives.
By 2027, 70% of organizations will combine data loss prevention and insider risk management disciplines with IAM context to identify suspicious behavior more effectively.
Increased interest in consolidated controls has prompted vendors to develop capabilities that represent an overlap between user behavior focused controls and data loss prevention. This introduces a more comprehensive set of capabilities for security teams to create a single policy for dual use in data security and insider risk mitigation. Gartner recommends organizations identify data risk and identity risk, and use them in tandem as the primary directive for strategic data security.
By 2027, 30% of cybersecurity functions will redesign application security to be consumed directly by non-cyber experts and owned by application owners.
The volume, variety and context of applications that business technologists and distributed delivery teams create means potential for exposures well beyond what dedicated application security teams can handle.
"To bridge the gap, cybersecurity functions must build minimum effective expertise in these teams, using a combination of technology and training to generate only as much competence as is required to make cyber risk informed decisions autonomously," said Gopal.
Learn more about the top priorities for security and risk leaders in 2024 in the complimentary Gartner ebook Top 3 Strategic Priorities for Security & Risk Management Leaders.
Gartner Security & Risk Management Summit
Gartner analysts are presenting the latest research and advice for security and risk management leaders at the Gartner Security & Risk Management Summit in
* * *
About Gartner for Cybersecurity Leaders
Gartner for Cybersecurity Leaders equips security leaders with the tools to help reframe roles, align security strategy to business objectives and build programs to balance protection with the needs of the organization. Additional information is available at https://www.gartner.com/en/cybersecurity.
* * *
About Gartner
Gartner delivers actionable, objective insight that drives smarter decisions and stronger performance on an organization's mission-critical priorities.
* * *
Original text here: https://www.gartner.com/en/newsroom/press-releases/2024-03-18-gartner-unveils-top-eight-cybersecurity-predictions-for-2024



United Risk Launches Applied Credit Underwriters to Target Credit and Political Risk Markets
The Hanover Insurance Group, Inc. to Issue First Quarter Financial Results on May 1
Advisor News
- Equitable launches 403(b) pooled employer plan to support nonprofits
- Financial FOMO is quietly straining relationships
- GDP growth to rebound in 2027-2029; markets to see more volatility in 2026
- Health-related costs are the greatest threat to retirement security
- Social Security literacy is crucial for advisors
More Advisor NewsAnnuity News
- Smart annuity planning can benefit long-term tax planning
- Agam Capital Announces the Continued Growth of Agam ISAC’s Bermuda Platform
- Best’s Special Report: Analysis Shows Drastic Shift in Life Insurance Reserves Toward Annuity Products, and a Slide in Credit Quality
- MetLife to Announce First Quarter 2026 Results
- CT commissioner: 70% of policyholders covered in PHL liquidation plan
More Annuity NewsHealth/Employee Benefits News
- No vote on bill requiring health insurance to cover infertility treatment
- Cost pressures are driving health care tradeoffs
- Clash of Titans: Hawai'i's Healthcare Leaders Disagree on Best Path Forward
- Insurance resolution sparks backlash
- Municipalities contend with surprise bills as health costs rise
More Health/Employee Benefits NewsLife Insurance News
- How improving the customer experience can build trust
- AI won’t solve the workforce crisis; here’s what will
- Agam Capital Announces the Continued Growth of Agam ISAC’s Bermuda Platform
- An Application for the Trademark “PREMIER ACCESS” Has Been Filed by The Guardian Life Insurance Company of America: The Guardian Life Insurance Company of America
- AM Best Assigns Credit Ratings to North American Fire & General Insurance Company Limited and North American Life Insurance Company Limited
More Life Insurance News