February 1, 2024 By Bonnie Netschert, PhD 3 min read

Cyberattacks are becoming increasingly sophisticated. Read about the concerns that industry leaders have for the future and three approaches organizations can take to build up their defenses.

Cyber workforce shortage

There are over four million unfilled cybersecurity jobs in the world today. Filling these vacancies has become a security imperative, and several global compliance mandates have been established to tackle the issue. For example, in the US, the 2023-2025 CISA Cybersecurity Strategic Plan aims to increase basic-level cyber skills across the country, transform cyber education and boost the cyber workforce. The European Union Agency for Cybersecurity (ENISA) provides a series of recommendations for reducing the cybersecurity skills shortage and gaps through higher education. Other regions around the world have similar cyber mandates.

Generative AI attacks

Social engineering attacks, which involve tricking users into giving attackers access to systems, will also increase in sophistication. Generative AI tools, such as ChatGPT, enable more attackers to make smarter, more personalized approaches, and deepfake attacks will become increasingly prevalent. Combatting generative AI attacks will involve implementing organization-wide cybersecurity awareness and training.

Cyberattacks will top USD 10.5 trillion by 2024

By the end of 2024, the cost of cyberattacks on the global economy is predicted to top USD 10.5 trillion. A shortage of professionals with the skills needed to protect organizations from cyberattacks will continue to be a running theme throughout 2024. This is a threat to business and societies. However, generative AI can have a transformative impact on defense mechanisms where organizations focus efforts on cybersecurity training, development and upskilling programs.

Cybersecurity transformation: the time is now

While every organization should create its own cybersecurity transformation roadmap, there are three approaches organizations can take to ensure that people are its first line of defense.

1. Crisis simulation

After a cybersecurity breach, every second counts. Security teams, line-of-business managers and executives should know exactly what role to play to help contain the damage. To help prepare, many organizations are testing their incident response (IR) plans and teams with cyber range simulations. Organizations with an incident response team can save USD 1.5 million in data breach costs compared to organizations without an IR team or IR plan testing.

Organizations gain:

  • Sharpened collaboration across organizations with increased knowledge of their attack surface to more effectively identify vulnerabilities and improve resilience
  • The ability to experience a simulated cybersecurity incident with the intensity and pressure of a real-life data breach
  • Confidence in responding and recovering from enterprise-level cybersecurity incidents, managing vulnerabilities and building a stronger security culture

2. Cybersecurity awareness and training

Many companies struggle to understand their cyber risk. IBM’s in-depth cybersecurity expertise leverages lessons learned from 1,500 businesses where we’ve hosted training sessions combined with industry best practices based on NIST and ISO standards to help organizations improve their cyber culture.

Organizations gain:

  • Reduction in number of incidents; hence, reduced overall cost
  • The visibility of live phishing tests linked with targeted training
  • An increase in security awareness and behavioral change

3. Cybersecurity talent transformation

With the increased sophistication and rise of cyberthreats, organizations struggle to develop and maintain the necessary cybersecurity talent to detect, prevent and respond to advanced attacks. The IBM Cyber Talent Transformation service is tailored to an organization’s cybersecurity objectives. using AI in its unique security talent management processes, which helps build resilient cybersecurity teams.

Organizations gain:

  • The cybersecurity talent and critical skills needed to meet current and future demands
  • The ability to upskill and reskill effectively and at speed
  • The ability to incorporate AI and skills strategies where organizations can grow and retain talent faster, while reducing the risk of critical cyber skills shortages that can hinder business performance

Join the IBM Consulting team on Tuesday, Feb. 13, 2024 from 10-11:00am EST, to hear from cybersecurity talent experts and learn how you can apply new approaches to transform your business to face today’s cyberattacks.

Learn from our cybersecurity experts on February 13
Was this article helpful?
YesNo

More from Security

Data privacy examples

9 min read - An online retailer always gets users' explicit consent before sharing customer data with its partners. A navigation app anonymizes activity data before analyzing it for travel trends. A school asks parents to verify their identities before giving out student information. These are just some examples of how organizations support data privacy, the principle that people should have control of their personal data, including who can see it, who can collect it, and how it can be used. One cannot overstate…

How to prevent prompt injection attacks

8 min read - Large language models (LLMs) may be the biggest technological breakthrough of the decade. They are also vulnerable to prompt injections, a significant security flaw with no apparent fix. As generative AI applications become increasingly ingrained in enterprise IT environments, organizations must find ways to combat this pernicious cyberattack. While researchers have not yet found a way to completely prevent prompt injections, there are ways of mitigating the risk.  What are prompt injection attacks, and why are they a problem? Prompt…

Building the human firewall: Navigating behavioral change in security awareness and culture

4 min read - The latest findings of the IBM X-Force® Threat Intelligence Index report highlight a shift in the tactics of attackers. Rather than using traditional hacking methods, there has been a significant 71% surge in attacks where criminals are exploiting valid credentials to infiltrate systems. Info stealers have seen a staggering 266% increase in their utilization, emphasizing their role in acquiring these credentials. Their objective is straightforward: exploit the path of least resistance, often through unsuspecting employees, to obtain valid credentials. Organizations…

IBM Newsletters

Get our newsletters and topic updates that deliver the latest thought leadership and insights on emerging trends.
Subscribe now More newsletters