-
The Verizon "2024 Data Breach Investigations Report" reveals that 68% of all breaches involve the human element, through error, stolen credentials, or social engineering.
-
Security is a core business function that shapes an organization's reputation and perceived trustworthiness, directly impacting customer reviews and stock prices.
-
IT team leaders should prioritize communicating the value of their security programs to leadership, using existing vendor resources and focusing on metrics that encourage proactive reporting of suspicious activity.
-
Gartner's 2024 Magic Quadrant for Privileged Access Management (PAM) emphasizes the growing need to secure both human and non-human identities, which now outnumber human users in many organizations.
-
Traditional PAM tools struggle to keep up with the dynamic and ephemeral nature of modern workloads, which require granular, context-aware controls for real-time, just-in-time authentication.
-
As organizations scale and rely on automation, containerized environments, and multi-cloud strategies, managing privileged access for workloads and other non-human identities becomes a key security challenge not fully addressed by current PAM solutions.
Stay Ahead in Cybersecurity!
Get the most critical cybersecurity news, insights, and strategies delivered to your inbox every week.
I will never spam or sell your information.
-
Cloud security engineers focus on securing cloud-based systems, applications, and data, with projected job growth of 9% over next decade.
-
Key responsibilities include implementing security policies, conducting risk assessments, and responding to incidents in cloud environments.
-
Popular certifications like AWS Security Specialty and Azure Security Engineer can help accelerate career growth and boost compensation.
-
In a recent Reddit discussion, cybersecurity professionals shared their biggest job frustrations, with many citing issues with upper management as the worst part of their roles.
-
Other common complaints included dealing with internal politics, handling auditors who lack practical knowledge, and working with people who don't understand the full scope of cybersecurity.
-
A lack of adequate funding for cybersecurity initiatives was also highlighted as a significant challenge faced by many in the industry.
-
Top cybersecurity positions like CISO can earn salaries up to $420,000, with factors like location, experience, and industry significantly impacting pay.
-
Highest paying states include California ($125,621 avg), New York ($121,819), and Massachusetts ($120,184). Top cities offer even higher salaries, like San Francisco at $149,801.
-
Job outlook is strong, with 3.5 million cybersecurity job openings predicted by 2025 and 33% growth for information security analysts from 2020-2030.
-
Three main AI models (Generative AI, Supervised and Unsupervised Machine Learning) are being used by defenders to enhance threat detection, generate reports, and predict attacks.
-
Cybercriminals are misusing AI for targeted phishing, creating polymorphic malware, vulnerability scanning, and generating deepfakes for social engineering attacks.
-
Threat actors are exploiting AI systems through various methods, including prompt injection, targeting responses, model manipulation, and infrastructure attacks on AI hosting platforms.
-
AI/ML systems introduce new types of zero-day vulnerabilities, such as prompt injection and training data leakage, which differ from traditional software flaws.
-
The rapid adoption of AI often prioritizes innovation over security, leading to an ecosystem where AI applications lack robust security measures from the ground up.
-
To address these challenges, security teams should adopt MLSecOps practices, perform proactive security audits, and adapt their strategies to incorporate AI-specific considerations.
-
Usage Confidence: Assess reliability of outputs, as vendors often include caveats about verifying results. Determine which outputs can be confidently relied upon to avoid delays from false positives/negatives.
-
Usage Friction: Evaluate ease of use, including prompt writing and integration with log sources. Address factors that may discourage adoption, such as utility-based charging models that make staff hesitant to use the system.
-
Usage Governance: Implement proper access controls and accounting to prevent misuse and wastage, especially for solutions with activation-based charging. Ensure maturity of governance structures.
-
Netskope, a SASE provider, has acquired Dasera to integrate data security posture management (DSPM) capabilities into its Netskope One platform.
-
The integration will enable Netskope to deliver advanced security across various use cases, including structured, semi-structured, and unstructured data stores and data lakes.
-
Netskope aims to provide a holistic approach to modern data security by offering the broadest and deepest data protection using a single platform, with DSPM capabilities being a part of the overall solution.
-
Cyera, a data security company, has acquired Trail Security, an Israeli DLP startup, for $162 million in cash and stock.
-
Trail Security has developed AI-enhanced DLP technology, which Cyera is integrating into its Data Security Posture Management (DSPM) platform to create a unified data security solution.
-
With the acquisition, Cyera will onboard 40 Trail employees to establish its DLP division, and the company expects to reach over 1,000 employees within the next two years.
-
SentinelOne announced an extension of its strategic collaboration agreement with AWS to deliver generative AI benefits, with SentinelOne's Purple AI cybersecurity analyst powered by Amazon Bedrock.
-
The expanded agreement will increase investments in SentinelOne's AI-powered Singularity Platform within AWS Marketplace, enabling enterprises to quickly access end-to-end protection from a unified, AI-powered platform.
-
SentinelOne will allow customers to choose specific large language models via Amazon Bedrock to power Purple AI, and will also use Amazon Bedrock Custom Model Import and customization capabilities to create tailored solutions.
Improve Your Cybersecurity Leadership
Join security leaders receiving the most critical insights, strategies, and resources to stay ahead in cybersecurity.
I will never spam or sell your information.
Application whitelisting is one of Information Assurance top 10 mitigation strategies. This project contains scripts and configuration files for aiding administrators in implementing Microsoft AppLocker as outlined in the Application Whitelisting using Microsoft AppLocker paper.
NotifySecurity is an Outlook add-in designed to assist users in reporting suspicious emails to security teams. It integrates with Swordphish to update reported statistics and provides relevant information like full SMTP headers for accurate reporting.
IAM Floyd is a tool for generating AWS IAM policy statements with a fluent interface, supporting 393 Services, 16621 Actions, 1783 Resource Types, and 1731 Condition keys. It offers two package variants: iam-floyd for general use and cdk-iam-floyd for integration with AWS CDK.
Before you go
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
Have ideas, questions or comments? Just hit reply - I read every message!
For more frequent cybersecurity leadership insights and tips, follow me on LinkedIn, BlueSky and Mastodon.
Best,
Nikoloz