Human-centric security design and enhancing people management are some of the top cybersecurity trends for 2023, according to Gartner.
.jpg&h=420&w=748&c=0&s=0)
The research firm advises that security and risk management (SRM) leaders must rethink their balance of investments across technology and human-centric elements when creating and implementing cybersecurity programs in line with nine top industry trends.
Richard Addiscott, senior director analyst at Gartner explained that a human-centred approach to cybersecurity is essential to reduce security failures.
He said, “Focusing on people in control design and implementation, as well as through business communications and cybersecurity talent management, will help to improve business-risk decisions and cybersecurity staff retention.”
To address cybersecurity risks and sustain an effective cybersecurity program, SRM leaders must be focused on three key domains.
The essential role of people for security program success and sustainability; technical security capabilities that provide greater visibility and responsiveness across the organisation’s digital ecosystem; and restructuring the way the security function operates to enable agility without compromising security.
According to Gartner the following nine trends will have a broad impact for SRM leaders across these three areas.
Human-centric security design
Human-centric security design prioritises the role of employee experience across the controls management life cycle. By 2027, Gartner predicts that 50 percent of large enterprise chief information security officers (CISOs) will have adopted human-centric security design practices to minimise cybersecurity-induced friction and maximise control adoption.
Addiscott explained, “Traditional security awareness programs have failed to reduce unsecure employee behaviour.
“CISOs must review past cybersecurity incidents to identify major sources of cybersecurity induced-friction and determine where they can ease the burden for employees through more human-centric controls or retire controls that add friction without meaningfully reducing risk.”
Enhancing people management for security program sustainability
Traditionally, cybersecurity leaders have focused on improving technology and processes that support their programs, with little focus on the people that create these changes.
CISOs who take a human-centric talent management approach to attract and retain talent have seen improvements in their functional and technical maturity. By 2026, Gartner predicts that 60 percent of organisations will shift from external hiring to “quiet hiring” from internal talent markets to address systemic cybersecurity and recruitment challenges.
Transforming the cybersecurity operating model to support value creation
CISOs must modify their cybersecurity’s operating model to integrate how work gets done. Employees must know how to balance a number of risks including cybersecurity, financial, reputational, competitive and legal risks. Cybersecurity must also connect to business value by measuring and reporting success against business outcomes and priorities.
Threat exposure management
The attack surface of modern enterprises is complex and creates fatigue. CISOs must evolve their assessment practices to understand their exposure to threats by implementing continuous threat exposure management (CTEM) programs.
Gartner predicts that by 2026, organisations prioritising their security investments based on a CTEM program will suffer two-thirds fewer breaches.
Identity fabric immunity
Fragile identity infrastructure is caused by incomplete, misconfigured or vulnerable elements in the identity fabric. By 2027, identity fabric immunity principles will prevent 85 percent of new attacks and thereby reduce the financial impact of breaches by 80 percent.
Cybersecurity validation
Cybersecurity validation brings together the techniques, processes and tools used to validate how potential attackers exploit an identified threat exposure. Through 2026, more than 40 percent of organisations, including two-thirds of midsize enterprises, will rely on consolidated platforms to run cybersecurity validation assessments.
Cybersecurity platform consolidation
As organisations look to simplify operations, vendors are consolidating platforms around one or more major cybersecurity domains.
SRM leaders need to continuously inventory security controls to understand where overlaps exist and reduce the redundancy through consolidated platforms.
Composable businesses need composable security
Organisations must transition from relying on monolithic systems to building modular capabilities in their applications to respond to the accelerating pace of business change. Composable security is an approach where cybersecurity controls are integrated into architectural patterns and then applied at a modular level in composable technology implementations.
By 2027, more than 50% of core business applications will be built using composable architecture, requiring a new approach to securing those applications.
Boards expand their competency in cybersecurity oversight
The board’s increased focus on cybersecurity is being driven by the trend toward explicit-level accountability for cybersecurity to include enhanced responsibilities for board members in their governance activities. Cybersecurity leaders must provide boards with reporting that demonstrates the impact of cybersecurity programs on the organisation’s goals and objectives.
Addiscott ended, “SRMs leaders must encourage active board participation and engagement in cybersecurity decision making. Act as a strategic advisor, providing recommendations for actions to be taken by the board, including allocation of budgets and resources for security.”