The Future of Cyber Security: My Thoughts On The 2023-2024 ACSC Annual Cyber Threat Report

Image credit: ChatGPT-4o “A fierce, super-intelligent cyber defender”

Today the Australian Signals Directorate (ASD) released its annual 2023-2024 Cyber Threat Report. 

For those of us in the cyber world, this is kind of like receiving an early Christmas present (for those who observe the Christian holiday): lots of high-quality cyber threat information gathered from all across the country (and sometimes abroad), all bundled up into a single report.

It is an interesting read, even if you’re not involved in the cyber industry. Threat reports are an excellent way to understand the current threat landscape and prepare for the kinds of attacks that adversaries focus on.

The 2023–24 cyber threat landscape reveals a rapidly evolving environment (I feel like I say this way too often now) in which businesses, critical infrastructure, and individuals face persistent and increasingly sophisticated threats. 

From ransomware and phishing to identity fraud and supply chain compromises, adversaries continue to exploit vulnerabilities, often targeting sensitive data, cloud applications, and operational technology.

State-sponsored adversaries and cybercriminals are leveraging advanced techniques, such as AI-driven social engineering and lateral movement across hybrid IT/OT systems, to maximise disruption and financial gain. Critical infrastructure sectors, such as energy, water, and transport, are particularly at risk, while businesses continue to grapple with Business Email Compromise (BEC) and ransomware. 

For individuals, the rise in identity fraud and phishing underscores the importance of personal cybersecurity awareness.

However, the fight against these threats is far from static. Collaboration between governments, industries, and individuals enables strong, proactive defences, along with adopting industry-leading frameworks like the NIST Cybersecurity Framework (CSF v2.0) and MITRE ATT&CK

With the right strategies, including secure-by-design principles, cyber hygiene practices, and leveraging AI for threat detection, we can build a more secure, resilient future.

As technology advances, so must our approach to cybersecurity, shifting from reactive to proactive measures (see my article here for more on this point) that protect and enable us to grow and succeed in a hyper-connected world. 

The Future of Cybersecurity

Below are three major areas that I feel will be the keys to safeguarding our future and enabling growth for businesses and individuals across all industries.

1. AWARENESS – How to interpret, think, and understand Cybersecurity

Actionable insights to target awareness align with understanding the fundamentals of cybersecurity and recognising the broader context of the threat landscape:

  • Training and Education: Regularly train staff to identify the latest phishing scams and social engineering techniques. Teach individuals and employees how to critically evaluate emails, links, and communications to avoid compromise.

  • Incident Response Plans: Cultivate a mindset of preparedness by treating cybersecurity incidents as a “when” rather than an “if” scenario. Regularly test these plans to reinforce understanding and readiness. We only rise to the level of our training and preparation.

  • Cyber Threat Landscape Understanding: Inform individuals and businesses about the top threats they face, such as BEC, ransomware, phishing, and identity fraud. Share industry data and examples to contextualise risks.

  • Cyber Hygiene: Emphasise the importance of ongoing practices like enabling MFA, using strong passphrases, and regularly updating software. This instils a mindset of vigilance and proactivity.

  • Promoting a Culture of Security: Create an environment where cybersecurity is everyone’s responsibility, and educate stakeholders on their role in protecting themselves and the valuable assets they access and consume.

2. INTELLIGENCE – How to use Cyber Threat Intelligence (CTI) to adapt to a volatile threat landscape

Leveraging intelligence and data to adapt our behaviours and keep pace (in the best case, get ahead) with adversarial activity:

  • Threat Intelligence Sharing: Encourage participation in platforms like the ASD’s CTIS to stay updated on the latest threats. Real-time threat information helps businesses and individuals adapt quickly. Leverage open source platforms like MISP and OpenCTI.

  • Adversary TTP Awareness: Use frameworks like MITRE ATT&CK to identify adversarial techniques and adapt defences. For example, understanding T1566 (phishing) and the more recent sub-technique (T1566.004) that uses impersonation of someone’s voice to trick unsuspecting people can guide better detection, email filtering and training.

  • Proactive Defences: Use intelligence from past incidents to adjust defences, such as improving backup solutions in response to ransomware trends targeting recovery systems.

  • Supply Chain Monitoring: Apply due diligence and real-time vendor risk assessments to identify and address vulnerabilities in third-party software and systems.

  • Data-Driven Decisions: Monitor internal logs, external CTI, and emerging threat patterns to prioritise resources for high-risk areas, such as credential management, internet-facing infrastructure, or ransomware prevention.

3. INNOVATION – How to create secure solutions in a hyper-connected world

Innovation revolves around using cutting-edge technology, tools and ideas to advance cybersecurity:

  • Leveraging AI for (Cyber) Defence: Adopt machine-learning algorithms and data science techniques for threat detection and response. Use generative AI to simulate phishing attacks or improve security awareness training.

  • Secure-by-Design Products: Develop tools and services with security as a core principle. For example, build and deliver IoT devices that are hardened by default, integrate quantum-resistant encryption into systems to prepare for advances in computing, and more.

  • Zero-Trust Architecture: Build infrastructures based on Zero-Trust principles to minimise risk from both external and internal threats.

  • Automation and Orchestration: Automate patch management, incident response workflows, and vulnerability scans to improve efficiency and consistency in security practices.

  • Decentralised Digital Identity: Learn, experiment and invest in decentralised identity systems to improve security for individuals while reducing reliance on centralised credentials.

  • Resilient Network Architectures: Create redundancies and segment networks to mitigate the impact of attacks, ensuring critical systems remain operational.

Previous
Previous

Identity is the New Black

Next
Next

Calculating The Environment Protection Score (EPS)