drj logo

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Zip Code*
Please enter a number from 0 to 100.
Strength indicator
I agree to the Terms of Service and Privacy Policy*
Yes, of course I want to receive emails from DRJ!

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

x
Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Why Subscribe to DRJ
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Fall 2026
    • Call for Presentations
    • DRJ Scholarship
    • Tracey Rice Memorial Scholarship
    • Other Industry Events
    • Schedule & Archive
  • WEBINARS
    • Upcoming Webinars
    • On Demand
    • DRJ Showcase Series
  • MENTOR PROGRAM
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • DRJ Glossary of Business Continuity Terms
    • Careers
    • The BCI Partnership
  • ABOUT
    • About DRJ
    • 2026 Media Kit
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • DEI
      • Glossary Committee
      • Rules and Regulations Committee

2024 Cybersecurity Predictions – Evasive Threats, CISO Priorities, Remote Work, and More

by Jon Seals | December 5, 2023 | | 0 comments

With the year quickly coming to a close, security expert Poornima DeBolle, co-founder and chief product officer at browser security company Menlo Security wanted to share three 2024 predictions.

PREDICTION #1: “Highly Evasive and Adaptive Threats (HEAT) Will Dominate Modern Attack Techniques”  

“The cybercriminal playbook changes rapidly, oftentimes faster than security teams and their defenses can keep up. This has been a well-known weakness in the landscape and yet, after years of technological innovation, we are still facing threats that are weaving past what many consider to be the most comprehensive security platforms. For example, Highly Evasive Threats exploit vulnerabilities in web browsers, using a variety of evasive techniques to get around detection-based security tools. These threats include multi-factor authentication (MFA) bypass, HTML smuggling, leveraging malicious password protections, and Legacy URL Reputation Evasion (LURE).  

Recently, we have seen a number of breaches in headlines that fall into the category of highly evasive threats, including Legacy URL Reputation Evasion (LURE), wherein attackers evade URL filtering security defenses by creating or infiltrating trusted websites with malware, flying through web filters that attempt to categorize domains based on trust. Using similarly evasive techniques, SEO poisoning is a type of cyberattack that attempts to exploit SEO algorithms for malicious purposes. It involves the manipulation of website content and code in order to raise its ranking on search engine results pages (SERPs). For example, researchers have seen the top result for a Honda manual lead to a Russian cybercriminal site, highlighting that the scale of SEO poisoning is at a level we haven’t seen in previous years. A recent example of a threat that evaded security tooling was seen in the recent Ducktail malware campaign, in which threat actors sent out malware camouflaged as a PDF file hidden among images of authentic products from well-known companies. In this case, cybercriminals strategically evaded detection tools by infiltrating trusted images and links.  

Highly Evasive Adaptive Threat campaigns are well-crafted, thought out, and have very high success rates. Cybercriminals don’t like reinventing the wheel if they don’t have to, and we will surely see an increase in these types of attacks in 2024 due to this proven success rate. Because of this, organizations must consider advanced browser security solutions that can thwart these attacks.”

PREDICTION #2: “Browser Security Will be on the Roadmap of Every CISO”   

“The browser will continue to be a conduit for highly evasive threats. We are not necessarily witnessing an increase in frequency of attacks, but rather attacks that are far more effective, despite the continued investment in security infrastructure. According to Gartner, worldwide end-user spending on IT security is projected to total $215 billion in 2024, an increase of 14.3% from 2023. Organizations are spending billions of dollars on security tooling, yet security attacks continue to make headlines daily. CISOs recognize the danger of highly evasive threats and are addressing browser security as part of their strategic plans for 2024 and beyond. However, there are multiple routes to consider.  

Enterprise browsers, separate and controlled browsers for use in corporate environments, are gaining a lot of market momentum. In a tight economy, Palo Alto is buying Talon for $625M. Island.io has raised $285M and even giants like Microsoft and Google are updating their browsers with enterprise browser capabilities. This rich market is a recognition of the importance of browser security, however CISOs are already grappling with an ever-expanding attack surface. Adding another browser only compounds this issue. Add that to how difficult it can be to ensure seamless integration between your SaaS applications and the enterprise browser, and they are now faced with a hefty decision on how to construct the right architecture.  

Despite the hype, enterprise browsers are currently limited to unmanaged devices, by contrast, hundreds of thousands of corporate devices are not installing a new browser, resulting in a mismatch of security posture that still needs to be reconciled. As much excitement as there is in the enterprise browser market, this solution still leaves a significant gap and adds unnecessary complexity.   

To secure the browser, CISOs will look to different offerings that go beyond installing a new enterprise browser. From cyber teams’ ability to manage existing browsers like Chrome and Edge to browser extensions for the last-mile security, browser security is the hot item on every security leader’s agenda. CISOs and their teams will be focused on determining which approach secures their infrastructure the best without adding more attack surface.”

PREDICTION #3: “Despite Companies Pushing for it, Many employees are not Going Back to the Office Full Time”  

“The work-from-home revolution that started during the pandemic has already lasted much longer than most people originally planned. Despite what many corporate leaders may envision, no enterprise company is going to have 100% of its workforce back in the office full time – all day, five days a week. According to a recent Pew Research study, 35% of workers who can work remotely are doing so full-time, up from only 7% before the pandemic. Although these employees are slowly trickling in year by year – 43% who can work remotely did so full-time in January 2022 and 55% in October 2020 – it is impossible to go back to a pre-pandemic work reality.   

Although many large companies are implementing new in-person mandates, we will not see a mass migration back into the office in 2024 for most companies, specifically for SMBs. Since a hybrid workforce is here to stay, enterprises need to ensure the workers are productive independent of their location. Browser security, zero-trust access to enterprise applications, and SaaS security will continue to be center stage in 2024.”

Fredy Pardo, Field CISO, Identity Hygiene company SPHERE, offers two more security concerns for 2024.

PREDICTION #1: Security strategies will shift from “Trust but Verify” to “Never Trust, Always Verify”

Organizations are re-evaluating their Privileged Access Management approaches. The traditional approach most companies embraced was to “trust but verify,” which is when a user is automatically trusted once they are logged into a system. But cyber-attacks have gotten more complex, and cybercriminals are evading detection as they weave themselves past the initial access point. The traditional boundaries that have kept out unwanted access are no longer effective.

In 2024, organizations will move to a model of “Never Trust, Always Verify” as a more secure and flexible IAM principle. The reality is that the vast majority of cyber-attacks have been launched by using weak, default, stolen and/or compromised credentials. There needs to be a true shift to Zero Trust for organizations to limit the chance and impact of a data breach.

PREDICTION #2: Identity-centric security is a key way we can stop data breaches

Identity and access management has become a business-critical function as securing access to company  resources is more complicated than it’s ever been. Identity-centric security – in which access to corporate resources are determined based on identity and specific attributes – will be at the top of every CISOs list of priorities in 2024 as privileged access accounts continue to provide a perfect gateway for data breaches.

In particular, organizations with a mid to high level of maturity are considering Privileged Access Management (PAM) as a baseline for strong, identity-based access as a starting point to prevent unwanted controls. Under a Zero-Trust strategy, security teams will continue to implement “Just-in-Time” access controls, including a clear verification of who is granting access, who is requesting access and what context the request was made in. In 2024, security teams will limit admin rights even more, following the principle of “Least Privilege,” since this approach has been found time and time again to eliminate implicit static administrative trust, reducing inherit risk.

Related Content

  1. Disaster Recovery Journal
    Working From Home
  2. How To Protect Remote Employees from the Unique Risks They Face
  3. Disaster Recovery Journal
    Cascading Crises: What Does Business Continuity Look Like Over the Next 12-18 Months?

Recent Posts

NVIDIA Nemotron 3.5 Lightning Is Live on DeepInfra: Day-Zero Access to the Fastest Open Model for Agents

August 11, 2026

CData Software Named to Inc. 5000 List, the Most Prestigious Ranking of America’s Fastest-Growing Private Companies

August 11, 2026

Healthcare Cybersecurity: From IT Issue to Operational Resilience

August 11, 2026

KnowBe4 Celebrates 16th Anniversary by Sponsoring Coral Regrowth and Adopting 16 Beehives

August 10, 2026

Echovane Raises Funding to Make Complex Market Research a Done-For-You AI-Native Service

August 10, 2026

AI Voice-Cloning Attacks Expose a Business Continuity Blind Spot

August 7, 2026

Archives

  • August 2026 (31)
  • July 2026 (83)
  • June 2026 (78)
  • May 2026 (67)
  • April 2026 (70)
  • March 2026 (89)
  • February 2026 (76)
  • January 2026 (61)
  • December 2025 (45)
  • November 2025 (58)
  • October 2025 (78)
  • September 2025 (65)
  • August 2025 (59)
  • July 2025 (70)
  • June 2025 (54)
  • May 2025 (59)
  • April 2025 (90)
  • March 2025 (57)
  • February 2025 (47)
  • January 2025 (73)
  • December 2024 (82)
  • November 2024 (41)
  • October 2024 (87)
  • September 2024 (61)
  • August 2024 (65)
  • July 2024 (48)
  • June 2024 (55)
  • May 2024 (70)
  • April 2024 (79)
  • March 2024 (65)
  • February 2024 (73)
  • January 2024 (66)
  • December 2023 (49)
  • November 2023 (80)
  • October 2023 (67)
  • September 2023 (53)
  • August 2023 (72)
  • July 2023 (45)
  • June 2023 (61)
  • May 2023 (50)
  • April 2023 (60)
  • March 2023 (69)
  • February 2023 (54)
  • January 2023 (71)
  • December 2022 (54)
  • November 2022 (59)
  • October 2022 (66)
  • September 2022 (72)
  • August 2022 (65)
  • July 2022 (66)
  • June 2022 (53)
  • May 2022 (55)
  • April 2022 (60)
  • March 2022 (65)
  • February 2022 (50)
  • January 2022 (46)
  • December 2021 (39)
  • November 2021 (38)
  • October 2021 (39)
  • September 2021 (50)
  • August 2021 (77)
  • July 2021 (63)
  • June 2021 (42)
  • May 2021 (43)
  • April 2021 (50)
  • March 2021 (60)
  • February 2021 (16)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Fall 2026
    • Spring 2026

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal (DRJ) is the leading resource for business continuity, disaster recovery, crisis management, and risk professionals worldwide. With a global network of more than 138,000 practitioners, DRJ delivers essential insights through two annual conferences, a quarterly digital magazine, weekly webinars, and a rich library of online resources at www.drj.com. Our mission is to empower resilience professionals with the knowledge, tools, and connections they need to protect their organizations in a fast-changing world. Join our community by attending our events, subscribing to our publications, and following us on social media.

    LEARN MORE

    LINKEDIN AND TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates

    LinkedIn

    @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2026 Disaster Recovery Journal
    • Terms of Use
    • Privacy Policy

    Register to win a Free Pass to DRJ Fall 2026 | Resilience In Motion

    Leave your details below for a chance to win a free pass to DRJ Fall 2026 | Resilience In Motion. The winner will be announced on August 31. Join us for DRJ's 75th Conference!
    Enter Now