Itโs that time again when everyone and their auntie Ethel get the crystal ball out and start predicting what security threats are going to emerge in the New Year. Iโm not going to do that, for one good reason: we already know what those threats are.
That’s because they’ve been hitting organisations large and small throughout 2024. So rather than hit you with vague concerns of what might be, let me tell you what will be. These are security lessons we must learn from 2024’s attacks, through the lens of news stories I have written for TechFinitive this year.
January: 2FA
The very first article that I wrote this year, back on 9 January, was about two-factor authentication. In particular I explained that popular 2FA app Authy was shutting down the desktop application, the 2FA security issue is one that continued to generate headlines across the year. It will do the same, without question, across 2025.
The lesson I learned from the Authy incident, being a long-time user myself, was that swapping 2FA apps is a right royal pain in the arse. But there’s another lesson here, this time to providers of 2FA systems: until they become less painful to use, users will continue to use the easy and way less secure method of using SMS codes instead.
From a security perspective, this is simply not sustainable. 2FA bypass attacks are on the up,ย new tricks will continue to appear to grab session cookies, and the tech we use into helping.
To be precise, providers must make it easier to configure apps and change from one code-generating platform to another.
In February, I was warning about how the fragmentation of the cybersecurity landscape was weakening defences for organisations across the globe.
I said at the time that I was sceptical about some of the claims in the referenced report, but the use of multiple security tools from different vendors is never going to be conducive to a smooth and seamless security strategy.
Iโm not saying that the onboarding of tools is done at the expense of threat hunting, vulnerability scanning and security awareness training. What I am saying is that it would be far better if integrated solutions removed any doubt.
The security lesson to learn here is that less can often be more. While security layers are a good thing, competing or conflicting security technologies are not.
Iโm going to take the liberty of jumping ahead a few months to May, and my story regarding World Password Day. There are so many lessons to pull out of this one that I hardly know where to start.
How about the notion of having a day every year where people think about taking password security more seriously is laughable? Or at least it would be were organisations not taking it so seriously.
Password security is a year-round thing, but it shouldnโt be. Yes, you heard me: the biggest lesson about password security is that passwords need to die.
Luckily, passkeys are helping with that transition to something better, something more secure. If your organisation hasnโt boarded the passkey bus yet, what are you waiting for?
Another jump, this time to August and a worrying story about how one attack campaign sought to exploit the patch management, or lack of it, the stance of your organisation.
The so-called Windows Update Downdate Attack, explained the researcher who developed it, meant that he was โable to make a fully patched Windows machine susceptible to thousands of past vulnerabilities, turning fixed vulnerabilities into zero-days and making the term โfully patchedโ meaningless on any Windows machine in the world.โ
If that doesnโt worry you, then get in the sea. The security lesson to learn from August 2024? Simply to use recognised patch management solutions for your business and employ a strong security posture to prevent malware infections.
In September, ransomware reared its ugly head. It was inevitable that I should include ransomware threats in this round-up as they are never far away from the headlines or your networks.
This particular article was about a shift in ransomware criminal group tactics, driven mostly by the success of law enforcement in disrupting ransomware infrastructures. As I said at the time: โRansomware-as-a-Service is now the dominant fixture on the threat landscape as far as these extortionist threat actors are concerned.โ
That was, is and shall remain a huge problem.
The lesson to be learned is that pretty much anyone, no matter their level of technical knowledge, can now be a ransomware threat actor simply by renting the process from someone who knows how to do it.
That, in turn, opens up the threat landscape, and unless your attack surface is shrinking through the application of effective ransomware defences, then youโre going to be in trouble sooner or later. Probably sooner.
Organisations must โcontinuously monitor the ransomware ecosystem, identify the groups that pose the most significant risk to them, and use threat intelligence to inform their defensive strategies,โ said Luke Donovan, Head of Threat Intelligence at Searchlight Cyber.
And talking of defensive strategies, one that seems to be undervalued is the not-so-small matter of your incident response playbook.
In October I warned that your incident response playbook is as critical as your infosec defence one. The lesson to be learned here is to pay attention and plan ahead. Please, don’t keep putting this off!
Prepare your communications strategy in advance and communicate clearly with different parties, tailoring your messaging where necessary to manage the aftermath in the medium and long term.
I couldnโt complete a round-up of cybersecurity lessons to learn from 2024 without mentioning AI. Which is why my final look back is just over my shoulder to the start of December, when I shared that one in five werenโt prepared for AI-based cyberattacks.
Say what now, at the end of 2024, really? What cave have they been living in?
Lessons learned? Iโm simply going to conclude by repeating the statistics from that article and let you work what you need to do about it out yourselves. Or you could always ask a generative AI tool to help, I guessโฆ
44% of organisations cited a lack of AI-related cybersecurity training for employees as a critical issue.
43% admitted that they lacked modern AI-powered cybersecurity solutions.
41% struggled with a lack of information from external experts about the evolving AI-related threat landscape.
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.