Itโ€™s that time again when everyone and their auntie Ethel get the crystal ball out and start predicting what security threats are going to emerge in the New Year. Iโ€™m not going to do that, for one good reason: we already know what those threats are.

That’s because they’ve been hitting organisations large and small throughout 2024. So rather than hit you with vague concerns of what might be, let me tell you what will be. These are security lessons we must learn from 2024’s attacks, through the lens of news stories I have written for TechFinitive this year.

January: 2FA

The very first article that I wrote this year, back on 9 January, was about two-factor authentication. In particular I explained that popular 2FA app Authy was shutting down the desktop application, the 2FA security issue is one that continued to generate headlines across the year. It will do the same, without question, across 2025.

The lesson I learned from the Authy incident, being a long-time user myself, was that swapping 2FA apps is a right royal pain in the arse. But there’s another lesson here, this time to providers of 2FA systems: until they become less painful to use, users will continue to use the easy and way less secure method of using SMS codes instead.

From a security perspective, this is simply not sustainable. 2FA bypass attacks are on the up,ย  new tricks will continue to appear to grab session cookies, and the tech we use into helping.

To be precise, providers must make it easier to configure apps and change from one code-generating platform to another.

February: Fragmentation

In February, I was warning about how the fragmentation of the cybersecurity landscape was weakening defences for organisations across the globe.

I said at the time that I was sceptical about some of the claims in the referenced report, but the use of multiple security tools from different vendors is never going to be conducive to a smooth and seamless security strategy.

Iโ€™m not saying that the onboarding of tools is done at the expense of threat hunting, vulnerability scanning and security awareness training. What I am saying is that it would be far better if integrated solutions removed any doubt.

The security lesson to learn here is that less can often be more. While security layers are a good thing, competing or conflicting security technologies are not.

May: F###ing passwords

Iโ€™m going to take the liberty of jumping ahead a few months to May, and my story regarding World Password Day. There are so many lessons to pull out of this one that I hardly know where to start.

How about the notion of having a day every year where people think about taking password security more seriously is laughable? Or at least it would be were organisations not taking it so seriously.

Password security is a year-round thing, but it shouldnโ€™t be. Yes, you heard me: the biggest lesson about password security is that passwords need to die.

Luckily, passkeys are helping with that transition to something better, something more secure. If your organisation hasnโ€™t boarded the passkey bus yet, what are you waiting for?

August: Patch management

Another jump, this time to August and a worrying story about how one attack campaign sought to exploit the patch management, or lack of it, the stance of your organisation.

The so-called Windows Update Downdate Attack, explained the researcher who developed it, meant that he was โ€œable to make a fully patched Windows machine susceptible to thousands of past vulnerabilities, turning fixed vulnerabilities into zero-days and making the term โ€˜fully patchedโ€™ meaningless on any Windows machine in the world.โ€

If that doesnโ€™t worry you, then get in the sea. The security lesson to learn from August 2024? Simply to use recognised patch management solutions for your business and employ a strong security posture to prevent malware infections.

September: Ransomware

In September, ransomware reared its ugly head. It was inevitable that I should include ransomware threats in this round-up as they are never far away from the headlines or your networks.

This particular article was about a shift in ransomware criminal group tactics, driven mostly by the success of law enforcement in disrupting ransomware infrastructures. As I said at the time: โ€œRansomware-as-a-Service is now the dominant fixture on the threat landscape as far as these extortionist threat actors are concerned.โ€

That was, is and shall remain a huge problem.

The lesson to be learned is that pretty much anyone, no matter their level of technical knowledge, can now be a ransomware threat actor simply by renting the process from someone who knows how to do it.

That, in turn, opens up the threat landscape, and unless your attack surface is shrinking through the application of effective ransomware defences, then youโ€™re going to be in trouble sooner or later. Probably sooner.

Organisations must โ€œcontinuously monitor the ransomware ecosystem, identify the groups that pose the most significant risk to them, and use threat intelligence to inform their defensive strategies,โ€ said Luke Donovan, Head of Threat Intelligence at Searchlight Cyber.

October: Incident response

And talking of defensive strategies, one that seems to be undervalued is the not-so-small matter of your incident response playbook.

In October I warned that your incident response playbook is as critical as your infosec defence one. The lesson to be learned here is to pay attention and plan ahead. Please, don’t keep putting this off!

Prepare your communications strategy in advance and communicate clearly with different parties, tailoring your messaging where necessary to manage the aftermath in the medium and long term.

December: AI

I couldnโ€™t complete a round-up of cybersecurity lessons to learn from 2024 without mentioning AI. Which is why my final look back is just over my shoulder to the start of December, when I shared that one in five werenโ€™t prepared for AI-based cyberattacks.

Say what now, at the end of 2024, really? What cave have they been living in?

Lessons learned? Iโ€™m simply going to conclude by repeating the statistics from that article and let you work what you need to do about it out yourselves. Or you could always ask a generative AI tool to help, I guessโ€ฆ

  • 44% of organisations cited a lack of AI-related cybersecurity training for employees as a critical issue.
  • 43% admitted that they lacked modern AI-powered cybersecurity solutions.
  • 41% struggled with a lack of information from external experts about the evolving AI-related threat landscape.
Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.