{"id":11332,"date":"2024-01-05T14:41:49","date_gmt":"2024-01-05T11:41:49","guid":{"rendered":"https:\/\/oberig-it.com\/?p=11332"},"modified":"2024-03-06T13:25:43","modified_gmt":"2024-03-06T10:25:43","slug":"cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more","status":"publish","type":"post","link":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/","title":{"rendered":"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more"},"content":{"rendered":"<p>As we bid adieu to 2023, we highlight major trends that impacted cybersecurity professionals in the past 12 months. Learn how the cyber world changed in areas including artificial intelligence, CNAPP, IAM security, government oversight and OT security.<\/p>\n<p><strong>1 &#8211; Excitement over GenAI for cyber defense<\/strong><br \/>\nArtificial intelligence, and generative AI (GenAI) specifically, captured the world\u2019s imagination in 2023, as we all marveled at the technology\u2019s potential for good and evil. Cybersecurity teams were no exception.<\/p>\n<p>Yes, cyberattackers quickly leveraged GenAI for malicious purposes, such as to <a href=\"https:\/\/www.scmagazine.com\/news\/ai-drives-holiday-phishing-scams-as-well-as-email-defenses\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">craft better phishing messages<\/span><\/a>, <a href=\"https:\/\/www.digitaltrends.com\/computing\/hackers-using-ai-chatgpt-to-create-malware\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">build smarter malware<\/span><\/a> and quickly <a href=\"https:\/\/www.technologyreview.com\/2023\/10\/04\/1080801\/generative-ai-boosting-disinformation-and-propaganda-freedom-house\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">create and spread misinformation<\/span><\/a>.<\/p>\n<p>But cyber defenders also saw this powerful technology begin to find its way into their tool boxes \u2013 boosting a broad swath of cyber capabilities, including vulnerability detection, identity and access management (IAM), incident response, malware analysis and security operations.<\/p>\n<p>In short, the optimism over AI\u2019s promise for cyber defense was palpable this year.<\/p>\n<p>Among 3,800 senior executives surveyed for PwC\u2019s \u201c2024 Global Digital Trust Insights\u201d report, 69% said their organizations plan to use GenAI for cyber defense in the next 12 months, while 47% already use it for cyber risk detection and mitigation.<\/p>\n<p>The \u201cState of Cybersecurity 2024\u201d report from the Computing Technology Industry Association (CompTIA), which polled 511 U.S. business and IT pros involved in cybersecurity, shows how respondents foresee using AI.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11298 size-full\" src=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-1-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.png\" alt=\"\" width=\"1214\" height=\"542\" srcset=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-1-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.png 1214w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-1-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-300x134.png 300w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-1-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-1024x457.png 1024w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-1-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-768x343.png 768w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-1-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-24x11.png 24w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-1-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-36x16.png 36w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-1-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-48x21.png 48w\" sizes=\"auto, (max-width: 1214px) 100vw, 1214px\" \/><\/p>\n<p>Tenable, whose products have had AI technology for years, was very much at the center of this trend, as it integrated <a href=\"https:\/\/www.tenable.com\/blog\/introducing-exposureai-in-tenable-one-meet-the-future-of-preventive-cybersecurity\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">GenAI capabilities across the Tenable One Exposure Management Platform<\/span><\/a> in 2023.<\/p>\n<p>\u201cAI has the potential to change how cybersecurity professionals search for patterns, how they explain what they\u2019re finding in the simplest language possible, and how they decide what actions to take to reduce cyber risk,\u201d former Tenable CPO Nico Popp wrote in the blog \u201c<a href=\"https:\/\/www.tenable.com\/blog\/ai-is-about-to-take-cybersecurity-by-storm-heres-what-you-can-expect\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">AI Is About To Take Cybersecurity By Storm<\/span><\/a>\u201d.<\/p>\n<p>For more information about using AI for cybersecurity, check out these Tenable resources:<\/p>\n<ul>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/cyber-exposure\/how-generative-ai-is-changing-security-research\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">How Generative AI Is Changing Security Research<\/span><\/a>\u201d (report)<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/cybersecurity-snapshot-genai-drives-broader-use-of-artificial-intelligence-tech-for-cyber\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">GenAI Drives Broader Use of Artificial Intelligence Tech for Cyber<\/span><\/a>\u201d (blog)<\/li>\n<\/ul>\n<p><strong>VIDEOS<\/strong><\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=jKLmyeCBM1g\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Tenable CEO Amit Yoran discusses AI and preventive security on CNBC<\/span><\/a><\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=N9-l79tycpQ\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">How Generative AI is Changing Security Research: The Development of the G-3PO Tool<\/span><\/a><br \/>\n<a href=\"https:\/\/www.youtube.com\/watch?v=BQsVV8AeKoY\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Making Decisions Easier with AI<\/span><\/a><\/p>\n<p><strong>2 &#8211; And an AI challenge: Using it safely and responsibly<\/strong><br \/>\nHere\u2019s another way in which AI impacted cyber teams in 2023: As organizations rushed to adopt AI to boost business operations, cyber teams \u2013 along with others like IT, GRC and legal \u2013 got tasked with ensuring AI use is secure, compliant and responsible.<\/p>\n<p>No small task. Global AI regulations are in flux, and organizations are scrambling to adopt usage policies. This year, we saw high-profile incidents in which employees inadvertently <a href=\"https:\/\/www.businessinsider.com\/samsung-chatgpt-bard-data-leak-bans-employee-use-report-2023-5\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">entered confidential corporate information into ChatGPT<\/span><\/a>.<\/p>\n<p>McKinsey &amp; Co.\u2019s \u201c<a href=\"https:\/\/www.mckinsey.com\/capabilities\/quantumblack\/our-insights\/the-state-of-ai-in-2023-generative-ais-breakout-year\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">The state of AI in 2023: Generative AI\u2019s breakout year<\/span><\/a>\u201d surveyed 1,684 organizations, of which 913 are using AI in at least one business function. Among those, 548 are using GenAI.<\/p>\n<p>The study found only 21% have GenAI usage policies; only 38% are actively mitigating its cybersecurity risks; and 28% are mitigating its compliance risks.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11301 size-full\" src=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-2-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.png\" alt=\"\" width=\"1077\" height=\"657\" srcset=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-2-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.png 1077w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-2-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-300x183.png 300w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-2-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-1024x625.png 1024w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-2-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-768x469.png 768w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-2-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-24x15.png 24w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-2-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-36x22.png 36w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-2-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-48x29.png 48w\" sizes=\"auto, (max-width: 1077px) 100vw, 1077px\" \/><\/p>\n<p>Of particular interest to cyber teams is the issue of protecting enterprise AI systems from cyberattacks, the topic of the Stanford University and Georgetown University report \u201c<a href=\"https:\/\/fsi9-prod.s3.us-west-1.amazonaws.com\/s3fs-public\/2023-04\/adversarial_machine_learning_and_cybersecurity_v7_pdf_1.pdf\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Adversarial Machine Learning and Cybersecurity: Risks, Challenges, and Legal Implications<\/span><\/a>.\u201d<\/p>\n<p>Here\u2019s a small sampling of advice and recommendations issued in 2023:<\/p>\n<ul>\n<li>ISACA\u2019s \u201c<a href=\"https:\/\/www.isaca.org\/-\/media\/files\/isacadp\/project\/isaca\/resources\/ebooks\/considerations-for-a-generative-ai-policy-1023.pdf\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Considerations for Implementing a Generative Artificial Intelligence Policy<\/span><\/a>\u201d<\/li>\n<li>McKinsey &amp; Co.\u2019s \u201c<a href=\"https:\/\/www.mckinsey.com\/il\/~\/media\/mckinsey\/business%20functions\/mckinsey%20digital\/our%20insights\/what%20every%20ceo%20should%20know%20about%20generative%20ai\/what-every-ceo-should-know-about-generative-ai.pdf\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">What every CEO should know about generative AI<\/span><\/a>\u201d<\/li>\n<li>OWASP\u2019s \u201c<a href=\"https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Top 10 Critical Vulnerabilities for Large Language Model Applications<\/span><\/a>\u201d<\/li>\n<li>Team8\u2019s \u201c<a href=\"https:\/\/team8.vc\/rethink\/cyber\/a-cisos-guide-generative-ai-and-chatgpt-enterprise-risks\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">A CISOs Guide: Generative AI and ChatGPT Enterprise Risks<\/span><\/a>\u201d<\/li>\n<li>\u201c<a href=\"https:\/\/www.ncsc.gov.uk\/collection\/guidelines-secure-ai-system-development\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Guidelines for secure AI system development<\/span><\/a>\u201d from the U.S. and U.K. governments<\/li>\n<li>The Cloud Security Alliance\u2019s \u201c<a href=\"https:\/\/cloudsecurityalliance.org\/artifacts\/security-implications-of-chatgpt\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Security Implications of ChatGPT<\/span><\/a>\u201d<\/li>\n<\/ul>\n<p><strong>3 &#8211; CNAPP takes center stage in cloud security<\/strong><br \/>\nIn the vast cloud security landscape, one development stands out: The accelerated adoption of cloud native application protection platforms (CNAPPs), as cybersecurity teams grapple with growing multi-cloud complexity.<\/p>\n<p>Here are some telling data points from the Cloud Security Alliance\u2019s \u201cCloud Native Application Protection Platform Survey Report,\u201d which was released in August and polled 1,200 IT and security pros:<\/p>\n<ul>\n<li>85% of organizations have either implemented or plan to implement CNAPPs in their cloud environments, a trend driven in part by multi-cloud use<\/li>\n<li>Fewer than 30% of organizations have integrated CSPM, CWP and CIEM across multi-cloud environments<\/li>\n<li>Asked to name CNAPP\u2019s core value proposition, respondents\u2019 top choices were:<br \/>\n&#8211; comprehensive visibility over security posture (25%)<br \/>\n&#8211; data posture understanding and data protection (16%)<br \/>\n&#8211; multi-cloud threat protection (13%)<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-11304 size-full aligncenter\" src=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-3-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.jpg\" alt=\"\" width=\"876\" height=\"384\" srcset=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-3-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.jpg 876w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-3-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-300x132.jpg 300w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-3-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-768x337.jpg 768w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-3-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-24x11.jpg 24w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-3-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-36x16.jpg 36w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-3-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-48x21.jpg 48w\" sizes=\"auto, (max-width: 876px) 100vw, 876px\" \/><\/p>\n<p><em>(Source: Cloud Security Alliance\u2019s \u201cCloud Native Application Protection Platform Survey Report, August 2023)<\/em><\/p>\n<p>To learn more about cloud security and CNAPP, check out these resources from Tenable:<\/p>\n<ul>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/decrypting-cnapp-moving-beyond-the-acronyms-and-analyst-jargon-to-a-unified-approach-to-cloud\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Decrypting CNAPP: Moving Beyond the Acronyms and Analyst Jargon to a Unified Approach to Cloud Security<\/span><\/a>\u201d (blog)<\/li>\n<li>\u201c<a href=\"https:\/\/cloudsecurityalliance.org\/blog\/2023\/07\/25\/navigating-cloud-security-challenges-key-concerns-for-cybersecurity-professionals\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Navigating Cloud Security Challenges: Key Concerns for Cybersecurity Professionals<\/span><\/a>\u201d (blog)<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/five-core-principles-for-hybrid-cloud-security\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Five Core Principles for Hybrid Cloud Security<\/span><\/a>\u201d (blog)<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/webinars\/cloud-security-master-class-november-2023\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">A Cloud Security Master Class<\/span><\/a>\u201d (on-demand webinar)<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/whitepapers\/holistic-security-for-aws-azure-and-gcp\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Holistic Security for AWS, Azure and GCP: Comprehensive Cloud-Native Application Protection for Multi-Cloud Environments<\/span><\/a>\u201d (white paper)<\/li>\n<\/ul>\n<p><strong>VIDEO<\/strong><\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=Ye5G4IA3Xsc\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">What is a Cloud-Native Application Protection Platform?<\/span><\/a><\/p>\n<p><strong>4 &#8211; Cloud adoption further complicates IAM security<\/strong><br \/>\nSecuring identity and access management (IAM) systems, a perennial challenge, remained complex in 2023, largely due to cloud adoption growth.<\/p>\n<p>Here\u2019s a telling stat: Roughly between mid-2022 and mid-2023, 90% of organizations suffered at least one identity breach. That\u2019s according to the Identity Defined Security Alliance\u2019s \u201c2023 Trends in Identity Security\u201d report, which surveyed 529 respondents in charge of IT security or identities.<\/p>\n<p>Why the difficulty in protecting digital identities? Reasons respondents gave included:<\/p>\n<ul>\n<li>A rise in identities driven primarily by adoption of cloud apps<\/li>\n<li>Roadblocks caused by complicated identity frameworks and by complex technical environments<\/li>\n<\/ul>\n<p>Meanwhile, the U.S. Cyber Safety Review Board (CSRB) spotlighted IAM security in its August report of the Lapsus$ cyber extortion group. \u201cIAM weaknesses were a consistent theme in attacks across all targeted entities and present opportunities to make ongoing improvements,\u201d <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-08\/CSRB_Lapsus%24_508c.pdf\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">reads the report<\/span><\/a>.<\/p>\n<p>Recently, Tenable CTO Glen Pendley stressed the importance of securing cloud identities in his Dark Reading article \u201c<a href=\"https:\/\/www.darkreading.com\/cloud-security\/securing-cloud-identities-to-protect-assets-and-minimize-risk\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Securing Cloud Identities to Protect Assets and Minimize Risk<\/span><\/a>.\u201d<\/p>\n<p>\u201cMost attacks we see today are client-side attacks, in which attackers compromise someone&#8217;s account and use their privileges to move laterally and access sensitive data and resources. To prevent this, you need visibility into your cloud&#8217;s identity infrastructure,\u201d he wrote.<\/p>\n<p>For guidance for beefing up IAM security, check out:<\/p>\n<ul>\n<li>IDSA\u2019s \u201c<a href=\"https:\/\/www.idsalliance.org\/identity-defined-security-101-outcomes-approaches\/page\/1\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Identity Defined Security Outcomes and Approaches<\/span><\/a>\u201d best practices<\/li>\n<li>Tenable\u2019s blog \u201c<a href=\"https:\/\/www.tenable.com\/blog\/identities-the-connective-tissue-for-security-in-the-cloud\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Identities: The Connective Tissue for Security in the Cloud<\/span><\/a>\u201d and on-demand webinar \u201c<a href=\"https:\/\/www.tenable.com\/webinars\/strengthen-the-effectiveness-of-your-identity-security-program-with-zero-trust-maturity\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Strengthen the Effectiveness of Your Identity Security Program with Zero Trust Maturity<\/span><\/a>\u201d<\/li>\n<li>CISA\u2019s \u201c<a href=\"https:\/\/media.defense.gov\/2023\/Oct\/04\/2003313510\/-1\/-1\/0\/ESF%20CTR%20IAM%20MFA%20SSO%20CHALLENGES.PDF\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Identity and Access Management: Developer and Vendor Challenges<\/span><\/a>\u201d and \u201c<a href=\"https:\/\/media.defense.gov\/2023\/Mar\/21\/2003183448\/-1\/-1\/0\/ESF%20IDENTITY%20AND%20ACCESS%20MANAGEMENT%20RECOMMENDED%20BEST%20PRACTICES%20FOR%20ADMINISTRATORS%20PP-23-0248_508C.PDF\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Identity and Access Management Recommended Best Practices Guide for Administrators<\/span><\/a>\u201d publications<\/li>\n<li>Cloud Security Alliance\u2019s blogs \u201c<a href=\"https:\/\/cloudsecurityalliance.org\/blog\/2023\/06\/23\/navigating-the-top-10-challenges-in-cloud-identity-and-access-management\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Navigating the Top 10 Challenges in Cloud Identity and Access Management<\/span><\/a>\u201d and \u201c<a href=\"https:\/\/cloudsecurityalliance.org\/blog\/2023\/04\/07\/configuration-and-monitoring-of-iam\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Configuration and Monitoring of IAM<\/span><\/a>\u201d<\/li>\n<\/ul>\n<p><strong>5 &#8211; Known vulns: Everything old is new again<\/strong><br \/>\nAnd in 2023, we re-confirmed that a frustrating scenario continues to play out: Attackers widely exploiting known vulnerabilities for which patches have long been available.<\/p>\n<p>That was a key insight from Tenable Research\u2019s \u201c<a href=\"https:\/\/www.tenable.com\/cyber-exposure\/tenable-2022-threat-landscape-report\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">2022 Threat Landscape Report<\/span><\/a> (TLR),\u201d released in February. Tenable Research found this issue so prevalent that it ranked known vulnerabilities first on the report\u2019s list of 2022\u2019s top vulnerabilities.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11307 size-full\" src=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/known-vulns-everything-old-is-new-again.jpg\" alt=\"\" width=\"1180\" height=\"600\" srcset=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/known-vulns-everything-old-is-new-again.jpg 1180w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/known-vulns-everything-old-is-new-again-300x153.jpg 300w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/known-vulns-everything-old-is-new-again-1024x521.jpg 1024w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/known-vulns-everything-old-is-new-again-768x391.jpg 768w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/known-vulns-everything-old-is-new-again-24x12.jpg 24w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/known-vulns-everything-old-is-new-again-36x18.jpg 36w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/known-vulns-everything-old-is-new-again-48x24.jpg 48w\" sizes=\"auto, (max-width: 1180px) 100vw, 1180px\" \/><\/p>\n<p><em>(Source: \u201cThreat Landscape Report\u201d from Tenable Research, February 2023)<\/em><\/p>\n<p>However, putting all the blame on security teams for not patching these bugs would be naive and simplistic, Tenable CSO and Head of Research Robert Huber cautioned.<\/p>\n<p>\u201cThe lesson here is that the broad array of siloed cybersecurity tools and systems organizations have in place is not helping to reduce risk,\u201d Huber wrote. Instead, cyber teams need a holistic view of their organization\u2019s attack surface to properly manage risk and exposures, he added.<\/p>\n<p>In June, CISA <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-074a\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">disclosed<\/span><\/a> an incident that exemplifies this issue: Multiple attackers breached the web server of an unnamed U.S. federal agency by exploiting known, years-old vulnerabilities.<\/p>\n<p>Further illustrating the challenge of prioritizing vulnerability remediation, CISA\u2019s <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Known Exploited Vulnerabilities (KEV) catalog<\/span><\/a> reached 1,000 items in September. By tracking known bugs exploited in the wild, it\u2019s meant to help vulnerability teams prioritize. CISA<a href=\"https:\/\/www.cisa.gov\/news-events\/news\/kev-catalog-reaches-1000-what-does-mean-and-what-have-we-learned\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\"> marked the milestone<\/span><\/a> in a blog and tackled the question of how to now prioritize \u201cwithin the KEV.\u201d<\/p>\n<p>For more information about detecting, prioritizing and fixing vulnerabilities, check out these Tenable blogs:<\/p>\n<ul>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/you-cant-fix-everything-how-to-take-a-risk-informed-approach-to-vulnerability-remediation\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">You Can&#8217;t Fix Everything: How to Take a Risk-Informed Approach to Vulnerability Remediation<\/span><\/a>\u201d<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/cvssv4-is-coming-what-security-pros-need-to-know\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">CVSSv4 is Coming: What Security Pros Need To Know<\/span><\/a>\u201d<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/mind-the-gap-how-waiting-for-nvd-puts-your-organization-at-risk\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Mind the Gap: How Waiting for NVD Puts Your Organization at Risk<\/span><\/a>\u201d<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/what-is-vpr-and-how-is-it-different-from-cvss\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">What Is VPR and How Is It Different from CVSS?<\/span><\/a>\u201d<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/tenable-2022-threat-landscape-report-reduce-your-exposure-by-tackling-known-vulnerabilities\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Tenable 2022 Threat Landscape Report: Reduce Your Exposure by Tackling Known Vulnerabilities<\/span><\/a>\u201d<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/aa23-215a-2022s-top-routinely-exploited-vulnerabilities\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">AA23-215A: 2022&#8217;s Top Routinely Exploited Vulnerabilities<\/span><\/a>\u201d<\/li>\n<\/ul>\n<p><strong>6 &#8211; The stakes get higher for OT security in critical infrastructure<\/strong><br \/>\nUrgency about the cyber safety of critical infrastructure grew in 2023. Threats multiplied and attacks intensified, <a href=\"https:\/\/spectrumlocalnews.com\/tx\/south-texas-el-paso\/news\/2023\/12\/11\/report--chinese-hackers-targeted-texas-power-grid--hawaii-water-utility--other-critical-infrastructure-\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">especially from nation-state actors<\/span><\/a>, as the attack surface for these organizations expanded due to factors like the convergence of IT and OT systems, and cloud adoption.<\/p>\n<p>In terms of quantity, cyberattacks against critical infrastructure appear to be on the upswing globally, based on many reports that gather these stats for specific <a href=\"https:\/\/statescoop.com\/new-york-775-million-cyberattacks-critical-infrastructure\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">states<\/span><\/a>, <a href=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/australia-says-state-sponsored-cyber-groups-targeting-critical-infrastructure-2023-11-15\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">countries<\/span><\/a>, <a href=\"https:\/\/www.wsj.com\/articles\/record-hacks-on-hospitals-endanger-patients-cyber-official-says-25a7ad3b\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">industry sectors<\/span><\/a> and<a href=\"https:\/\/www.axios.com\/2023\/12\/01\/ransomware-wave-hospitals-schools-mortgages\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\"> attack methods<\/span><\/a>.<\/p>\n<p>The chart below, which tallies actual and projected global attacks costing victims more than $1 million, comes from the study \u201c<a href=\"https:\/\/www.mdpi.com\/1424-8220\/23\/8\/4060\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Impact, Vulnerabilities, and Mitigation Strategies for Cyber-Secure Critical Infrastructure<\/span><\/a>,\u201d published in April by researchers from Florida International University and Utah Valley University.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11310 size-full\" src=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-4-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.jpg\" alt=\"\" width=\"877\" height=\"613\" srcset=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-4-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.jpg 877w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-4-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-300x210.jpg 300w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-4-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-768x537.jpg 768w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-4-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-24x17.jpg 24w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-4-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-36x25.jpg 36w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-4-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-48x34.jpg 48w\" sizes=\"auto, (max-width: 877px) 100vw, 877px\" \/><\/p>\n<p><em>(Source: \u201cImpact, Vulnerabilities, and Mitigation Strategies for Cyber-Secure Critical Infrastructure\u201d study from Florida International University and Utah Valley University, April 2023)<\/em><\/p>\n<p>Governments, worried about these facilities whose services are essential to society and to national security, took steps to boost their cybersecurity.<\/p>\n<p>For example, here are some CISA initiatives:<\/p>\n<ul>\n<li>It launched in March its \u201c<a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-establishes-ransomware-vulnerability-warning-pilot-program\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Ransomware Vulnerability Warning Pilot Program<\/span><\/a>\u201d to help critical infrastructure facilities fend off ransomware attacks<\/li>\n<li>More recently it kicked off a pilot program to <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/piloting-new-ground-expanding-scalable-cybersecurity-services-protect-broader-critical\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">offer them free managed cybersecurity services<\/span><\/a><\/li>\n<li>In October, CISA and other agencies published guidance for <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-10\/Fact_Sheet_Improving_OSS_in_OT_ICS_508c.pdf\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">improving open-source software security in OT environments<\/span><\/a><\/li>\n<li>In November, it launched the \u201c<a href=\"https:\/\/www.cisa.gov\/shields-ready\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Shields Ready<\/span><\/a>\u201d campaign to promote critical infrastructure security and resilience<\/li>\n<\/ul>\n<p>For guidance on critical infrastructure cybersecurity:<\/p>\n<ul>\n<li>\u201c<a href=\"https:\/\/dfrlab.org\/2023\/07\/10\/critical-infrastructure-and-the-cloud-policy-for-emerging-risk\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Critical Infrastructure and the Cloud: Policy for Emerging Risk<\/span><\/a>\u201d (Atlantic Council)<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/how-to-tackle-ot-challenges-asset-inventory-and-vulnerability-assessment\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">How to Tackle OT Challenges: Asset Inventory and Vulnerability Assessment<\/span><\/a>\u201d (Tenable)<\/li>\n<li>\u201c<a href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/Key-OT-security-best-practices\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">7 key OT security best practices<\/span><\/a>\u201d (TechTarget)<\/li>\n<li>\u201c<a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/82\/r3\/final\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Guide to Operational Technology (OT) Security<\/span><\/a>\u201d (NIST)<\/li>\n<li>\u201c<a href=\"https:\/\/www.iansresearch.com\/resources\/all-blogs\/post\/security-blog\/2023\/06\/08\/secure-both-it-and-ot-environments-effectively\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Secure Both IT and OT Environments Effectively<\/span><\/a>\u201d (IANS Research)<\/li>\n<li>\u201c<a href=\"https:\/\/www.tenable.com\/blog\/a-practical-way-to-reduce-risk-on-the-shop-floor\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">A Practical Way To Reduce Risk on the Shop Floo<\/span><\/a>r\u201d (Tenable)<\/li>\n<\/ul>\n<p><strong>VIDEOS<\/strong><\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=dvTRU_O_hnk\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Tenable.ot Security Spotlight &#8211; The Ransomware Ecosystem<\/span><\/a><br \/>\n<a href=\"https:\/\/www.youtube.com\/watch?v=Ko2zZutoAU0\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Tenable.ot Security Spotlight &#8211; Ransomware in OT Systems<\/span><\/a><\/p>\n<p><strong>And a bonus item!<\/strong><br \/>\nThis blog highlights six cyber trends, but it\u2019s the season of giving so here\u2019s one more: the <a href=\"https:\/\/www.sec.gov\/files\/rules\/final\/2023\/33-11216.pdf\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">new cybersecurity-disclosure rules from the U.S. Securities and Exchange Commission<\/span><\/a> that just went into effect.<\/p>\n<p>Adopted in July and finalized with some amendments in September, the rules establish new requirements for publicly traded companies regarding disclosures about their cybersecurity incidents, risk management, strategy and governance.<\/p>\n<p>Their goal? To make cybersecurity disclosures more consistent, comparable and useful for decision-making, which will benefit companies, their investors and the markets, the agency said in a <a href=\"https:\/\/www.sec.gov\/news\/press-release\/2023-139\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">statement<\/span><\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11315 size-full\" src=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-5-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.png\" alt=\"\" width=\"225\" height=\"225\" srcset=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-5-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable.png 225w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-5-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-150x150.png 150w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-5-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-24x24.png 24w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-5-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-36x36.png 36w, https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/risunok-5-tenable-obzor-klyuchevyh-tendenczij-kiberbezopasnosti-v-2023-godu-ot-speczialistov-tenable-48x48.png 48w\" sizes=\"auto, (max-width: 225px) 100vw, 225px\" \/><\/p>\n<p>For example, with some exceptions, companies must disclose cyber incidents four business days after deeming them material, and describe their nature, scope and timing, as well as their actual or potential businesss impact. (In a bizarre pressure tactic, a <a href=\"https:\/\/www.csoonline.com\/article\/1248125\/ransomware-gang-files-sec-complaint-against-company-that-refused-to-negotiate.html\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">ransomware gang filed an SEC complaint<\/span><\/a> against a victim, alleging it didn\u2019t comply with the new disclosure rules.)<\/p>\n<p>\u201cFor a long time, the largest and most powerful U.S. companies have treated cybersecurity as a nice-to-have, not a must have. Now, it\u2019s abundantly clear that corporate leaders must elevate cybersecurity within their organizations,\u201d Tenable Chairman and CEO Amit Yoran <a href=\"https:\/\/apnews.com\/article\/sec-cybersecurity-breach-disclosure-risk-hacking-bb6252463637793bfdc8ace5bfcbe7df\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">told the Associated Press<\/span><\/a> in July. He shared more of his thoughts in this <a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7090467231423205378\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">LinkedIn post<\/span><\/a>.<\/p>\n<p>The new SEC rules are part of a broader trend by governments worldwide to place more accountability for cyber incidents on both <a href=\"https:\/\/www.tenable.com\/blog\/cybersecurity-snapshot-find-mitre-attck-complex-need-help-mapping-to-it-theres-an-app-for-that#:~:text=U.S.%20national%20cybersecurity%20plan%20seeks%20to%20make%20tech%20vendors%20more%20accountable\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">technology vendors<\/span><\/a> and <a href=\"https:\/\/www.sec.gov\/news\/press-release\/2023-227\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">cybersecurity leaders<\/span><\/a>.<\/p>\n<p>To get more details about the new rules, check out this July <a href=\"https:\/\/www.tenable.com\/blog\/faq-what-the-new-sec-cybersecurity-rules-mean-for-infosec-leaders\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">FAQ<\/span><\/a> from Tenable; this <a href=\"https:\/\/www.sec.gov\/news\/statement\/gerding-cybersecurity-disclosure-20231214\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">statement from the SEC\u2019s Division of Corporate Finance<\/span><\/a> director; and <a href=\"https:\/\/www.fbi.gov\/investigate\/cyber\/fbi-guidance-to-victims-of-cyber-incidents-on-sec-reporting-requirements\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">guidance from the FBI<\/span><\/a> and the <a href=\"https:\/\/www.justice.gov\/media\/1328226\/dl?inline\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Justice Department<\/span><\/a>.<\/p>\n<p>Also, check out coverage and analysis from <a href=\"https:\/\/cyberscoop.com\/sec-cybersecurity-incidents-disclosure-rule\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">CyberScoop<\/span><\/a>, <a href=\"https:\/\/www.natlawreview.com\/article\/secs-new-rules-cybersecurity-risk-management-strategy-governance-and-incident\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">The National Law Review<\/span><\/a>, <a href=\"https:\/\/techcrunch.com\/2023\/12\/18\/new-sec-data-breach-disclosure-rules\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">TechCrunch<\/span><\/a>, <a href=\"https:\/\/www.sans.org\/blog\/summary-of-the-new-sec-rules-and-regulations\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">SANS Institute<\/span><\/a> and <a href=\"https:\/\/www.securityweek.com\/sec-shares-important-clarifications-as-new-cyber-incident-disclosure-rules-come-into-effect\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">SecurityWeek<\/span><\/a>.<\/p>\n<p><strong>Source:<\/strong> <a href=\"https:\/\/www.tenable.com\/blog\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we bid adieu to 2023, we highlight major trends that impacted cybersecurity professionals in the past 12 months. Learn how the cyber world changed in areas including artificial intelligence, CNAPP, IAM security, government oversight and OT security. 1 &#8211; Excitement over GenAI for cyber defense Artificial intelligence, and generative AI (GenAI) specifically, captured the [&hellip;]<\/p>\n","protected":false},"author":850,"featured_media":11296,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[142],"tags":[],"class_list":["post-11332","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u261d Oberig IT blog<\/title>\n<meta name=\"description\" content=\"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u26a1 Oberig IT blog for integrator partners, vendors and end customers\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u261d Oberig IT blog\" \/>\n<meta property=\"og:description\" content=\"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u26a1 Oberig IT blog for integrator partners, vendors and end customers\" \/>\n<meta property=\"og:url\" content=\"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/\" \/>\n<meta property=\"og:site_name\" content=\"Oberig IT\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Oberig.disti\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-05T11:41:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-03-06T10:25:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/18.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1875\" \/>\n\t<meta property=\"og:image:height\" content=\"625\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Albekova Paula\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Albekova Paula\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u261d Oberig IT blog","description":"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u26a1 Oberig IT blog for integrator partners, vendors and end customers","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/","og_locale":"en_US","og_type":"article","og_title":"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u261d Oberig IT blog","og_description":"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u26a1 Oberig IT blog for integrator partners, vendors and end customers","og_url":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/","og_site_name":"Oberig IT","article_publisher":"https:\/\/www.facebook.com\/Oberig.disti","article_published_time":"2024-01-05T11:41:49+00:00","article_modified_time":"2024-03-06T10:25:43+00:00","og_image":[{"width":1875,"height":625,"url":"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/18.png","type":"image\/png"}],"author":"Albekova Paula","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Albekova Paula","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/#article","isPartOf":{"@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/"},"author":{"name":"Albekova Paula","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/person\/9d804f9c469169d256ca04bc0446793d"},"headline":"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more","datePublished":"2024-01-05T11:41:49+00:00","dateModified":"2024-03-06T10:25:43+00:00","mainEntityOfPage":{"@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/"},"wordCount":2101,"commentCount":0,"publisher":{"@id":"https:\/\/oberig-it.com\/en\/#organization"},"image":{"@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/#primaryimage"},"thumbnailUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/18.png","articleSection":["Articles"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/","url":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/","name":"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u261d Oberig IT blog","isPartOf":{"@id":"https:\/\/oberig-it.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/#primaryimage"},"image":{"@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/#primaryimage"},"thumbnailUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/18.png","datePublished":"2024-01-05T11:41:49+00:00","dateModified":"2024-03-06T10:25:43+00:00","description":"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more \u26a1 Oberig IT blog for integrator partners, vendors and end customers","breadcrumb":{"@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/#primaryimage","url":"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/18.png","contentUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2024\/01\/18.png","width":1875,"height":625},{"@type":"BreadcrumbList","@id":"https:\/\/oberig-it.com\/en\/articles\/cybersecurity-snapshot-a-look-back-at-key-2023-cyber-data-for-genai-cloud-security-vulnerability-management-ot-cyber-regulations-and-more\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/oberig-it.com\/en\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity Snapshot: A Look Back at Key 2023 Cyber Data for GenAI, Cloud Security, Vulnerability Management, OT, Cyber Regulations and more"}]},{"@type":"WebSite","@id":"https:\/\/oberig-it.com\/en\/#website","url":"https:\/\/oberig-it.com\/en\/","name":"Oberig IT","description":"Distribution of complex IT and information security solutions","publisher":{"@id":"https:\/\/oberig-it.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/oberig-it.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/oberig-it.com\/en\/#organization","name":"Oberig IT","url":"https:\/\/oberig-it.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/06\/logo-new.svg","contentUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/06\/logo-new.svg","caption":"Oberig IT"},"image":{"@id":"https:\/\/oberig-it.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Oberig.disti"]},{"@type":"Person","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/person\/9d804f9c469169d256ca04bc0446793d","name":"Albekova Paula","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/267b2447d88f2254471421efc84e51964ec66e50c0a67b40f9346d135523b971?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/267b2447d88f2254471421efc84e51964ec66e50c0a67b40f9346d135523b971?s=96&d=mm&r=g","caption":"Albekova Paula"},"sameAs":["https:\/\/oberig-it.com\/"]}]}},"_links":{"self":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts\/11332","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/users\/850"}],"replies":[{"embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/comments?post=11332"}],"version-history":[{"count":3,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts\/11332\/revisions"}],"predecessor-version":[{"id":12447,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts\/11332\/revisions\/12447"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/media\/11296"}],"wp:attachment":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/media?parent=11332"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/categories?post=11332"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/tags?post=11332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}