Site navigation

Cybersecurity in 2024 | The High Cost of Innovation

Graham Turner

,

Cybersecurity trends in 2024
A new report breaks down some key data and insights for what was a tumultuous year in cybersecurity.

In 2024, we saw businesses scramble in a bid to adopt cutting-edge technologies to stay competitive.

A Hiscox report has revealed the cybersecurity cost of this prerogitive, offering a look at some sweeping data from the year. From a rise in cyber-attacks, to growing concerns about reputational damage, the findings underscore the urgent need for robust cyber-resilience strategies if businesses are to move into 2025 ready to embrace the nascent technologies that so defined the year gone in a safe and sensible way.

The 2024 Cyber Readiness report highlights that cyber-risk remains a top concern for business leaders, even as it slips from first to third place among perceived risks in 2023. In a climate of economic instability and intense competition for talent, cyber-risk still ranks higher than economic issues and skills shortages.

Over two-thirds (67%) of companies surveyed reported an increase in cyber-attacks over the past year, with organisations experiencing an average of 66 attacks in 2023/24, up from 63 in the previous year.

Despite heightened awareness, over a quarter (26%) of business leaders admit their organisations lack the financial resources needed to effectively manage cybersecurity threats.

Below, we’ll take a deeper dive into the report’s data to see how 2024 looked for cybersecurity.

Financial and Reputational Fallout

According to the report, the financial impacts of cyber-attacks have grown significantly.

Payment diversion fraud was the most common outcome of attacks in the past year, affecting 58% of organisations – up from just 34% the previous year.

Reputation, however, is a growing focus. Sixty-one percent of business leaders believe reputational damage from a cyber-attack could significantly harm their organisation, while 64% are concerned about losing business if client and partner data is not securely managed.

Among UK businesses, 35% cite avoiding reputational damage as the main driver behind their cybersecurity plans, a higher proportion than in any other surveyed market.

The study also reveals that the primary reasons companies paid ransoms over the past year were to protect customer data, safeguard reputation, and recover critical information. Despite these payments, only 18% of victims were able to fully recover their data, highlighting the limitations of relying on ransom payments as a recovery strategy.

Human and Insider Threats

The report identifies human factors as a major contributor to cyber-risks, emerging as a persistent cybersecurity trend in 2024.

Business email compromise (BEC) remains the leading point of entry for cyber-attacks, followed by cloud servers and employee vulnerabilities.

Alarmingly, employees moved from the fourth to the third most common entry point in the past year, with social engineering techniques such as phishing and spoofing becoming increasingly sophisticated.

Remote work and the use of personal devices have also introduced new risks. Forty-four percent of organisations experiencing heightened cyber risk attribute this to employees using their own devices for work. These devices often lack the robust security measures found in company-issued equipment, increasing the likelihood of malware infections, phishing attacks, and data breaches.

Insider threats are another pressing concern. Forty-two percent of leaders consider threats from employees, contractors, or business partners to be significant. This issue is compounded by the rise in remote work, which creates additional vulnerabilities by decentralising data access and reducing oversight.

Cybersecurity Trends 2024: The Challenge of Emerging Technologies

While technologies like AI, the Internet of Things (IoT), and cloud computing offer opportunities for growth, they also expand companies’ attack surfaces.

Over half (56%) of business leaders believe generative AI (genAI) will significantly impact their cybersecurity risk profile, yet one in four do not see emerging technologies as presenting significant new risks – a perspective that may leave them unprepared for future threats.

Seven-in-ten organisations have already integrated genAI into their operations, and 64% of leaders believe it will play a pivotal role in shaping their cybersecurity approach by 2030.

However, the rapid adoption of such technologies has outpaced the development of adequate security measures, with 32% of firms admitting they are falling behind in implementing necessary cybersecurity tools.

Compounding the issue is a critical shortage of skilled cybersecurity professionals. Over half (52%) of companies report significant challenges in finding qualified talent, while 34% acknowledge that a lack of expertise is compromising their ability to manage risks associated with emerging technologies.


Recommended reading


This skills gap highlights the need for businesses to invest in both technology and training. Security orchestration, automation, and response (SOAR) platforms, for instance, can help mitigate resource shortages by automating complex processes and improving response times.

“Despite perceptions that cybersecurity risks are declining, the reality is quite the opposite – attacks are growing in frequency and complexity, exposing significant gaps in business defences,” said Eddie Lamb, chief information and security officer, Hiscox Group.

“As emerging technologies outpace traditional security measures, many firms are struggling to invest adequately in the right talent, tools and strategies to protect against these evolving threats.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data