Artificial Intelligence & Machine Learning
,
Cybercrime
,
Fraud Management & Cybercrime
CISO Liability, AI, Ransomware and Shadow IT
British attorney Jonathan Armstrong examines four cybersecurity legal trends that will shape 2024: heightened personal liability for security leaders, the impact of ransomware, legal and ethical concerns about AI, and the influence of shadow IT, especially regarding messaging apps.
See Also: OnDemand | Understanding Human Behavior: Tackling Retail’s ATO & Fraud Prevention Challenge
In 2023, the mutating nature of ransomware became a challenge for cybersecurity response, Armstrong said. Ransomware gangs shifted to “one to many” attacks, targeting third-party vendors to make multiple corporations vulnerable.
Armstrong advised CISOs to prioritize vendor vulnerabilities and consider even lower-tier vendors with sensitive information. Regulatory pressures make data breaches a “competitive sport,” as regulators grade organizations against each other. Ransomware gangs exploit this by making reports about their attacks, showcasing a more ruthless and educated approach.
To combat this, CISOs need to adapt training strategies, focus on the evolving threat landscape, and collaborate with vendors for due diligence and contractual measures.
In a video interview with Information Security Media Group, Armstrong discussed:
- How the landscape of personal liability for CISOs will evolve in 2024;
- The evolution of ransomware and its impact on CISOs;
- What legal challenges and ethical considerations arise as AI plays an increasingly crucial role in the space.
Armstrong, an experienced lawyer with Cordery in London, is an expert on data protection and data security law. He advises multinational companies on risk, compliance and technology.