Category: News

Microsoft disables feature after abuse by threat actors

Application developers relying on Windows’ App Installer feature for distributing software over the web will have to find another vehicle, after Microsoft disabled a key protocol because it is being abused by threat actors.

Microsoft said Thursday it has disabled the ms-appinstaller protocol handler by default because at least four groups have been using it in the past two months to distribute malware.

It’s the second time in two years that Microsoft has blocked this protocol because of abuse.

The protocol allows developers to send links that start with ms-appinstaller:// rather than the more familiar http:// or https://  to trigger Microsoft’s App Installer system that orchestrates a download process.

Not only are threat groups abusing the protocol, multiple cybercriminals are also selling a malware kit as a service that abuses the MSIX file format. These threat actors distribute signed malicious MSIX application packages using websites accessed through malicious advertisements for legitimate popular software.

“Threat actors have likely chosen the ms-appinstaller protocol handler vector because it can bypass mechanisms designed to help keep users safe from malware, such as Microsoft Defender SmartScreen and built-in browser warnings for downloads of executable file formats,” Microsoft says.

In one example of abuse, a gang is spreading malware by fooling people using search engines to find legitimate software such Zoom, Tableau, TeamViewer, and AnyDesk. Victims who click on links to these sites after doing a search go to a landing page spoofing the original software provider’s landing pages that include links to malicious installers through the ms-appinstaller protocol. The victim sees a popup box that says, for example, “Install Zoom?”. The box includes an “Install” button. One tip this is a scam: The box says the app publisher is “Legion LLC” instead of Zoom Communications.

Another gang is distributing so-called versions of Adobe Acrobat Reader. It first serves a message that the victim’s computer needs an update. A popup box says “Install Adobe Protected PDF Viewer?” Again, one sign this is a fraud is the Publisher is an unknown company instead of Adobe.

Infosec leaders should warn employees about the risks of downloading and installing applications without approval. Users should also be educated to use the browser URL navigator to validate that, upon clicking a link in search results, they have arrived at an expected legitimate domain. They should also be told to verify that the software that is being installed is expected to be published by a legitimate publisher.

It also helps to have phishing-resistant authentication processes.

The threat actors using this tactic are Storm-0569, Storm-1113, Sangria Tempest, and Storm-1674.

The post Microsoft disables feature after abuse by threat actors first appeared on IT World Canada.

Cybersecurity Year in Review 2023: A zero-day nightmare

There’s usually a word or phrase that sums up my annual Cybersecurity Year in Review.

“Lack of resilience” was 2022’s theme, highlighting the Canada-wide outage at Rogers Communications. “A crazy mess” was 2021’s theme, because of the SolarWinds Orion and other supply chain hacks.

This year, successful ransomware attacks hit a record level. But for me, that only made it the number two story of 2023.

What topped that were the seemingly never-ending admissions by thousands of organizations that their MOVEit file transfer servers had been plucked by the Clop ransomware/extortion gang. It discovered a single vulnerability that opened the doors to data exploitation on a huge scale.

Technically, CVE-2023-34362 is a SQL injection to remote code execution flaw allowing an unauthenticated user to upload a web shell and gain remote access to the database of the applications.

According to stats compiled by Emsisoft, by Dec. 20, this one vulnerability spawned 2,691 hacks and the theft of data on over 91 million people around the world.

Which is why I’ve declared 2023 the Year of A Zero Day Nightmare.

Before we get to the nitty gritty of the MOVEit saga, remember infosec pros should have known that file transfer servers stocked with data have been alluring targets for threat actors for years. In 2021, vulnerabilities in the Accellion FTA application were used to hack servers. At the beginning of the year, customers using Fortra’s GoAnwhere MFT servers were hacked.

In fact the Clop/Cl0p gang went after all three file transfer suites. Do you see a pattern here …?

Add this: According to researchers at Kroll LLC, Clop members were likely experimenting with ways to exploit the MOVEit vulnerability as far back as 2021, before they figured out how to exploit GoAnywhere MFT. For some reason — probably realizing the pickings were much bigger with MOVEit — the gang decided to first go after GoAnywhere servers.

Progress Software’s MOVEit is an on-premises or cloud application that compresses, encrypts and transfers large files. Customers often use it to send files to third parties like payroll processors. In fact, many organizations had their customer or employee data stolen not directly from their servers, but from third-party processors. For example, the compromise of MOVEit at National Student Clearinghouse, a nonprofit that provides reporting and verification services to American post-secondary institutions, affected nearly 900 schools and 51,000 people. Colorado State University was one of those institutions. In fact CSU was victimized six times through different providers.

Of the stolen data on 91 million people, the biggest chunk, 11.3 million, came from Maximus Inc., which administers many U.S. federal, state, and municipal programs. The second biggest (8.9 million) came from Welltok Inc., a provider of support services to a number of U.S. health plans like Blue Cross. The third biggest (6.9 million) was from Delta Dental, a provider of dental insurance plans. The eighth biggest (3.4 million) was theft from BORN Ontario, a Canadian non-profit registry of mothers, newborns, and children, with data going back to 2010.

According to KonBriefing Research, the vast majority of victim organizations (2,290) were in the U.S.. Canada was second (152).

Interestingly, Clop’s strategy was to forgo the complexity of deploying ransomware. The gang just stole data and tried to extort victim firms. It isn’t known how many capitulated.

IT departments were seemingly defenceless. Or oblivious to suspicious activity (see this Kroll report).

“The MOVEit product is often used to exchange information with other companies, which makes it difficult to protect the server from the internet,” Johannes Ullrich, head of research at the SANS Institute, told IT World Canada. “For a zero-day, it is also difficult to develop any kind of web application firewall rules or other rules to protect the server. Log monitoring may have shown some of the exploit activity, but not knowing what to look for makes it difficult to identify the activity.

“So in short, this was a hard vulnerability to avoid. Some victims may have been slow to apply the patch (and maybe sloppy looking for exploitation after the vulnerability became known).”

Traditionally at this point, after naming the top story of the year, this piece lists notable hacks from the previous 12 months. If there’s enough information released by the victim firms, there are lessons CISOs can learn from some of these incidents — rank your IT assets and prioritize patching, change default passwords on network devices like routers, force employees to use app-based multifactor authentication or security keys for logins, have a practiced incident response plan, have a practiced data recovery plan. These lessons can be neatly summed up as “Obey Cybersecurity 101.”

But before briefly recounting those incidents to CISOs and CEOs, I draw attention to two investigations into attacks this year: One was by the U.S. Cyber Safety Review Board into the reasons behind and lessons learned from the successful hacks of the Lapsus$ gang. (Two members of the gang were just sentenced by a U.K. judge)

The board is a wing of the U.S. Cybersecurity and Infrastructure Security Agency. Composed of public and private experts who talk behind closed doors with victim firms, its mandate is to look into and report on the causes of significant cyber incidents.

Here are a few quotes from the Lapsus$ report: “If richly resourced cybersecurity programs were so easily breached by a loosely organized threat actor group, which included several juveniles, how can organizations expect their programs to perform against well-resourced cybercrime syndicates and nation-state actors?”

“The board found that the multi-factor authentication (MFA) implementations used broadly in the digital ecosystem today are not sufficient for most organizations or consumers. In particular, the board saw a collective failure to sufficiently account for and mitigate the risks associated with using Short Message Service (SMS) and voice calls for MFA.” Its advice: Make employees use an authenticator app or a security key. The report is also critical of wireless carriers for too easily allowing crooks to get away with SIM card swaps.

Another report that made interesting reading was the unclassified version of an investigation by the Inspector General of the U.S. Air Force into a low-level Airman’s access to restricted information he allegedly leaked to a political discussion group. It’s is a lesson about an insider threat and the importance of determining the need to know.

Now here’s that recap of some of the year’s other interesting news:

As I said earlier, the number two news story of the year was the continued soaring number of ransomware attacks. By the count of NCC Group, the number was over 4,000, twice as many as last year. Sometimes it was hard for reporters to keep track, as companies or municipalities announced they had suffered a “cybersecurity incident.” Others said they had suffered an “encryption event,” thus avoiding the “r” word.

Among the Canadian victims: Ontario’s Liquor Control Board, bookstore chain Indigo, a service provider to five Ontario hospitals and the Toronto Public Library. According to The Globe and Mail, the library still can’t check out or return books via its computer system.

Others hit by ransomware around the world included supersports car manufacturer Ferrari and MGM Resorts in Las Vegas.

A California law enforcement agency paid just over US$1 million to a ransomware gang after it was hit early last month. The Los Angeles Times reported that the San Bernardino County Sheriff’s Department and its insurance carrier split the cost so the department could get access to its data. The department had to shut down its email, in-car computers and a system deputies use for background checks.

Some gangs took pity after hitting victims that might arouse public anger, like hospitals. For example, at the beginning of the year, the LockBit ransomware crew gave Toronto’s Hospital for Sick Children a decrypter key so it could restore scrambled data.

However, others found new strategies for squeezing victims for money. The AlphV/BlackCat gang created a website that mimicked an unnamed financial company it hit that refused to pay. The message on the site: This company was hacked and here’s all of its data.

According to threat researcher Brett Callow of Emsisoft, the Medusa gang created a 51-minute video of screenshots of data allegedly copied from the Minneapolis Public School system to show the world it really had stolen data.

In September, I moderated a panel on ransomware at the annual SIBOS conference of the Swift IT messaging financial network, where one panelist declared ransomware is a crisis.

Law enforcement agencies did score some successes against ransomware and other cyber crooks. At least some of the AlphV/BlackCat gang’s infrastructure was taken down. (The gang says in retaliation it will show no mercy to critical infrastructure.) The FBI took down the Hive ransomware gang. It also arrested the alleged head of Breached Forums. The alleged perps behind DoppelPaymer ransomware gang were arrested. The RCMP and the FBI took down the Genesis criminal market. Police in Europe took down a gang specializing in business email compromise scams. The Five Eyes intelligence co-operative worked to take down the Snake malware network. And the suspected developer of the Ragnar Locker gang was nabbed in Paris.

BlackBerry CEO John Chen left the Canadian company after a decade at the helm. His effort to shift what was once the leading mobile device manufacturer into a leading cybersecurity company failed.

Considering the challenges Chen faced when he arrived — the rise of Apple’s iPhone and the failure of the BB10 operating system to catch on, “he really has done a good job,” said Brian Jackson, a research director at InfoTech Research. But while Chen bought endpoint provider Cylance in 2019 to add to its mobile device management platform, Jackson said enterprises saw the company as a point solution. On the enterprise side, partnerships were needed, Jackson said. A promising 2018 deal with Amazon, Jackson added, “never got off the ground.” By contrast, he added, Chen forged many partnerships to sell its IoT portfolio, particularly to car manufacturers.

Huge victims of hacks included two American communications providers. T-Mobile had to notify 37 million customers of a data theft.  Comcast Communications notified over 35 million of its subscribers of a data breach. On Oct. 10, it was notified that Citrix Netscaler Application Delivery Controllers needed to be patched, followed by more details on Oct. 23. Comcast acted. But not fast enough.

A Canadian supermarket chain said the total impact of the cyber attack it suffered could be over $54 million. 

Canadian Prime Minister Justin Trudeau confirmed that a Canadian pipeline was impacted in some way by a Russian hacktivist. No details were forthcoming. Separately, Canadian energy producer Suncor reported a cyber attack. Microsoft reported a Chinese group going after American critical infrastructure. Microsoft also reported a China-based threat actor was able to access the cloud-based Microsoft email accounts of approximately 25 organizations — including government agencies, as well as related consumer accounts of individuals likely associated with these organizations — by forging authentication tokens.

In one of the most creative attacks of the year, an unnamed criminal group tried to extort the respected Dragos industrial control cybersecurity company. It compromised the personal email address of a new sales employee before they started work at Dragos. That allowed the crooks to impersonate the new employee and get enrolled with the company online. After failing to elevate access privileges, the gang tried to extort Dragos by threatening to reveal their successful penetration. When that failed, they sent messages to family members of Dragos executives. One big lesson from this incident: Additional identity verification is needed for online onboarding of new staff.

Another imaginative attack: A Russian group spotted a Polish diplomat’s ad to sell a used BMW and turned it into an opportunity to spread malware by cloning the ad and, to get clicks, claiming the price had gone down.

Dressing someone in a uniform — in this case FedEX — will still fool employees, and allow a hacker to slip a USB key into a computer. 

Canadian privacy commissioners made several important rulings. Home Depot Canada was criticized for not getting customers’ consent before sharing details of customers’ e-receipts. But the federal privacy commissioner’s attempt to have Facebook take responsibility for the Canadian part of the Cambridge Analytica scandal under Canadian privacy law was rejected by a judge. That ruling is being appealed.

Looking ahead, in 2024, watch for reports from the U.S. Securities and Exchange Commission into allegations that SolarWinds misled investors about its cybersecurity risks and vulnerabilities relating to the compromise of its Orion software update mechanism in 2020; Canada’s privacy commissioner’s investigation into the data theft of federal employees from relocation companies; and Nova Scotia’s privacy commissioner’s investigation into that province’s MOVEit hack.

Finally, those reading this story should be cheered that, at least according to one expert, an infosec pro has a job for life.

The post Cybersecurity Year in Review 2023: A zero-day nightmare first appeared on IT World Canada.

Predictions 2024: Environmental, Social and Governance

In December, Dubai hosted the 28th United Nations Climate Change Conference (COP28), described by the UN as the world’s only multilateral decision-making forum on climate change.

To put it simply, a UN advisory stated, COP is where the world comes together to agree on ways to address the climate crisis, such as limiting global temperature rise to 1.5 degrees Celsius, helping vulnerable communities adapt to the effects of climate change, and achieving net-zero emissions by 2050.

With an estimated 70,000 delegates in attendance, much was done, leading to the signing of an agreement by 197 nations as well as the EU to deliver what the UN described as a “new era of climate action.

“Today, the Parties agreed (on) a landmark text named The UAE Consensus, that sets out an ambitious climate agenda to keep 1.5°C within reach. The UAE Consensus calls on Parties to transition away from fossil fuels to reach net zero, encourages them to submit economy wide Nationally Determined Contributions (NDCs), includes a new specific target to triple renewables and double energy efficiency by 2030, and builds momentum towards a new architecture for climate finance.”

During his closing speech, Dr. Sultan Al Jaber, president of COP28, stated, “the world needs to find a new way. By following our North Star, we have found that path. We have worked very hard to secure a better future for our people and our planet. We should be proud of our historic achievement.”

The signing of the UAE Consensus means that not only will governments need to double down on their efforts to reach sustainability goals, but organizations of all sizes will have to as well.

With that in mind, consider this from Leah Goldfarb, environmental impact officer with Platform.sh, an enterprise-grade platform for building, running and scaling web applications: In 2024, sustainability IT is poised to take centre stage. “Companies will need to measure their IT footprint to understand where they need to act to reduce emissions to meet their net-zero commitments.

“And following the guidance of the GHG protocol, the reporting on emissions will become standardized. In terms of the cloud, the importance of a location-based approach will shift demand to datacentres that run on low-carbon energy.

“Resource-conscious computing and observability will also become imperative. Organizations that have not already made the switch to high-density cloud computing (e.g., PaaS: Platform-as-a-Service) will need to do so to meet KPIs and sustainability goals.”

In its Predictions 2024 Environmental Sustainability report released last month, Forrester  stated, “the green market revolution involves three key goals for organizations: minimizing their own environmental impact; enhancing the sustainability of current products and services; and developing new environmentally friendly products and services to capitalize on the green market’s potential. Rapidly emerging regulations in environmental sustainability present outsized challenges as well as opportunities.”

The consulting firm predicts that next year the sustainability management software market will double due to compliance needs. “Mandatory requirements,” it contends, “will increasingly require public companies to measure, calculate, and report complex environmental sustainability metrics across their organizations on a consistent basis. Accurate data collecting, carbon accounting and versatile reporting capabilities will demand automation with software.

“Challenges like supply chain decarbonization, emission factors for greenhouse gas calculations, and multiple worldwide regulations will also drive demand. Expect the sustainability management software market to experience upheaval, as niche specialists will need to evolve, partner with larger vendors, or be acquired as the market skyrockets.”

Other organizations also weighed in with ESG predictions for 2024:

Policymakers and technology leaders will finally pay attention to AI’s energy consumption problem: According to Arun Iyengar, the chief executive officer (CEO) of Canadian AI chip maker Untether AI, “Of all the major green think tanks in Canada and the U.S., none of them have written anything of substance about how regulation of AI might/will include incentives for it to be run on greener chips – this will finally come to the forefront of discussions as AI becomes more ubiquitous.”

Fully autonomous vehicles will not make it on the roads in Canada in 2024: Iyengar maintained that the dream of fully autonomous vehicles getting on the road in 2024 will remain a dream. AVs have been ‘around the corner’ for nearly a decade. However, substantial technological hurdles persist – particularly in Canada, where AVs falter in inclement weather.

Next year, we will see many organizations fall behind on their environmental goals as they adopt AI. Brent Allen, vice president and country manager with Pure Storage Canada, predicted, “with  business leaders rushing to adopt AI, many are realizing they are not prepared for its energy requirements.

“The organizations that come out on top will be those that take the time to update their IT infrastructure with energy efficiency in mind before widespread AI adoption. They will be able to leverage AI and maintain a competitive edge without compromising on their commitments to reducing carbon emission.”

Finally, PwC’s 2024 Canadian ESG Reporting Insights, released in late November, indicated trouble ahead for many organizations, as findings revealed that more than four in five companies (81 per cent) do not financially quantify their climate-related risks, and 73 per cent of those surveyed do not fully disclose how they have analyzed and incorporated ESG issues into their long-term strategy.

Sustainability reporting pressures on Canadian companies are becoming even more demanding and complex with the new Corporate Sustainability Reporting Directive (CSRD) mandate for companies both inside and outside the EU, for reporting on ESG issues, PwC noted.

It added, “many Canadian companies are unaware that CSRD applies to them and their obligations under it. Companies that are not prepared to meet the new regulatory requirements will find themselves at risk for not just financial penalties, but also reputational damage.”

The post Predictions 2024: Environmental, Social and Governance first appeared on IT World Canada.

Cyber Security Today, Dec. 29, 2023 – Get cracking on your cybersecurity strategic plan

Get cracking on your cybersecurity strategic plan.

Welcome to Cyber Security Today. It’s Friday, December 29th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



This is my last podcast for 2023. I’m sure this being the last regular workday of the year another report of a data breach isn’t on your mind. So I want to take a few minutes to encourage cybersecurity managers to set some time aside during the long weekend — or even next week when the pace of things will hopefully be slow — to think about your organization’s formal cybersecurity strategy. Not just your patching policy or your plan to refresh software and hardware, but the overall strategy.

Working piecemeal on cybersecurity won’t make your firm better able to withstand attacks.

If you already have a strategic cybersecurity plan, it probably needs the annual honing. So for this episode I want to focus on those of you that don’t have a formal plan.

This isn’t a matter of outlining a few points on a piece of paper by yourself. Or after a meeting with the security or IT team. You can’t create a strategic plan without knowing what cyber risks the business is willing to accept. So to start, plan on scheduling a meeting with your organization’s leaders. Learn what the organization needs, and then their IT needs. And then ask management what level of risk it’s willing to accept for operations. Management also has to set corporate security policies, such as the acceptable use of company-owned devices and who on staff needs extra security login protection such as multifactor authentication.

From there the broad strokes of the plan can be outlined. Is one day of downtime acceptable? Are a couple of hours acceptable? Is only five minutes of downtime acceptable? Remember there will be different performance demands for different applications. Once you understand the business risks, you can delve into the IT side: Inventory the organization’s hardware and software and then do a risk assessment of each component. Design security controls — or get replacement technology — to blunt the vulnerabilities. The strategic plan has to include the corporate security policies set by management, identity and access control management, data management, a backup and recovery plan and a plan for security awareness training.

It also has to include an incident response plan. Some outlines for creating cybersecurity strategies leave this to the last. I think it should be first: After all, 30 seconds after hearing (or reading) this podcast you may be warned your organization is under attack. A good incident response plan starts with choosing who will be on the IR team, creating a contact list and building a response playbook to deal with eventualities your organization will likely face.

Finally, the cybersecurity strategic plan has to be approved by management — and reviewed annually.

I’ve shortened the process — hey, the long weekend is beckoning. But there are lots of articles online that go into greater detail. One of your IT providers may have resources. I relied in part on the book Security Battleground, An Executive Field Manual by Intel Press.

Finally, I want to thank audio producers Don Naylor, James Roy and Miadori Nagai for making me sound good, ITWorldCanada.com editor Lynn Greiner for catching mistakes I make in my copy before news stories are posted on our website, and publisher Jim Love for his support..

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. My next podcast will be Wednesday, January 3rd. Between now and then I’ll post breaking news at ITWorldCanada.com. 

The post Cyber Security Today, Dec. 29, 2023 – Get cracking on your cybersecurity strategic plan first appeared on IT World Canada.

2024 Telecom predictions: 5G, AI, sustainability and messaging trends to guide innovation

Next year, the telecommunications ecosystem will be guided by four key themes: 5G, artificial intelligence, sustainability and the messaging evolution, a report by Juniper Research identified.

Further, experts weighed in on developments in the optical transport, cable and open RAN markets going into 2024.

5G

In a recent report, Ericsson estimated that almost one-in-five of all global mobile subscriptions will be 5G subscriptions by the end of 2023. North America is expected to have the highest 5G subscription penetration globally, at 61 per cent, by the end of 2023.

“The roll-out out of 5G continues and we see an increasing number of 5G standalone networks being deployed, bringing opportunities to support new and more demanding applications for both consumers and enterprises,” said Fredrik Jejdling, executive vice president and head of networks, Ericsson.

Juniper says that the boom in 5G subscriptions, will, in turn, improve the value proposition of 5G satellite-based services, which will take on private networks, IoT and mobile broadband for cellular communications. 

Juniper forecasts that there will be over 300,000 connections accessing 5G satellite networks in 2024, with regions such as North America, Western Europe and Far East and China accounting for approximately 80 per cent of all major satellites in operation today.

This year, we saw leading carriers like Rogers and Telus achieve their first satellite phone calls, paving the way to wireless coverage in remote and underserved areas. 

That said, 5G satellite services will not necessarily be a commercial priority for operators in 2024, but developing this ecosystem in preparation for commercial service will be. For instance, operators must have the pricing of satellite services reflect the pricing of terrestrial services already in use, Juniper noted.

Further, Juniper forecasts that 5G Advanced, the next evolution in 5G technology which is anticipated to launch in 2024, will have significant benefit to the entertainment and education sectors, by providing support for more interactive application use cases.

5G Advanced will also have notable impacts on certain IoT sectors: the specification’s impact on network end node-positioning capabilities will impact the development of autonomous vehicles and ADAS (Advanced Driver Assistance Systems).

Moreover, with 5G roaming connections expected to rise from 35 million in 2023 to 77 million by the end of 2024, the adoption of BCE (Billing and Charging Evolution) 2.0 will increase in 2024. This is because the growth in 5G roaming will exacerbate operator revenue leakage caused by TAP (Transferred Account Procedure), which is ineffective for 5G monetisation.

TAP results in revenue leakage, Juniper said, as operators are limited in the volumes of data they can exchange in TAP files, a major issue when using the protocol for 5G connections, which produce vast amounts of data per connection. 

Further, BCE is expected to enable operators to deploy new charging models that apply premium charges against 5G roaming traffic. Therefore, operators will be able to apply differential pricing for roaming access to different network slices on 5G standalone networks. These network slices will have different KPIs for quality of service, such as latency, allowing enterprises to optimize their purchases of roaming access for their needs.

AI

Generative AI will revolutionize the automation of personalized marketing campaigns in the telecommunications industry, such as individualized product descriptions, social media messages, and email outreach. 

Specifically, Juniper predicts chatbots that leverage generative AI will engage with users with personalized conversations, recommendations and question answering.

Additionally, generative AI will automate user segmentation, enabling enterprises to identify and segment audiences based on demographics and behaviours, to allow them to create more targeted marketing campaigns.

“Moving into 2024, telecom business leaders will need to stay on top of this quickly evolving technology, with AI-powered automation and predictive analytics, AI-enhanced customer interfaces and cybersecurity, and more,” said Manav Gupta, vice president and chief technical officer, technical sales, at IBM Canada.

On a broader scale, Juniper expects network-wide AI implementation to come to the fore in 2024. This will include AI services that can access data from the entirety of the network, from the core to edge nodes, rather than in isolation. Operators will therefore be able to further optimize their network operations, including predictive maintenance and security. 

Juniper also expects tier 1 operators to further integrate AI into all areas of their networks, including the core, RAN, session management, security and location-based services. The most tangible benefit of this network-wide implementation, the research company says, will be the ability for all network areas to communicate in real-time, and adjust network functions accordingly.

AI will also be crucial to developing advanced segmentation solutions that will enable operators to better monetize emerging roaming services.

Juniper research author Alex Webb said, “AI-based segmentation will differentiate enterprise traffic by use case; enabling premium billing of mission-critical 5G standalone connections, thus reducing revenue leakage.”

Messaging evolution

A rise in the pricing of text messaging services and phone frauds will lead to a shift in the mobile messaging landscape in 2024, with businesses and developers exploring alternative communications channels via open APIs, Juniper explained.

The increased use of third party channels such as WhatsApp for Business will also be an ever-growing threat to operators’ mobile messaging revenue. As a result, operators will be forced to increase pricing to compensate for a decline in their revenue.

However, operators are unable to optimally price their messaging traffic due to fraud such as Artificial Inflation of Traffic (AIT) and message trashing that plague text messaging networks. This can further increase enterprises’ spend on SMS due to undelivered messages, or in authenticating non-existent users.

Sustainability

In 2024, Juniper expects operators to focus on new initiatives that look to reduce the impact of the telecommunications industry on the environment. They will, therefore, seek diminished returns on implementing more network virtualization that reduces carbon footprint.

Operators will employ the following to further sustainability:

AI and machine learning– Operators will make efficiency gains by automating the network orchestration of operations and supply chains. 
Sustainable Supply Chains– Operators will invest in new sustainable supply chain practices such as the electrification of delivery vehicles and minimizing the number of required base stations, especially as 6G network launches require the need to deploy new network hardware, additional base stations and more
Energy-efficient equipment and batteries– The introduction of higher frequency bands in spectrum auctions for 5G NSA (Non-standalone) necessitated a greater number of base stations and network cells, which will place pressure on operators to deploy energy-efficient equipment.

Other telecom predictions came from experts at the Dell’oro Group, including:

The Open RAN movement will account for more than 15 per cent of total RAN, despite a short term decline in revenue. The movement allows operators to better manage flattish carrier revenue trends and the increased network complexities that come with their next generation architecture requirements. Virtualization/containerization will be increasingly foundational in this RAN transformation/automation journey. Consequently, many operators are expected to start with cloud RAN plus O-RAN compatible fronthaul, while multi-vendor RAN will be deployed where it makes sense.
The Optical Transport equipment market is on a path to increase 4 per cent before the end of 2023. Entering 2023, vendors had a record level of backlog. But as component supply improved, equipment manufacturers started playing catch-up and delivered a large number of optical systems in the first half of 2023. However, this created excess inventory for service providers, who then started pushing out deliveries to 2024, which is expected to smooth out market revenues. If all backlog had been delivered in 2023, it would have created a glut of optical network capacity entering 2024, resulting in a market contraction and another period of supply/demand imbalance.
Cable operators to improve broadband networks-The emergence of 5G fixed wireless services by industry players like T-Mobile and burgeoning fiber competition are putting pressure on cable operators to expand their broadband throughput and capacity. Efforts will hence be aimed toward network upgrades and DOCSIS 4.0 transition, to boost bandwidth and competitiveness amid industry changes.

The post 2024 Telecom predictions: 5G, AI, sustainability and messaging trends to guide innovation first appeared on IT World Canada.

Predictions 2024 from cybersecurity vendors, Part 2

We’ve collected comments from more than 40 vendors to give infosec pros an idea of what they might face in the next 12 months. Their predictions cover everything from meeting the talent shortage to quantum computing:

More advanced persistent threat groups (APTs) will become more active — even beyond the 138 identified by MITRE and those that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) outlines with active cycles, says Fortinet in its Cyberthreat Predictions report.

These groups will likely engage in dual cybercrime and cyber-espionage activities, the report says. Fortinet also expects to see a trend in which more APT groups will transition to employing even more stealthy, innovative methods to initiate attacks. Techniques such as HTML smuggling are gaining popularity, and Fortinet foresees additional novel methods emerging in the coming year.

“Alongside what’s sure to be a banner year for new Common Vulnerabilities and Exposures (CVEs), we should expect the growth of TTPs and, therefore, the MITRE ATT&CK framework,” the report says.

Margareta Petrovic, global managing partner for risk and cybersecurity consulting and KPS Sandhu, head of global strategic initiatives for cybersecurity, Tata Consultancy Services:

There are over 700,000 cybersecurity job openings in the U.S., and according to some estimates, there is a need for more than 2.7 million cyber professionals globally. The talent gap in cybersecurity has created a dire need for skilled and qualified people to prevent, detect, and respond to novel and ever-growing cyber threats and incidents.

To combat these rising challenges, companies should consider hiring in-house specialists to bolster internal teams, or outsource this work to large external resource companies (consulting firms, cloud providers) to reduce costs and risks. If hiring is not imminently possible, administrators should opt for a managed services provider. The partner can then implement and operate a unified security platform using automated and streamlining processes to strengthen defences against advanced threats while providing complete visibility into the security posture of the enterprise.

Avishai Sharlin, GM, Amdocs Technology:

2024 will mark the year when quantum computing takes one more step towards center stage in a thrilling race between tech giants IBM and Google. As quantum computing accelerates, so does the need for post-quantum-resistant encryption. Public clouds are already adopting innovative mitigation strategies to protect sensitive data in this quantum era.

Sam Curry, VP and CISO, Zscaler:

The security industry will look beyond ‘Zero Trust’ to ‘Negative Trust’. In 2023, zero trust matured in the eyes of security teams and the C-suite, and is continuing to gain traction. But adversaries are also starting to take greater notice of it too and are searching for ways to exploit it. We therefore predict the next evolution of Zero Trust is going to be Negative Trust as a deception methodology. We expect attacks will become less malware-based, as adversaries will want to leverage IT tools and be under the radar of detection. If an adversary has gained access to a zero trust environment by using a stolen identity, organizations still need to avoid damage, and this can happen by deceiving the intruder. The way to achieve this is to put that adversary in an environment where they can’t be sure what is real or not (e.g. simulating that the space houses thousands of applications, but there is actually only handful of real applications in that environment), then traps and tripwires can be set to catch the bad actors in the act.

Mike Lyborg, CISO of Swimlane:

Third-party risk assessment on vendors will be rewritten, driving a further reduction in the tools/system sprawl. On the heels of major third-party breaches in 2023 like MOVEit, third-party risk assessments will move from a check-the-box assessment of tools to a comprehensive analysis of a vendor’s cybersecurity maturity. These assessments will ask more questions specifically about how companies have dealt with vulnerabilities like Log4j or MOVEit to understand the process in place when incidents arise, rather than just analyzing tools in place. With this mindset, more organizations will require a software bill of materials from vendors before purchasing software to fully understand the elements of the technology before adding it to their software stack.

Steve Cobb, CISO of SecurityScorecard:

Organizations that rely on questionnaires alone to assess their vendors’ security posture will be three times more likely to experience a third-party breach. The recent shockwave caused by the MOVEit vulnerability demonstrated an unsettling truth: cyberattacks spare no one, not even organizations boasting formidable security measures. With 98 per cent of companies having a relationship with at least one breached vendor, the conventional checklist approach won’t be enough to properly vet vendors in the new era of third-party risk. But here’s the kicker: most vendors, swamped by questionnaires, do little more than rush through the process, ticking boxes, without the skills or resources to delve deeper into their security programs. In 2024, security teams and vendors will join forces, not as adversaries, but as allies on a mission to identify and manage risk across the digital ecosystem. The days of superficial questionnaires will be replaced by proactive efforts to build a robust security ecosystem, as organizations recognize that true cybersecurity resilience requires a united front against evolving threats.

From Max Shier, CISO, Optiv:

Zero Trust will be solidified as a valid concept that works. Organizations and vendors have had ample time to develop and implement architectures and products to meet zero trust principles now that they understand it just isn’t an industry buzzword – it’s a valid concept that works. Remote work will continue to be prevalent, and zero trust is instrumental in ensuring those remote workers are accessing services and resources in a secure manner. Zero Trust implementation will continue to pick up across all verticals in 2024.

Jerome Becquart, COO of Axiad:

Cybercriminals will increasingly target account recovery methods. With the uptick in phishing attacks and resulting guidance from the U.S. White House Office of Management and Budget, The Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology in 2024, more organizations will strengthen their authentication method by going passwordless. In fact, we’re already seeing this move in the market, with large enterprises including Google and Amazon now offering consumers the ability to log-in more securely with passkeys. While this is a step in the right direction, it’s only half the journey. As the “front door” of the house gets stronger, cybercriminals will shift from stealing credentials (e.g., passwords) to attacking the “back door,” or account recovery methods. For example, let’s say a cybercriminal enters incorrect information on an account five times. The account recovery process then kicks in. If that process involves calling a help desk to answer security questions or answering them online, there’s a good chance hackers will be able to ascertain the information they need to hack their way in by perusing social media. We’re already seeing this happen, but, in 2024, we’ll see an escalation of cybercriminals targeting account recovery methods to compromise credentials.

Joshua Bartolomie, vice-president of global threat services, Cofense:

Organizations will shift to focusing on what they don’t know about their cybersecurity risks, leaning on threat intelligence more than ever. As threats continue to mount due to global conflict and economic pressure, organizations will pivot to analyzing what they don’t know about their cybersecurity risks rather than making assumptions and move past “check the box” strategies. To do this, organizations will need to lean on threat hunters and threat intelligence to find out what should be a focus in their cybersecurity strategies. Threat hunters are like house inspectors who come in and poke at the walls and the foundation to find things that need to be fixed. Good, actionable threat intelligence will help organizations quantify their risk, give context into how threats are delivered and allow security teams to make informed decisions to stay ahead of threats.

Douglas McKee, executive director, software engineering, SonicWall:

Large and small businesses will see a continued increase in Log4j attacks in 2024. Security professionals prefer to forget about past vulnerabilities such as Log4j, as they are often tied to a traumatic time. However, this is exactly what threat actors prey on. While many patches are in place from big-name vendors, and security vendors have issued a wide range of signatures to cover Log4j, it is still one of the biggest supply chain vulnerabilities discovered to date. Due to its position in the supply chain, its continued discovery in new places and its unfortunate continued implementation in new code, it is well worth an attacker’s time. SonicWall’s threat data is trending to demonstrate a potential 10 per cent year-over-year increase from 2022 to 2023 in Log4j-related attacks. By the end of 2024, we predict there will be an even larger increase.

Amitabh Sinha, CEO, Workspot:

The increasing adoption of cybersecurity tools will exacerbate the end-user experience. Zero-day patches, security tool updates, application updates, driver updates, and more, are compromising the user experience every day. Nearly 75 per cent of CISOs say that employees in their organization are frustrated with current security policies that are taking a toll on their productivity. As companies continue implementing these layered security protocols to safeguard their systems, users will increasingly encounter friction in their daily work interactions. This growing user dissatisfaction could pose a significant risk to organizations’ employee retention, and as we move into 2024, we will see workers be more reluctant to tolerate cumbersome software updates, patches, and security measures that hinder their ability to work efficiently. Organizations will need to take a holistic approach that does not compromise security nor the end-user experience to keep their employees happy. This requires tools that help them monitor end-user satisfaction and productivity, and understand the impact of frequent, disruptive updates on their users.

Martin Hedley, advanced cyber security engineer, ISN

The cybersecurity threat landscape is evolving constantly. We have seen supply chain cybersecurity attacks increase in frequency throughout 2023 and anticipate that trend line to keep increasing in 2024, especially as bad actors are also leveraging AI to create more malicious attacks faster than ever before. There are absolutely cybersecurity concerns companies need to be mindful of. First is to determine what security controls are put in place to protect that company’s data when it’s shared with third parties. Also, organizations need to ensure that contractors and vendors have a strong internal security posture that follows industry best practices.

Darren Williams, CEO and founder, BlackFog:
After a record-breaking 2023, we expect that ransomware will not ease anytime soon. Fundamentally, ransomware is becoming the main threat to all organizations, and insurance is no longer a viable option. Action needs to be taken. In 2024 we predict ransomware gangs will look for new ways to force victims into paying. We have already seen gangs contact the SEC directly, reporting victims immediately to inflict maximum damage, forcing regulatory, reputational and class action liabilities. We expect this is just the beginning of several new tactics to maximize payouts. We also expect to see ransomware disrupt major infrastructure through IoT devices and non-traditional platforms. These diverse systems often have limited security designed in and have significant exposure for organizations, particularly in the manufacturing industry.”

Sabrina Gross, regional director of strategic partners, Veridas:
In 2024, deepfake abuse is going to significantly increase. This will become particularly prevalent on social media, especially with elections in the U.S. and EU as well as potentially one in the U.K.. It will become a popular technique among cyber criminals for financial crime, with voice deepfakes being used for phone fraud. As a result, over the next year, customers will expect organizations to have processes in place to prevent fraud and to ensure they are actively investing resources that combat deepfakes.

Dr. John Pritchard, chief product officer, Radiant Logic:
Although privacy and data protection risks were early concerns for AI adoption, we are now seeing greater privacy options available on the market. The bigger concern for most enterprises leveraging GenAI is inaccurate or fabricated answers, otherwise known as chat hallucination, a phenomenon in which Large Language Models (LLMs) generate text that is coherent but is not based on factual or true information. These models can sometimes produce responses which are creative but misleading or entirely fictional. The challenge in natural language processing is to ensure the AI models provide accurate and reliable information without engaging in chat hallucination. This will put pressure on companies to assess and test the accuracy, appropriateness, and actual usefulness before being accepted.

Maurice Uenuma, VP & GM, Americas at Blancco:
New concerns about AI will gain ground in regard to quantum computing and the future of cybersecurity. Enterprises are becoming more aware of potentially significant future impacts of AI on previously well-established data security strategies. For instance, while only theoretical at this juncture, one of the big concerns about AI combined with quantum computing is that there is a possibility that most of what is encrypted at present could be decrypted in the future. As security strategists continue to think through these possibilities in 2024, more enterprises will begin to plan their post-quantum computing strategies along with new, emerging security capabilities to ensure they have security controls that work not just today, but tomorrow as well.

Steve Leeper, VP product marketing, Datadobi:

We predict that an intensified focus on risk management will become a strategic imperative for companies worldwide. Governance, risk, and compliance (GRC) practices are anticipated to receive heightened attention as companies grapple with the complexities of managing access to data, aging data, orphaned data, and illegal/unwanted data, recognizing these as potential vulnerabilities. Moreover, immutable object storage and offline archival storage will continue to be essential tools in addressing the diverse risk management and data lifecycle needs within the market.

Adam Gavish, CEO and co-founder, DoControl:

In the new year, cloud access security (CASB) solutions provided by secure access service edge (SASE) will lose their flavor. Today, SASE solutions secure remote connections so that employees can browse to corporate applications from any network and any device, making the old proxy mode CASB enforcement irrelevant. More organizations are transitioning to SaaS-only operations than ever before, making it harder to secure complex networks. In 2024, we will see security teams advancing to API mode CASBs that understand how SaaS applications work and how SaaS data is modeled, allowing them to enforce and remediate through robust API integrations.

Rajeev Gupta, co-founder and chief product officer, Cowbell Cyber:

Artificial intelligence and machine learning will likely play a significant role in both cybersecurity and insurance. AI can be used to detect and respond to cyber threats more effectively, and it can also help insurance companies assess and manage risk more accurately. Multifactor authentication (MFA) will likely get universally implemented. There will not be any SaaS or Cloud solution that will accept only a single-factor authentication. Biometric authentication and other forms of advanced identity verification will become more prevalent, enhancing security measures.

The post Predictions 2024 from cybersecurity vendors, Part 2 first appeared on IT World Canada.

OpenAI predictions for 2024: Hashtag Trending Holiday Byte for December 27, 2023

TRANSCRIPT

Hey, it’s Jim Love, your host of Hashtag Trending. Welcome to another edition of Holiday Bytes. There’s been a lot of chatter about what’s happening at OpenAI, driven by some postings on the OpenAI site and some items that got posted and then disappeared.

Sam Altman, OpenAI’s CEO, has shared a roadmap featuring enhanced reasoning, the debut of GPT 5, improved voice models, and some exciting new features including ChatGPT with memory.

Now, based on all of that, here are some predictions for OpenAI in the coming year.

These predictions, while focused on chat GPT, highlight the fierce competition in AI. With players like Anthropic’s ClodeAI, Google’s Gemini, and emerging open-source alternatives like Mistral AI, the race is heating up. Altman’s roadmap, though groundbreaking, is just the entry ticket to this new competition.

Enhanced reasoning, a new frontier.

ChatGPT’s eloquence masks a key limitation. It lacks real reasoning. It knows the likely next word, it seems very real, but it doesn’t truly understand what it’s talking about. It doesn’t know truth from fiction. It can’t discern right from wrong. It doesn’t know what it doesn’t know.

And what we see is hallucinations are often just ChatGPT veering off course, confidently continuing with the most probable text, regardless of accuracy. Now there are workarounds. Fine-tuning and prompt engineering can help. They mitigate some of the limitations. Techniques like “Chain of Thought” can correct issues and enhance accuracy.

And I’m going to delve into some super prompts later this week for those interested.

You can make it more accurate, but these are just temporary fixes. Recent developments in open-source models are showing promise in logical reasoning. I’ve seen a demo where an open-source model seems to genuinely understand and logically process its responses, and crack some logical problems that would defeat open AI’s 4.5 version.

Now, OpenAI is pushing these boundaries, aiming for a more nuanced and accurate chat GPT. But remember, Altman’s ultimate goal with OpenAI is artificial general intelligence. In a recent interview, he expressed confidence that a large language model could achieve AGI sooner than we think.

GPT 5 is in training.

Expected to outshine chat GPT 4. Altman hinted at this before his departure last year. Mira Murati, now the chief technology officer, had to step in to prevent him from giving away too much in that interview. Now with rivals like Google’s Gemini, open AI is under pressure to stay ahead, especially with the potential enhancements in its image and video processing and logical reasoning.

And don’t let that video reference slide by. Video is going to play a huge role in generative AI going forward. What it can do already from a number of offerings is amazing. It’s a great editing tool right now, and it speeds up production, but it’s going to get better and better in terms of the creation of video.

And there will be synergy between this analysis and production. The more generative AI studies video, the better it’s going to be at producing it.

But video is also an enormous source of unstructured and extremely relevant content, Video can convey so much more information than text going beyond facts to sentiment to emotion and more.

So look to video, not just in terms of creation or editing, but as a new content source for training and what that can do as we move forward towards making AI have an even greater understanding of our emotional as well as our factual needs and behaviors.

ChatGPT with memory

One of ChatGPT’s current limitations is its inability to remember past interactions, even in the same conversation sometimes. This is partially addressed through stored user instructions, but that’s just a temporary fix.

Imagine if ChatGPT could recall all its interactions with you. The possibilities for personalization are now immense. OpenAI is reportedly working on this. Project Sunshine or ChatGPT with memory is what it’s called. This could revolutionize user experience and make it much more personalized and efficient.

However, a significant hurdle to this is – security. I’ve seen demonstrations of how easily chat GPT security can be breached and how prompts can be revealed. So before this memory feature goes live, expect major security enhancements.

Voice interaction: Beyond the Turing Test.

Yeah. If you’ve only used Siri, Alexa or Google for voice commands, prepare to be impressed by OpenAI’s capabilities. You can check it out now.

Their AI can engage in almost human-like conversations.

I’ve actually done an interview with the AI at a conference that I was hosting, and the only giveaway was a slight delay in response, something Google’s Gemini cleverly omitted in its demo.

And this year, voice interactions with AI become even more natural. The integration of the Whisper API suggests a future of hands-free, accurate interactions, and in every native language.

Sign in with OpenAI

Applications using ChatGPT’s API currently involve some cost considerations. Each API call, though inexpensive, can add up, especially with complex calculations or with large user bases. So the proposal for OpenAI’s new login system where costs are tied to the actual end user’s account instead of the developer’s account could be a game changer for developing sophisticated applications

And the app store

Despite being delayed by Altman’s firing and rehiring, the concept of an AI app store remains compelling. Apple reportedly makes 80 billion a year or more from their app store. And if you saw Altman’s developer conference launch, you’ll know, he’s obviously been inspired by Steve Jobs, not just in presentation style, but he studied Jobs’ strategy.

And with OpenAI needing funds for ongoing operations and ambitious projects, I think this idea of the App Store is far from dead. It’s not the sort of genie you could put back in the bottle.

And those are my predictions for 2024 and that’s it for this holiday bite.

And if you want to see more from YouTube, check out the Best of YouTube series that I’m launching this week. I’d love to hear your opinion. I’d love to know whether we should continue it.

We’ll be back with our interview show on the weekend of January 6th and our daily show resumes on January 8th. Until then, wishing you all a fantastic new year.

The post OpenAI predictions for 2024: Hashtag Trending Holiday Byte for December 27, 2023 first appeared on IT World Canada.

Cyber Security Today, Dec. 27, 2023 – A record year for ransomware

A record year for ransomware.

Welcome to Cyber Security Today. It’s Wednesday, December 27th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

 



 

The year isn’t quite over but it’s clear that 2023 hit a record for ransomware attacks. Researchers at NCC Group say that as of the end of November the total number of attacks around the world hit 4,276 — slightly more than twice as many as last year. And December’s numbers haven’t been added.

More year-end numbers to consider: More than 26,000 vulnerabilities were discovered this year, according to researchers at Qualys. However, less one per cent of them were high risk — about 7,000. And of them, only 206 had weaponized code available. These are the ones information security professionals have to pay attention to, because they are the most likely to be exploited. By the way, of those 206 vulnerabilities, just over 32 per cent were involved network infrastructure or web applications. High-risk holes need to be patched or mitigated fast. According to the research, the mean time to exploit vulnerabilities this year was 44 days. However, many times threat actors were able to create an exploit the same day a vulnerability was publicized.

Speaking of the need for fast patching of critical applications, here’s something to ponder: On a podcast earlier this month I reported that a vulnerability in JetBrains’ TeamCity application development platform was being exploited by a Russian-based group. According to a new report from ReversingLabs, a patch for that hole was released in September. But by this month only two per cent of TeamCity administrators had installed it.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Dec. 27, 2023 – A record year for ransomware first appeared on IT World Canada.

HR Predictions 2024: Generative AI, employee experience, remote work and more

Generative AI will continue to influence how HR teams increase productivity and optimize employee experience in 2024, a new report from McLean & Company which surveyed 1,373 business professionals in September 2023, found.

Additionally, experts say HR will continue to focus on optimizing hybrid work as well as attracting and retaining the right talent in 2024.

Generative AI 

Nearly half of HR organizations will seek to build a business case and demonstrate return on investment (ROI) on the implementation of new technologies like artificial intelligence (AI), with a whopping 79 per cent of respondents citing increased productivity and efficiency as the primary reason.

Despite this potential, HR organizations have been slow to assess the new technology, with just 28 per cent reporting they are taking steps to implement generative AI in 2024.

They continue to face numerous roadblocks such as a lack of budget, and skills gaps, as well as inadequate technology. The risks of AI also remain a major concern for many HR professionals, with 32 per cent of respondents citing risk as a reason for not implementing generative AI.

The continued trend of AI in the workplace, primarily for productivity enhancements, requires HR to adopt a dual approach, advised Miriam Connaughton, chief people officer at employee experience platform, Simpplr.

“On one hand, HR should explore and implement AI tools that can improve HR service delivery, enhance the employee experience, and provide predictive insights into turnover and engagement challenges. On the other hand, they need to be proactive in addressing the legal and ethical implications of AI, especially concerning privacy and data security.”

She added that HR professionals must also focus on transparent communication about how AI is used in the workplace and its impact on employees, fostering a culture of trust and ethical AI usage.

The report explained that the key to building trust in HR while navigating change and disruption in 2024 will be to take a data-driven approach to decision-making, and communicating the “why” to leadership and employees. One important part of this, the report said, is qualitative data in the form of the employee voice.

This is even more critical as employees feel increased pressure and uncertainty, with concerns about AI taking over jobs and certain skill sets.

The report said, “employees expect to be involved in initiatives that impact them more than ever, so it’s crucial to engage with employees during the planning and rollout phases of initiatives to capture the employee voice and build trust.”

Connaughton acknowledged that organizations should prioritize a gradual transition when using AI to augment or replace employees’ capabilities, rather than making an overnight change.

Preparing workers for changes related to AI will also require great upskilling and reskilling efforts in 2024, she added.

Employee experience 

Communicating clearly on the company’s AI goals and upskilling needs, in turn, would help HR professionals to maximize employee experience, another major goal in 2024, the report stressed.

“Organizations that prioritize the employee experience are putting it into action by providing employees with interesting and purposeful work and enabling them to perform their tasks without friction, while also ensuring the organization’s values and culture are resonating with employees.”

Focusing on things like diversity, equity and inclusion (DEI), social and environmental sustainability performance, creativity, workforce productivity and the ability to change at scale to capitalize on new opportunities can help augment employee experience.

More practically, Connaughton referred to things like flexible work options, establishing clear career progression opportunities, offering competitive benefit packages, and providing robust employee wellness initiatives, as well as active listening to employee feedback as essential to employee experience.

The report, however, warns against generalizing employee experience. HR functions are advised to gauge the lived experiences of employees, and identify individual, key areas of improvement.

Remote work

Tech big hitters like Meta, IBM, Amazon, and even remote work poster child Zoom have pressed for a return to office (RTO), but the report revealed that location flexibility will not change in 2024.

Most organizations are, in fact, taking a “wait and see approach”, leveraging internal data to inform decision-making, and using that data to communicate the rationale to employees.

“There is too much noise around the pros and cons of remote work for organizations to make informed decisions solely based on external benchmarks or trends,” the report said. “And, ‘because I said so’ won’t cut it with employees who have options; organizations must look internally and listen to employees to understand the needs of different groups and the impact of RTO to facilitate data-driven decision-making.”

There is much economic growth tied to hybrid work, and it is only getting bigger, especially as emerging, younger workers join the workforce, said Dave Drewery, associate director, Work-Learn Institute, during an HRPA conference

“So if any organization wants to fight for talent, and think about how they would survive in a competitive marketplace, they need to be considering hybrid work and what it means for their people,” said Drewery.

Talent acquisition

The job market will be resilient going into 2024, according to research from recruiting agency Robert Half, with 54 per cent of hiring managers planning to add new permanent positions in the first six months of the year, while another 40 per cent anticipate hiring for vacated positions.

Further, capitalizing on top talent laid off from other companies and their own employee turnover were tied, with 48 per cent of hiring managers citing these as factors in their hiring plans, said the research.

2024 is all about opening the aperture for talent, said Susan Tohyama, chief human resources officer, Ceridian. “My prediction – and hope – is that 2024 is the year when organizations make skills-based hiring and internal talent mobility a reality for their workforce. It’s time to help eliminate bias from talent in terms of who should do what job and why. The way to do that is to ensure external hires aren’t prioritized over internal talent mobility, and that hiring focuses on the skills people have.”

During the pandemic, a lot of companies were hiring for quantity, while in 2024, the quality of the hire will be top priority, added Steve Knox, global head of talent acquisition, Ceridian.

Interestingly, research company Forrester noted that tech leaders will turn to shadow HR to upgrade talent acquisition, especially as the shelf life of tech skills becomes even shorter and emerging skills like AI are harder and more expensive to find. Therefore, tech leaders will turn to skills-based talent practices to keep their workforce up to date and adaptive to future demands. 

Retention

A retention plan will be of equal importance for companies, especially as hiring challenges and economic pressures persist in 2024.

Ninety per cent of managers, in fact, cited concerns with retaining top talent for the first half of 2024, the Robert Half report highlighted.

“Though expanding teams will be a big priority for companies in the new year, managers need to focus on the needs and wellbeing of their existing staff too, to boost retention and productivity”, said David King, senior managing director, Robert Half, Canada and South America. “Regular compensation and benefit audits are key to ensuring you remain competitive, and offering perks such as flexibility can help lessen turnover.”

The post HR Predictions 2024: Generative AI, employee experience, remote work and more first appeared on IT World Canada.

Predictions 2024: Artificial intelligence

The hottest topic of 2023, artificial intelligence (AI), has not only generated lots of interest this year, it has pundits of all descriptions coming out of the woodwork with predictions of what will happen in 2024. Their opinions may differ, but they’re in agreement about one thing: the excitement isn’t going to abate any time soon.

Here’s a look at some of their predictions.

……

Observability and IT management software vendor SolarWinds believes that the complexity of today’s enterprise IT environments, along with resource constraints and mounting workloads, is pushing IT teams towards AI-powered automation.

“As AI becomes more sophisticated and its application more widespread – from consumer uses like ChatGPT to impactful enterprise implementations like automated service delivery and anomaly detection – it’s no longer the presence of AI that’s notable, but the application of it,” said Jeff Stewart, vice president of global solutions engineering at SolarWinds.

The company predicts that organizations will embrace Artificial Intelligence for IT Operations (AIOps) to support busy teams, noting that AIOps are paving the way toward autonomous operations, which will require little to no human intervention, and IT Service Management (ITSM) will support faster, more successful IT outcomes using AI-powered tools.

……

Analytics and AI experts at SAS came up with a dozen predictions, noting that AI is everywhere, and “stories are rampant about its promise and its threat.” Here’s a selection of their thoughts.

First, Bryan Harris, chief technology officer at SAS, who took aim at generative AI (GenAI), noting, “GenAI does a lot of things, but it can’t do everything. In 2024, organizations will pivot from viewing generative AI as a stand-alone technology to integrating it as a complement to industry-specific AI strategies.”

Udo Sglavo, vice president of advanced analytics, touched on jobs, saying, “In 2023, there was a lot of worry about the jobs that AI might eliminate. The conversation in 2024 will focus instead on the jobs AI will create. AI helps workers at all skill levels and roles to be more effective and efficient. And while new AI technologies in 2024 and beyond may cause some short-term disruptions in the job market, they will spark many new jobs and new roles that will help drive economic growth.”

But not all is rosy, said Stu Bradley, senior vice president of risk, fraud and compliance solutions. “Even as consumers signal increased fraud vigilance, GenAI and deepfake technology are helping fraudsters hone their multi-trillion-dollar craft. Phishing messages are more polished. Imitation websites look stunningly legitimate. A crook can clone a voice with a few seconds of audio using simple online tools. We are entering the Dark Age of Fraud, where banks and credit unions will scramble to make up for lost time in AI adoption – incentivized, no doubt, by regulatory shifts forcing financial firms to assume greater liability for soaring APP [authorized push payment] scams and other frauds.”

And the CIO will face additional challenges too, added Jay Upchurch, the company’s chief information officer. “CIOs have struggled with ‘shadow IT’ in the past and will now confront ‘shadow AI’ – solutions used by or developed within an organization without official sanction or monitoring by IT,” he said. “Well-intentioned employees will continue to use generative AI tools to increase productivity. And CIOs will wrestle daily with how much to embrace these generative AI tools and what guardrails should be put in place to safeguard their organizations from associated risks.”

……

In the HR realm, “AI will bridge the gap between managers and their direct reports,” said Somen Mondal, general manager, talent intelligence at global human capital management company Ceridian. “In 2024, AI will fill the missing gaps that managers have inadvertently caused. Whether it’s crafting more thoughtful performance reviews or identifying internal growth opportunities for their direct reports, AI will provide much needed support on tasks where managers are either inexperienced or too burnt out to handle. These AI capabilities will help them become stronger managers, in turn allowing them to better empower their direct reports.”

……

Human resources also prompted James Beer, senior vice president operations for digital infrastructure provider Hut 8, and colleague Josh Rayner, vice president of high performance computing, to collaborate on this prediction: “Outside of business, governments – among the largest employers in many Western countries – will also start integrating AI into their systems in 2024 to help manage their extensive human resource functions, service operations, employee training, and launching national-level AI programs. Expect to see governments continue to deliberate and educate the private sector on AI privacy concerns and policies, as they continue to integrate AI into their service operations over the year ahead.”

……

“The future of AI is verticalized,” observed Pete Reilly, COO of enterprise analytics firm AnswerRocket. “From ChatGPT to Bard, we saw our fair share of general-purpose AI tools come to light this year. In 2024, we can expect to see a new wave of AI technology that will be tailored to each industry and individual profession. As opposed to the mainstream conversational AI tools many businesses are using today, tailored AI technologies will be more well-versed in each domain. Both organizations and their employees will be able to obtain reliable and deeper insights to become more productive and strategic than ever before.”

……

Like SAS’s Bradley, Joey Stanford, vice president of data privacy and compliance at Platform as a Service (PaaS) provider for developers Platform.sh, also targeted security. “AI security will not keep up with the potential for threats next year, in part because the broad use of AI is outpacing our collective ability to understand it and establish guardrails. There are many inherent problems with AI models, one being the ability for political agendas and other motives to influence output skewed AI models will continue to create issues in 2024.”

……

Sabrina Gross, regional director of strategic partners at digital identity verification and biometrics authentication vendor Veridas has regulations on her mind. “With the increased use of AI, we will see more discussions and regulation efforts around the world to set up AI safeguards in 2024. We’ve already seen discussions in 2023 with the EU’s AI Act, the U.K. AI Summit and Biden’s Executive Order on AI. However, in 2024, safeguards will begin to focus on how accurately AI performs – especially when these systems do not have enough information or lack clear instruction.”

……

CEO of Canadian AI chip maker Untether AI, Arun Iyengar contemplated government too, but in a different context, noting, “policymakers and technology leaders will finally pay attention to AI’s energy consumption problem.”

His second prediction was a bit more disturbing: “There will be a decrease in humans training AI; AI will start training AI. In 2024, AI will begin getting smart enough to take over these jobs, and AI will be sophisticated enough to start training itself.”

……

Dr. John Pritchard, chief product officer at identity data management firm Radiant Logic said, “much like what we saw with networking, cloud computing and mobile apps, the early market begins with euphoria, followed by a period of diffusion, before becoming mainstream. AI will go through a similar adoption curve through 2024. When it comes to enterprise software specifically, I expect to see major advancements in the augmented workforce as AI accelerates and improves human capabilities. Although there is early concern about AI replacing the human worker, I see augmentation as a bigger near-term change as AI starts to drive hyper-automation. We see this in software development, marketing content generation, document editing and even movie production.”

……

For developers, Elizabeth Lawler, CEO of  developer tool vendor AppMap, predicts, “GenAI and AI coding assistants will move from what some people call “junior developer” level, with a 25-30 per cent code acceptance rate status, to CTO status through embedded context. The ability to add more context, including runtime context, will exponentially increase the value and massively improve the acceptance rate (70 per cent and better) of AI generated code”

……

Finally, Devavrat Shah, Co-CEO and founder of generative AI platform vendor Ikigai Labs predicts yet another twist on GenAI: LGMs. He said, “today, nearly every organization is experimenting with LLMs (large language models) in some way. Next year, another major AI technology will emerge alongside LLMs: Large Graphical Models (LGMs). An LGM is a probabilistic model that uses a graph to represent the conditional dependence structure between a set of random variables. LGMs are probabilistic in nature, aiming to capture the entire joint distribution between all variables of interest. They are particularly suitable for modeling tabular data, such as data found in spreadsheets or tables.

“Enterprises already have tons of time-series data, so it’ll be easy for them to begin getting value from LGMs. As a result, in 2024, LGM adoption will take off, particularly in retail and healthcare.”

The post Predictions 2024: Artificial intelligence first appeared on IT World Canada.