Cybersecurity Best Practices: Step Back to Leap Forward

Cybersecurity Best Practices: Step Back to Leap Forward

Cybersecurity best practices require organizations to pause, assess their current position, and plan strategically before moving forward. The ISACA State of Cybersecurity 2024 report offers a data-driven snapshot of where the industry stands today, and the results reveal persistent gaps in workforce readiness, budget allocation, and technology adoption. Understanding these findings is the first step toward building a stronger, more resilient security program.

Anyone who has competed in sports understands two core truths about preparation: if you are not improving, you are getting worse, and luck is what happens when preparation meets opportunity. These principles translate directly to cybersecurity strategy. Organizations that invest time in reviewing past performance, identifying weaknesses, and reallocating resources will consistently outperform those that simply react to threats as they emerge.

The ISACA report, based on a global survey conducted in the second quarter of 2024, highlights several critical trends across workforce dynamics, budget constraints, AI in cybersecurity, and the evolving threat landscape. Each of these areas demands attention from security leaders, CFOs, and business owners who want to stay ahead of adversaries rather than chase them. The question this article answers is simple: what should organizations do now to convert these findings into a stronger security posture?

The cybersecurity workforce is aging, and that creates risk

One of the most significant findings in the 2024 report is a demographic shift in the cybersecurity workforce. For the first time, the largest group of respondents falls between ages 45 and 54, overtaking the 35 to 44 bracket that had long dominated. This aging workforce signals an approaching wave of retirements that could leave critical roles unfilled if organizations do not act now.

Succession planning is no longer optional for cybersecurity teams. Organizations need to identify high-potential employees, create mentorship pipelines, and document institutional knowledge before it walks out the door. The cost of replacing a senior cybersecurity professional is substantial, not just in salary, but in the months of ramp-up time a replacement needs to reach full effectiveness.

Staffing levels are improving, but gaps remain

Staffing data shows modest progress. Thirty-eight percent of respondents now believe their cybersecurity team is appropriately staffed, a two-percentage-point increase over the prior year. However, 43% still report feeling somewhat understaffed. This gap matters because understaffed teams face higher burnout, slower incident response times, and greater vulnerability to social engineering attacks and other threats that exploit human fatigue.

Attracting and retaining talent requires more than competitive salaries. Flexible work arrangements, clear career progression paths, and meaningful professional development opportunities all rank as top priorities for cybersecurity professionals evaluating job offers. Organizations that cut these benefits to save costs risk accelerating the very attrition they are trying to prevent.

Occupational stress threatens cybersecurity team stability

Sixty-six percent of cybersecurity professionals report that their stress levels are significantly higher than they were five years ago. The primary driver is an increasingly complex threat environment where adversaries use sophisticated techniques, attack surfaces expand through cloud adoption and remote work, and regulatory requirements grow more demanding each quarter.

High occupational stress directly undermines cybersecurity best practices. Burned-out analysts are more likely to miss alerts, make configuration errors, and leave their roles entirely. Organizations that fail to address stress risk entering a vicious cycle: departures increase workloads on remaining staff, which drives more departures.

What keeps cybersecurity professionals up at night

The report identifies several specific stressors. Limited remote work options push talented professionals toward employers that offer greater flexibility. Declining employer benefits, including reduced funding for professional development training and fewer flexible scheduling options, erode job satisfaction. Economic uncertainty makes employees reluctant to leave, but their disengagement quietly degrades team performance even if headcount remains stable.

Proactive organizations are responding by investing in mental health resources, setting realistic workload expectations, and creating rotation programs that prevent any single analyst from carrying an outsized share of on-call duties.

Cybersecurity budgets remain underfunded despite growing threats

Budget constraints continue to hamper security programs across industries. Only 36% of respondents say their cybersecurity budgets are appropriately funded, and just 47% expect any increase in the coming year. These numbers represent a troubling disconnect between the escalating threat landscape and the resources allocated to defend against it.

Underfunded cybersecurity programs are forced to make trade-offs that increase risk. Delayed tool upgrades, deferred training, and skeleton-crew staffing during off-hours all create exploitable windows. Security leaders who can translate cyber risk into financial terms, quantifying the potential cost of a breach versus the cost of prevention, stand a better chance of securing adequate funding from executive leadership and boards. Pairing that financial framing with formal risk advisory services gives leadership a credible basis for funding decisions.

Social engineering attacks remain the top threat vector

Despite advances in technical defenses, social engineering attacks continue to be the most prevalent attack type identified in the report. Phishing emails, pretexting calls, and business email compromise schemes exploit human psychology rather than software vulnerabilities, making them difficult to counter with technology alone. The FBI’s Internet Crime Complaint Center has repeatedly documented business email compromise as one of the costliest categories of cybercrime, as detailed in its annual Internet Crime Report.

The one bright spot: non-malicious insider incidents have declined, likely reflecting the impact of effective security awareness training programs. This finding reinforces that investing in employee education delivers measurable returns. Regular phishing simulations, role-based training modules, and clear reporting procedures all contribute to reducing the success rate of social engineering attacks.

AI in cybersecurity is promising but still underutilized

The integration of AI in cybersecurity operations remains in its early stages. Threat detection and response and endpoint security are the two most common use cases, but adoption is far from universal. Many organizations are experimenting with AI-powered tools without fully integrating them into their security workflows or developing governance frameworks to manage their use.

A critical gap exists in professional involvement. Security teams are often excluded from the selection, development, and implementation of AI solutions and policies within their own organizations. This disconnect can lead to tools that do not align with operational needs, policies that overlook security implications, and missed opportunities to apply AI for proactive threat hunting.

Building an AI-ready cybersecurity team

Organizations that want to capitalize on AI in cybersecurity should take three immediate steps. First, include security professionals in every AI procurement and deployment decision. Second, invest in upskilling programs that teach existing staff how to work alongside AI tools, interpreting outputs, tuning models, and recognizing when automation produces false positives. Third, establish clear governance policies that define acceptable AI use cases, data handling requirements, and accountability structures. Frameworks such as the NIST Cybersecurity Framework provide a practical reference for defining those governance and accountability structures.

The long-term payoff is significant. AI can help address staffing shortages by automating routine tasks like log analysis and alert triage, freeing human analysts to focus on complex investigations and strategic planning. Realizing this benefit requires deliberate planning and investment, not passive adoption.

Cyber insurance awareness is dangerously low

Nearly half of the survey respondents do not know what type of cyber insurance their organization carries. This knowledge gap creates serious risk during incident response, when assumptions about coverage can lead to costly surprises. A team that believes ransomware payments are covered, only to discover they are excluded, faces a materially different decision-making landscape during a crisis.

Cyber insurance requirements vary widely depending on organizational size, industry, and risk profile. A technology company with extensive customer data has fundamentally different coverage needs than a non-profit with a simple technology stack and limited threat targets. Regardless of size, every organization should ensure its cybersecurity team understands the scope, exclusions, and notification requirements of its cyber insurance policy.

Strategic recommendations for moving forward

The ISACA report’s findings point to several actionable cybersecurity best practices that organizations can implement now to strengthen their security posture heading into 2025 and beyond.

Workforce planning must become a board-level priority. This means funding succession planning, improving work conditions to reduce attrition, and creating pathways for non-security professionals to transition into cybersecurity roles. Leveraging contractors and consultants can fill immediate gaps while longer-term hiring pipelines develop.

Budget advocacy requires a new approach. Security leaders should present risk in business terms, benchmarking their organization’s spending against industry peers and modeling the financial impact of potential incidents. Boards respond to data, not fear, and a sound control environment supported by audit and assurance services helps validate that the dollars spent are reducing real exposure.

AI adoption should be intentional and inclusive. Security teams must be at the table when AI tools are evaluated, purchased, and deployed. Continuous learning programs should ensure the workforce stays current with emerging technologies.

Every cybersecurity professional should know their organization’s cyber insurance coverage. This knowledge is not a nice-to-have, it is a critical input to incident response planning and risk management. Organizations across every sector we serve in our industries practice face these same pressures, and the strongest responses pair financial discipline with technical rigor.

Organizations that embrace these recommendations position themselves not just to survive the current threat landscape, but to turn preparation into opportunity. In cybersecurity, as in sports, the teams that study their past performance and invest in disciplined improvement are the ones that create their own luck.

Frequently Asked Questions

What are the biggest cybersecurity workforce challenges in 2024?

The top cybersecurity workforce challenges include an aging talent pool, with the largest cohort now aged 45 to 54, persistent understaffing (43% of teams report being understaffed), and elevated occupational stress driven by an increasingly complex threat environment. Organizations need succession planning, competitive benefits, and workload management to address these gaps.

How is AI used in cybersecurity today?

AI in cybersecurity is primarily used for threat detection and response and endpoint security. Adoption remains in early stages, and many organizations lack governance frameworks for AI deployment. Security professionals are often excluded from AI procurement decisions, which limits the effectiveness of these tools.

Why are cybersecurity budgets underfunded?

Only 36% of organizations report having appropriately funded cybersecurity budgets, and fewer than half expect increases. Budget shortfalls often result from difficulty translating cyber risk into financial terms that resonate with executive leadership. Security leaders who quantify breach costs against prevention investments are more successful at securing adequate funding.

What is the most common type of cyberattack?

Social engineering attacks remain the most prevalent threat vector, according to the ISACA 2024 report. These attacks, including phishing, pretexting, and business email compromise, exploit human behavior rather than technical vulnerabilities. Regular security awareness training and phishing simulations are the most effective countermeasures.

How can organizations reduce cybersecurity employee burnout?

Organizations can reduce burnout by setting realistic workload expectations, offering flexible work arrangements, investing in mental health resources, and creating on-call rotation programs. Providing professional development opportunities and clear career advancement paths also improves retention and morale among cybersecurity professionals.

Do organizations need cyber insurance?

Every organization should carry cyber insurance appropriate to its risk profile, and cybersecurity teams must understand the policy’s scope and exclusions. Nearly half of professionals surveyed do not know what coverage their organization carries, which creates dangerous gaps during incident response when coverage assumptions may prove incorrect.

Let’s talk about your business.