---
title: "Lessons Learned: Five Cybersecurity Takeaways from 2023"
description: Here’s our pick of the top five cybersecurity lessons we learned from 2023.
image: https://insights.comforte.com/hubfs/comforte%20AG_Lessons%20Learned_7.12.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG - Lessons Learned: Five Cybersecurity Takeaways from 2023](https://insights.comforte.com/hubfs/comforte%20AG_Lessons%20Learned_7.12.png)](https://insights.comforte.com/lessons-learned-five-cybersecurity-takeaways-from-2023)

[Mirza Salihagic](https://insights.comforte.com/author/mirza-salihagic) l Dec 7, 2023 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Research, Trends, and Predictions](https://insights.comforte.com/tag/research-trends-and-predictions)

# Lessons Learned: Five Cybersecurity Takeaways from 2023

After another (nearly) action-packed 12 months it’s time to take stock. There have been breaches galore, new cybersecurity mandates and regulations, fascinating data points and the emergence of some industry trends which will shape the future of IT. Here’s our pick of the top five things we learned from 2023.

1. **Generative AI will turn up the heat on security teams**

Generative AI (GenAI) had its breakout year in 2023, thanks to the extraordinary impact of ChatGPT. It has the potential to transform industries as diverse as customer service and software development. But from a cybersecurity perspective, there’s also a certain amount of understandable concern. That’s because the [technology also has the potential](https://insights.comforte.com/chatgpt-will-democratize-cybercrime-and-force-firms-to-double-down-on-data-security?hsLang=en) to supercharge phishing campaigns, both in scale and sophistication, and potentially help threat actors write malware to evade defenses more easily. [The appearance](https://www.zdnet.com/article/wormgpt-what-to-know-about-chatgpts-malicious-cousin/) of WormGPT and FraudGPT reinforced these fears.

The AI models themselves and the companies that run them also emerged as potential targets for threat actors – potentially [those who want](https://insights.comforte.com/ai-means-business-so-start-with-data-centric-security?hsLang=en) to mine or corrupt training data. A quickly patched vulnerability at [ChatGPT developer OpenAI](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en) highlighted the potential for unauthorized access. It all adds up to yet another compelling argument for data-centric security.

1. **Enterprise data is under attack from all angles**

As if we needed any more convincing of the potential imbalance between threat actors and network defenders, Verizon’s annual *Data Breach Investigations Report* (DBIR) [was on hand to remind us](https://insights.comforte.com/verizons-data-breach-investigations-report-enterprise-data-is-under-attack-from-all-sides?hsLang=en). This year distilled from 16,312 incidents and 5,199 data breaches, it offered up yet another fascinating snapshot of the global threat landscape.  
We learned that most breaches over the past 12 months were external (83%) and stemmed from financial motives (95%), and were carried out by organized criminals. Threat actors gained access to networks primarily via stolen credentials (45%), phishing (12%) and vulnerability exploitation (5%). And the “human element” was responsible for a massive 74% of breaches – evidenced by social engineering, misconfiguration and other errors. Malicious insiders are also a growing threat – especially in the public sector where they were responsible for 30% of breaches, up from 22% the year before. Ransomware remains a potent threat for organizations of all shapes and sizes, responsible for a quarter (24%) of breaches.

1. **Bring-your-own-encryption goes mainstream as multi-cloud woes mount**

First came the rush to migrate to the cloud. Now comes the reckoning. [It’s claimed that](https://info.flexera.com/CM-REPORT-State-of-the-Cloud) 87% of organizations have now invested in public cloud infrastructure from multiple providers. But over the past year, organizations have become increasingly concerned about the implications for the security and compliance of data stored in these environments. That’s because, while the service provider (CSP) offers some protections, securing the data itself is the job of the customer. And with GDPR and the Californian CCPA leading similar legislation in the US, the stakes are higher than they’ve ever been. Security is now the number two cloud challenge for global organizations after spend management, [cited by 79%](https://info.flexera.com/CM-REPORT-State-of-the-Cloud).

This has made bring-your-own-encryption (BYOE) increasingly popular over the past 12 months. The idea is for cloud customers to use their preferred encryption solution, instead of, or in addition to, one offered by the CSP. It means that the generation of encryption keys and tokenization secrets are 100% in the control of the customer, so only protected data is ever allowed into the public cloud. It also helps deliver consistency across multiple clouds, and more flexibility to migrate data across these environments. Industry partnerships like [comforte’s tie-up](https://insights.comforte.com/the-value-of-data-centric-protection-in-google-cloud-and-bigquery?hsLang=en) with Google and BigQuery show the direction of travel for 2024.

1. **Security will be key to compliance efforts in 2024**

The past year has also seen organizations get serious about some big compliance mandates coming down the road in 2024. They include [PCI DSS 4.0](https://insights.comforte.com/safeguarding-cardholder-information-why-data-discovery-and-classification-matter-in-pci-4.0?hsLang=en), which will partially go into effect in March 2024 and has a string of new requirements for organizations that handle cardholder data. It will make continuous data discovery, classification and protection an essential capability.

Also on the roadmap for operators of “essential services” in the EU will be NIS 2, which is also landing in 2024. That will make strong encryption a baseline requirement for all. And in the US there is President Biden’s [National Cybersecurity Strategy](https://insights.comforte.com/why-data-protection-is-critical-to-the-new-u.s.-cybersecurity-strategy?hsLang=en), which will seek to promote the defense of critical infrastructure and the “privacy and the security of personal data” — by holding data stewards accountable and driving through legislation for a national data security standard. Watch this space.

1. **Security is about growth as much as risk mitigation**

Finally, a more subtle lesson learned from 2023. Yes, we witnessed another cascade of damaging [data breach stories](https://insights.comforte.com/breaches-galore-means-its-time-for-data-centric-security?hsLang=en) — from Tesla and Discord.io to the Police Service of Northern Ireland. And yes, we read how breach costs have now [reached an all-time high](https://insights.comforte.com/as-breach-costs-soar-organizations-need-data-protection-across-the-multi-cloud?hsLang=en) of $4.45m on average globally, rising to $10.9m in healthcare and $9.5m in the US. But the reality is that cybersecurity is increasingly being viewed as a business enabler rather than a reactive cost that is necessary to mitigate risk. In fact, one [study claims](https://www.ibm.com/downloads/cas/YLGDAMVR) the most cyber-mature organizations report a 43% higher average revenue growth rate than the least mature.

[Effective data security can](https://insights.comforte.com/from-defense-to-growth-how-effective-security-can-power-business-success?hsLang=en) preserve IP, which is critical to growth plans. It can open up new markets by supporting regulatory compliance. And it can give businesses the confidence to invest in R&D and digital transformation, safe in the knowledge that these investments will be protected.

Expect more of the same next year, and no doubt one or two surprises.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/lessons-learned-five-cybersecurity-takeaways-from-2023&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/lessons-learned-five-cybersecurity-takeaways-from-2023&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/lessons-learned-five-cybersecurity-takeaways-from-2023&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/lessons-learned-five-cybersecurity-takeaways-from-2023&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/lessons-learned-five-cybersecurity-takeaways-from-2023&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Learn how to discover, classify, and protect all sensitive data.

Click the button below to download the solution brief for our Data Security Platform:

[![Download Solution Brief](https://no-cache.hubspot.com/cta/default/4026697/65e094b1-44ae-496e-be17-1678a1876675.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/65e094b1-44ae-496e-be17-1678a1876675)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>