TL;DR: Hybrid work, transparency demands, crowdsourced security, AI-powered abuse, and adversary targeting of MFA and EDR will remain central in 2023, according to INTIGRITI’s year-ahead cybersecurity trends. The practical issue is not new tooling alone, but whether identity, endpoint, and incident response controls can keep pace with faster attacker adaptation and broader attack surfaces.
At a glance
What this is: INTIGRITI’s trend roundup says 2023 security pressure will concentrate on hybrid work risk, AI-enabled abuse, transparency, bug bounties, and attacks on MFA and EDR.
Why it matters: It matters to IAM and security teams because identity controls, phishing-resistant authentication, and endpoint governance now sit inside a faster-moving threat cycle that attackers actively try to outpace.
By the numbers:
- Crowdsourced security markets are projected to reach $243 million in 2032, with a predicted growth rate of 7.8% over 10 years, according to Future Market Insights.
👉 Read INTIGRITI's full cybersecurity trends roundup for 2023
Context
Cybersecurity trends usually expose where existing control assumptions are weakening, and this article points to three pressure zones: hybrid work, AI-enabled abuse, and the continuing race between defensive tooling and attacker adaptation. The primary issue is not whether organisations have controls, but whether identity, authentication, endpoint, and incident response controls can still hold in a more distributed operating model.
The identity angle is real even in a broad cyber trends piece. Remote work changes access boundaries, AI increases the scale of social engineering, and MFA becomes a more attractive target when attackers can test for weaker implementations. That makes the article relevant to IAM, PAM, and security teams that have to govern access across both human users and the systems now automating parts of their workflows.
Key questions
Q: How should security teams govern access changes across hybrid identity environments?
A: They should treat provisioning, review, and revocation as one lifecycle control loop rather than separate tasks. The practical goal is to keep permissions aligned with current business need across cloud, SaaS, and on-premise systems. If identity state cannot be updated quickly enough, stale access becomes the real control gap.
Q: Why do conventional MFA controls keep showing up as attacker targets?
A: Because many implementations are still easier to intercept, fatigue, or bypass than teams assume. Attackers focus on MFA where they can exploit push approval habits, non-phishing-resistant factors, or weak recovery processes, so the control needs to be evaluated by assurance level, not by presence alone.
Q: How can organisations defend against AI-generated phishing and impersonation?
A: They should stop relying on grammar, tone, or voice recognition as trust signals. High-risk requests need channel verification, step-up approval, and identity checks that are independent of the message itself. That is especially important for finance, help desk, and privileged-access workflows.
Q: What should teams do when endpoint telemetry suggests EDR evasion is underway?
A: Isolate the endpoint, preserve process and network telemetry, and look for adjacent account use from the same host before assuming the event is limited to malware removal. If the attacker has already used the machine for credential or token access, the response must expand into identity containment, not just endpoint cleanup.
Technical breakdown
Why hybrid work expands the attack surface
Hybrid work shifts security from a bounded office perimeter to many smaller, less controlled environments. That makes device hygiene, home network exposure, and user behaviour part of the control plane, not just a user-support issue. The article’s point about onboarding and update discipline reflects a basic reality: if endpoints leave managed space, identity assurance and device trust become harder to maintain consistently.
Practical implication: tie remote access to device posture, training, and conditional access instead of assuming the network boundary will absorb risk.
How AI changes phishing and malicious code generation
AI changes attacker economics by reducing the cost of producing convincing lures, custom code, and repetitive security-relevant output. Large language models do not replace attackers, but they can compress the effort needed for phishing campaigns, reconnaissance, and content generation. That means AI is both a productivity layer for defenders and a scale layer for adversaries, especially where trust decisions depend on human judgement alone.
Practical implication: redesign user-facing trust checks and security review workflows so they do not depend only on spotting obviously bad language or formatting.
Why MFA and EDR become recurring attacker targets
The article frames security as an ongoing race because attackers adapt as soon as controls become common. MFA is a target when implementations are not phishing-resistant, and EDR becomes a target when attackers can evade detection or blind monitoring. In practical terms, a control’s market penetration can make it more attractive to bypass rather than less relevant to defend.
Practical implication: validate which MFA methods are actually resistant to phishing and measure whether EDR detections survive common evasion paths.
NHI Mgmt Group analysis
Identity controls are now part of the cybersecurity perimeter, not a separate discipline. This article shows why remote work, MFA, and AI-assisted abuse cannot be analysed as isolated problems. Access decisions now depend on endpoint trust, user behaviour, and the quality of authentication signals. For IAM teams, the practical conclusion is that identity governance must be treated as an operational security control, not a back-office compliance function.
AI creates a scale problem before it becomes a sophistication problem. The main impact of AI in this context is not novelty, but throughput. Attackers can generate more convincing phishing attempts and more varied malicious content at lower cost, which stretches review, detection, and training processes. That shifts programme risk from one-off bad messages to continuous manipulation pressure, and teams should measure whether their controls still work when adversary output volume rises.
Phishing-resistant MFA should be the baseline, because conventional MFA is now an explicit target. The article’s point about attackers targeting MFA reflects a broader governance failure: organisations often treat MFA adoption as a finish line rather than a control class with different assurance levels. The named concept here is MFA assurance gap: the difference between having MFA in place and having MFA that withstands modern phishing and interception tactics. Security teams should close that gap by treating implementation quality as the real control question.
Transparency is becoming a control expectation, not just a communications choice. The article’s emphasis on openness after a breach maps to a wider governance trend in which customers, regulators, and partners expect explicit incident handling detail. That expectation matters to identity programmes because access and authentication failures are often the first visible indicators of deeper compromise. Practitioners should align breach communications with evidence from access logs, identity events, and response timelines so trust is not undermined by inconsistent disclosure.
What this signals
Hybrid work and AI-assisted abuse are converging on the same weak point: trust decisions that are too easy to automate but too hard to verify. For programmes that already struggle with access sprawl, the practical signal is that authentication quality and endpoint posture now have to be managed as one policy domain, not separate disciplines.
MFA assurance gap: organisations increasingly have MFA everywhere, but not necessarily MFA that can withstand current phishing patterns. Teams that still measure success by rollout coverage alone will miss the real governance issue, which is whether the deployed factor type is strong enough for the threat model and whether recovery paths undermine it.
The operational lesson is to align identity telemetry with incident response and user education. If remote work, phishing, and EDR evasion all remain in the same threat mix, then logging, alert triage, and admin access review need to be tuned for faster attacker adaptation rather than periodic control checklists.
For practitioners
- Harden remote access around device trust Require conditional access, device posture checks, and enforced patching for remote endpoints before they can reach sensitive systems. This is especially important where home networks and unmanaged devices are part of the normal operating model.
- Upgrade MFA to phishing-resistant methods Review whether your current authentication methods resist token theft, push fatigue, and adversary-in-the-middle attacks. Where possible, prioritise phishing-resistant authentication for privileged users and sensitive workflows.
- Test AI-era phishing resilience Run simulations that use AI-generated language patterns, not just obvious scam templates, so user training and email controls are tested against more realistic social engineering.
- Measure EDR evasion tolerance Validate whether your endpoint detections still fire when common evasion techniques are used. Focus on alert fidelity, response workflows, and whether security teams can still investigate with enough telemetry.
Key takeaways
- This trend roundup is really about control fatigue: hybrid work, AI, MFA abuse, and EDR evasion all push security teams toward continuous verification.
- The scale signal is clear enough to justify change, with the global cybersecurity workforce now at 4.7 million and crowdsourced security projected at $243 million by 2032.
- Practitioners should focus on assurance quality, device trust, and detection resilience instead of assuming that broad tool adoption equals effective control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 , Initial Access; TA0006 , Credential Access; TA0005 , Defense Evasion | The article highlights phishing, MFA bypass, and EDR evasion as recurring attacker behaviours. |
| NIST CSF 2.0 | PR.AA-1 | Remote work and stronger identity assurance align with authentication and access management. |
| NIST SP 800-53 Rev 5 | IA-2 | MFA quality and access assurance are central to the article's identity risk discussion. |
| CIS Controls v8 | CIS-5 , Account Management | The piece connects identity control quality to modern access risk and remote work. |
| NIST AI RMF | MANAGE | The article's AI discussion is about risk handling and abuse scale, not model development. |
Map phishing and evasion scenarios to ATT&CK tactics and test whether controls still detect them.
Key terms
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Conditional Access: Conditional access is a policy model that decides whether an action should proceed based on context such as posture, resource sensitivity, timing, and scope. For AI agents, it must be evaluated at request time so a valid credential does not automatically equal permitted behaviour.
- EDR evasion: Techniques used by attackers to avoid endpoint detection and response tooling, reduce telemetry, or delay alerting. EDR evasion matters because modern response programs depend on reliable endpoint visibility, so bypassing it can frustrate investigation and slow containment.
- AI-assisted phishing: AI-assisted phishing is social engineering where generative models help create more convincing, tailored, or higher-volume lure content. The risk is not only better wording, but faster iteration, which lets attackers adapt messages until they evade filters or persuade a target to act.
What's in the full article
INTIGRITI's full article covers the operational detail this post intentionally leaves for the source:
- The article's longer-form discussion of how remote work changes baseline security assumptions for end users and device management.
- The source's full explanation of why AI creates both defensive opportunity and offensive scale for phishing and malicious code.
- The article's additional commentary on how transparency expectations affect breach response and customer trust.
- The full trend review's context for why MFA and EDR will keep attracting attacker attention as adoption rises.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps identity and security practitioners build the control discipline needed to manage modern access risk.
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org