TL;DR: Hybrid work, transparency demands, crowdsourced security, AI-powered abuse, and adversary targeting of MFA and EDR will remain central in 2023, according to INTIGRITI’s year-ahead cybersecurity trends. The practical issue is not new tooling alone, but whether identity, endpoint, and incident response controls can keep pace with faster attacker adaptation and broader attack surfaces.
NHIMG editorial — based on content published by INTIGRITI: Top cybersecurity trends for 2023
Questions worth separating out
Q: How should security teams govern access changes across hybrid identity environments?
A: They should treat provisioning, review, and revocation as one lifecycle control loop rather than separate tasks.
Q: Why do conventional MFA controls keep showing up as attacker targets?
A: Because many implementations are still easier to intercept, fatigue, or bypass than teams assume.
Q: How can organisations defend against AI-generated phishing and impersonation?
A: They should stop relying on grammar, tone, or voice recognition as trust signals.
Practitioner guidance
- Harden remote access around device trust Require conditional access, device posture checks, and enforced patching for remote endpoints before they can reach sensitive systems.
- Upgrade MFA to phishing-resistant methods Review whether your current authentication methods resist token theft, push fatigue, and adversary-in-the-middle attacks.
- Test AI-era phishing resilience Run simulations that use AI-generated language patterns, not just obvious scam templates, so user training and email controls are tested against more realistic social engineering.
What's in the full article
INTIGRITI's full article covers the operational detail this post intentionally leaves for the source:
- The article's longer-form discussion of how remote work changes baseline security assumptions for end users and device management.
- The source's full explanation of why AI creates both defensive opportunity and offensive scale for phishing and malicious code.
- The article's additional commentary on how transparency expectations affect breach response and customer trust.
- The full trend review's context for why MFA and EDR will keep attracting attacker attention as adoption rises.
👉 Read INTIGRITI's full cybersecurity trends roundup for 2023 →
AI, MFA evasion, and remote work risks: what teams must recheck?
Explore further
Identity controls are now part of the cybersecurity perimeter, not a separate discipline. This article shows why remote work, MFA, and AI-assisted abuse cannot be analysed as isolated problems. Access decisions now depend on endpoint trust, user behaviour, and the quality of authentication signals. For IAM teams, the practical conclusion is that identity governance must be treated as an operational security control, not a back-office compliance function.
A question worth separating out:
Q: What should teams do when endpoint telemetry suggests EDR evasion is underway?
A: Isolate the endpoint, preserve process and network telemetry, and look for adjacent account use from the same host before assuming the event is limited to malware removal. If the attacker has already used the machine for credential or token access, the response must expand into identity containment, not just endpoint cleanup.
👉 Read our full editorial: Why existing cybersecurity controls are falling short for AI and MFA