Security 2023: Supply Chain Resilience, Talent and More

Every year Splunk’s leaders and technology experts assemble a set of predictions reports looking at the year ahead and beyond. Our chief strategy officer, Ammar Maraqa, introduced the reports yesterday and touched on each of the four editions. But I think the Data Security Predictions report is worth a deeper dive, because there’s a lot in there — and a lot at stake for security leaders.

The main theme of this year’s report is a word that comes up in a lot of my conversations: resilience. CISOs and business leaders describe a greater emphasis on overall business resilience, and they say that security leaders are playing a broader role than the classic function of “keep adversaries out.”

This trend has accelerated in the last few tumultuous years, but in my own career I’ve long seen it building. That’s not to say that a lot of “chief resilience officer” titles will be created in the coming years. But we’re already seeing that companies that intentionally merge cybersecurity and business resilience are designating a chief trust officer, because trust is an essential outcome of a truly resilient system.

Mostly smaller companies take that path, and I don’t think the new job title will catch on broadly. But the linking of resilience and security is here to stay. As are a number of the key challenges.

Supply Chains Get SBOM’d

One of the most important predictions in this year’s report is about how we’ll handle supply chain attacks. Generally, we’re going to see more investment around protecting the software supply chain and mitigating the effects a vulnerability can have across the entire tech industry.

For any organization, the process of figuring out whether a given supply chain vulnerability is hiding in your infrastructure or software offerings is a laborious task. A lot of teams are just emailing their vendors and waiting for a reply to the question, “Are you compromised? Are we?” If the flaw is likely to exist in many of the software products your organization consumes, it might take a month to get all those replies back.

As prominent supply chain attacks continue, it’s going to drive the industry to adopt the software bill of materials, or SBOM. This bill of materials details which components, such as a piece of open-source software, are embedded in a software product. When a certain version of a certain component is reported to be compromised, there’s no email; you just look at the SBOM and know where you stand. And you can turn to the task of remediation in minutes or hours, rather than in days or weeks.

I can’t overstate it: Wide adoption of SBOMs will revolutionize the software industry in terms of security and remediation.

Talent is Not a Resume Bullet

Automation holds a lot of promise, but you can’t automate away the entire talent shortage. Instead, smart organizations will continue to expand the search for talent to include a greater diversity of backgrounds. They’ll put an emphasis on talents (innate curiosity, problem-solving, a taste for adrenalin) versus learned skills (required experience or certifications).

I’ve had success with this approach. Some of my best red teamers had been English and philosophy majors, people without a computer science degree. Going forward, more organizations are going to adopt this approach toward entry-level talent. But the impetus doesn’t come from the hiring manager or the HR partner. This approach comes from the top, from CISOs who are tired of hearing “we can’t find any talent” and “we need people with 10 years of NSA experience to be tier-one analysts” in the same conversation.

And a Few Bonus Predictions

By the time I joined Splunk this fall, the Predictions reports were well under way, and I was focused on settling into my role as CISO. As I highlight key features in this year’s report (which also touches on ransomware and the expanding cybercrime economy, privacy, the impact of machine learning and more), I also have a few late thoughts of my own about the road ahead.

A primary driver of the focus on resilience is the permanent move, for so many organizations, to a hybrid-remote workforce model. Though many organizations may think they’ve essentially made the shift to hybrid-remote, this new model will drive a lot of decisions, innovation and budget.

Secondly, the issue of accountability is also likely to evolve. The U.S. Securities and Exchange Commission is taking a more forceful approach with public companies. The October conviction of Uber’s former chief security officer definitely caught the attention of security leaders across the industry. I think we’ll see more SEC action, and legislation that will change how incidents and risks must be disclosed in SEC 10-K filings.

Ultimately, moves toward greater transparency are good for the market, the software industry and security teams. Although it can seem that security teams always have to react to one crisis after another, I think we’re at a very good time in this industry. No one got into this field looking for a slow, sleepy pace, and I see the challenges as opportunities to learn and improve. Security is not about achieving a specific level of maturity and declaring that you’ve scaled the mountain. It’s about evolving in a constantly changing environment, and getting a little smarter, a little better, every day.

And that’s a future I look forward to.

Related Articles

Security Predictions 2026: What Agentic AI Means for the People Running the SOC
Leadership
10 Minute Read

Security Predictions 2026: What Agentic AI Means for the People Running the SOC

Splunk's Hao Yang shares our security predictions for 2026 and how agentic AI is reshaping how we see the SOC.
The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility
Leadership
4 Minute Read

The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility

Systems show symptoms. Business context shows impact. Discover why the future of observability is understanding what matters most to your customers.
MachineGPT, Agentic AI, and the New Foundation for Digital Resilience
Leadership
4 Minute Read

MachineGPT, Agentic AI, and the New Foundation for Digital Resilience

MachineGPT is foundational to the rise of Agentic AI in the enterprise, which is poised to fundamentally reshape digital operations – and it's advancing faster than we expected.
MachineGPT: Speaking the Language of Machines to Shape the Future of AI
Leadership
4 Minute Read

MachineGPT: Speaking the Language of Machines to Shape the Future of AI

MachineGPT brings the power of generative AI to one of the most overlooked resources: machine data. Splunk SVP & GM Kamal Hathi explains why mastering data as the heartbeat of the digital world is a game changer.
Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25
Leadership
3 Minute Read

Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25

Splunk's Kamal Hathi recaps our innovation highlights from .conf25, marking a pivotal moment for Splunk and Cisco as we deliver significant new value to our customers that make the use of AI a practical reality in their organizations.
Machine Data: Fighting Fire With Fire for Digital Resilience
Leadership
2 Minute Read

Machine Data: Fighting Fire With Fire for Digital Resilience

Kamal Hathi shares how Cisco and Splunk are helping organizations manage the explosion of machine data and AI-driven complexity, delivering real-time digital resilience to counter threats at machine speed and scale.
.conf25: Reinventing Digital Resilience for the Agentic Era
Leadership
3 Minute Read

.conf25: Reinventing Digital Resilience for the Agentic Era

Kamal Hathi shares how Cisco and Splunk deliver the data foundation, agentic intelligence, and cross-domain insights needed to build a more secure, resilient, and always-on digital enterprise.
UK Needn’t Fear The Data Deluge
Leadership
4 Minute Read

UK Needn’t Fear The Data Deluge

UK businesses face a data explosion—fueling growth but also raising risks in security, compliance, and operations. With smart data management strategies, organisations can regain control, boost resilience, and turn data into a true competitive edge.
Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco
Leadership
7 Minute Read

Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco

Cisco and Splunk deliver Digital Resilience by Design with seamless troubleshooting across security, observability, and networking domains, powered by AI innovations to manage complexity and stay ahead of risk.