IBM X-Force Report Reveals the Importance of Security Fundamentals

IBM X-Force Report Reveals the Importance of Security Fundamentals

The News: IBM releases its 2024 X-Force Threat Intelligence Index. Additional detail is available in IBM’s press release.

IBM X-Force Report Reveals the Importance of Security Fundamentals

Analyst Take: IBM Security X-Force, the company’s team of cybersecurity experts, has been publishing its Threat Intelligence Index annually since 2012. The report has grown in recognition and clout over this timeframe, in large part due to the vast amount of data and expertise that goes into it. This spans IBM’s security operations telemetry data and incident response investigations, its research, and other commercial and open-source data points. In arguably the most notable example, the 2024 report draws on insights and observations from over 150 billion security events per day in more than 130 countries, according to IBM. The main objective of the report is to help organizations craft effective security strategies and to make informed decisions about their security by uncovering how security threats and trends are evolving based on how cybercriminals are adapting and changing their tactics, techniques, and procedures.

One of the most important findings from the 2024 report was that cybercriminals are doubling-down on exploiting user identities—with a 71% year-to-year increase in the volume of attacks using valid credentials, according to the report. Simply put, it is a “log in versus hack in” approach to gaining access to corporate networks, infrastructure, and data.

Against this backdrop, phishing remains a long-standing prominent initial access vector, but it dropped from being noted by 41% of respondents in the prior study to 30%, tying valid accounts as the most selected access vector and outpacing exploitation of public-facing applications by just 1%. Credential stuffing is becoming more common, especially when it comes to cloud account credentials available for sale on the dark web. At the same time, it remains important for users to keep in mind that social engineering attacks such as phishing are becoming more creative, pointed to the individual, and effective with the use of AI.

On the note of AI, these workloads represent a future frontier to be protected from cyber-criminals. This is especially true as generative AI workloads become more broadly adopted across organizations and across key business functions and considering that standards for safe and responsible data usage are still being established for AI. This being acknowledged, IBM’s report found that the return on investment (ROI) is not yet there for attackers to focus heavily on targeting these workloads at scale. I agree with IBM’s assessment that this is likely to come if a single generative AI solution secures half of the market share, and as the market consolidates around a few technologies.

Unsurprisingly, ransomware remains a major threat, but its incidence dropped 11.5% year-to-year, according to the study. What is new is that attackers are targeting critical infrastructure—in fact, nearly 70% of attacks that X-Force responded to in 2023 targeted critical industries. The increase in incidence, severity, and awareness of these attacks over the past couple of years, and the resulting technological development in areas such as data immutability and recovery testing and assurance, has resulted in a focus on, and increased ability to, rebuild critical infrastructure and recover data, for customers. In response, malicious actors have pivoted to information stealing; there was an alarming 266% increase in info-stealers, and data theft and leak rose to the most common impact of cyberattacks for organizations, in IBM’s study.

A final key theme to note is the importance of IT operations remaining diligent about and committed to the fundamentals; IBM’s research found that nearly 85% of attacks on critical sectors could have been mitigated with systems and software patching, multi-factor authentication, and policies of least-privileged access (that is, allowing users only the access to data and systems that they need to do their job). I have observed this trend as well and expect it to remain an important focus area for the foreseeable future.

Looking ahead, the threat landscape will continue to evolve. Threat detection and intelligence will only continue to become more critical, as a tool allowing organizations to guide their security decisions and to inform their incident response plans.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other Insights from The Futurum Group:

The Six Five Insider at IBM Analyst Day with Rob Thomas and Dr. Dario Gil

IBM Announces New Quantum Processor and IBM Quantum System Two

Growing the IBM-AWS Alliance – The Six Five on the Road at AWS re:Invent 2023

Author Information

Krista Case

Krista Case brings over 15 years of experience providing research and advisory services and creating thought leadership content. Her vantage point spans technology and vendor portfolio developments; customer buying behavior trends; and vendor ecosystems, go-to-market positioning, and business models. Her work has appeared in major publications including eWeek, TechTarget and The Register.

Related Insights
How Genesys and AWS Are Redefining AI-Driven Customer Engagement
July 24, 2026

How Genesys and AWS Are Redefining AI-Driven Customer Engagement

Keith Kirkpatrick, Vice President & Research Director, Enterprise Software & Di at Futurum, Genesys Cloud's expanded AWS partnership leverages agentic AI to transform enterprise customer engagement and enable autonomous interactions...
So This Is How AIs Attack- Observations From the OpenAI & Hugging Face Incident
July 24, 2026

So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident

Fernando Montenegro and Mitch Ashley, VPs at Futurum, read the OpenAI and Hugging Face agentic incident as a live test of enterprise readiness to detect and contain AI agents that...
WEKA Engineers the AI Chassis to Conquer the Inference Power Paradox
July 24, 2026

WEKA Engineers the AI Chassis to Conquer the Inference Power Paradox

Brad Shimmin, VP and Practice Lead at Futurum, shares his insights on WEKA’s launch of the WEKApod 3 appliances and NeuralMesh 6 software. By taking total control of its hardware...
Solving the Distributed AI Dilemma: Oracle Base Database Cloud@Customer Brings OCI Automation to Local Workloads
July 24, 2026

Solving the Distributed AI Dilemma: Oracle Base Database Cloud@Customer Brings OCI Automation to Local Workloads

Brad Shimmin at Futurum analyzes Oracle's launch of Base Database Cloud@Customer X11, exploring how converged application VMs and local AI Database 26ai deployments solve data gravity and latency issues....
Conduent's AI-Powered CX Platform: A Major shift for Customer Engagement?
July 24, 2026

Conduent’s AI-Powered CX Platform: A Major shift for Customer Engagement?

Conduent sells its tolling business to Quarterhill for $70M to redirect resources toward AI platform services, capitalizing on surging demand as the AI market projects to reach $25.7B by 2026....
ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth
July 23, 2026

ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth

Futurum Research analyzes ServiceNow Q2 FY 2026 earnings, focusing on AI Control Tower adoption, security expansion, and workflow demand....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.