Growing complexity
Over the past few years, we have witnessed the cyber landscape becoming more complex and harder to defend against. Unfortunately there is no end in sight for this trend, with 2025 forecasted to follow the same trajectory. As Darren Thomson, Field CTO EMEAI at Commvault, recognises: “In 2025, we need to be prepared to ride a new wave of existing challenges. Take phishing for example: the 2024 UK Government’s Cyber Security Breaches Survey identifies it as the most predominant attack vector, affecting 84% of those breached. But while phishing itself is not new, cyberattacks like this have only grown in complexity as attackers exploit six ‘mega trends’ in technology: artificial intelligence (AI), cloud computing, social media, software supply chains, the emergence of homeworking, and the Internet of Things (IoT). These trends collectively accelerate the scale and impact of attacks.”
Larger scale attacks are much harder to protect against, so renewing and revising cyber and recovery strategies should be a priority for 2025. Tom Atkins, AVP – East at Censys, acknowledges that: “Things are continuing to become more complex in almost every dimension. And even with security budget increases (which are not a given), the same resource limitations remain. So tools, programs, and processes that can really move the needle from a risk reduction standpoint will continue to be a focus.”
With all of these factors set to make cybersecurity an even tougher challenge in 2025, Matt Hillary, CISO at Drata, predicts that: “Security, privacy, and compliance will become increasingly intertwined, necessitating a more integrated, collaborative, and comprehensive approach to governance, risk, and compliance across these sometimes-divided practices and domains. Organizations will be compelled to integrate previously siloed functions and think about them holistically, leading to more robust and dynamic treatment of common risks that span these domains.”
AI – friend, foe, or both?
AI is another prominent factor adding to the complexities of cybersecurity for the year ahead. As a tool readily available to enhance the activities for both cyber attackers and defenders, we will see a lot more discussion around ‘fighting AI with AI’. As Geoff Barlow, Product and Strategy Director at Node4, explains: “AI is playing a dual role in the cybersecurity arena, both enhancing and challenging it. While AI increases the speed, volume, and sophistication of cyberattacks, making it easier for cybercriminals, it also offers powerful tools for defence, which can help organizations anticipate and respond to threats.
“Over the next 12 months, organizations will focus on improving threat detection, hunting and intelligence capabilities using AI enhanced tools,” he adds. “We should expect to see AI agents being used to automate areas such as incident response, automating repetitive tasks and allowing security operations teams to focus on more advanced threat protection.”
Gilad Elyashar, Chief Product Officer at Aqua Security, agrees, noting that: “With rising threat volumes, organizations will increasingly rely on AI-guided remediation, automated workflows, and contextual analysis to expedite fixes and reduce manual workload. Advanced tools will assign responsibility, provide targeted guidance, and adapt in real time, enhancing both accuracy and speed. This transition will strengthen cloud resilience, as organizations move from merely identifying risks to actively and efficiently closing vulnerabilities across their dynamic infrastructures.”
Yet, with the rise of AI has also come a debate about the ethics of its use. AI regulations are being put in place across the world to regulate its development and ensure the new technology is used safely and responsibly. This is a conversation that needs to continue and to be top of the list when making decisions about AI, in 2025, according to Chris Jackson, Chief Product & Technology Officer at Six Degrees. “AI-driven products and services are set to keep evolving rapidly in the new year, and it is important for organizations to ensure they don’t forget the ethics that go alongside this,” he urges. “AI is no different from any other data usage, and therefore all decisions it makes are directly subject to GDPR parameters. It is imperative to have the necessary consent to process any data, and organizations need to be very clear about intentions within data protection policies. Additionally, there is a ‘right of explanation’ – all affected individuals must be told about any automated decision making, the significance of this, and how the automated decision making operates. This should be something that everyone is thinking about, but worryingly it is often a secondary consideration.”
2025: the year of resilience
One thing is certain: 2025 will come with its challenges in the cybersecurity area. With new threats, heightened risks, and more complex attacks, organizations across the world will be reevaluating their security strategies to ensure they are prepared for the year ahead. There is no single right answer on how to do so, but resilience is key. Have the necessary prevention, detection, and recovery measures in place so that operations can continue, no matter what comes our way in 2025.






