Opens in a new tab
vmblog logo 2024 wht (updated)

GlobalSign 2025 Predictions: Trends in the PKI Industry – Traditional Identity Security in Modern Business

Share: 

David Marshall | Published: November 21, 2024

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By Mohit Kumar, GMO GlobalSign

As we move into 2025, we look back on a year that has seen significant change in the cybersecurity landscape. The ongoing attacks on every industry imaginable demonstrate that businesses, governments and organizations must respond more strongly by implementing the strictest cybersecurity rules and digital security. Perhaps as a result, we’ve seen tremendous shifts in the way digital security has evolved and is being used. The Public Key Infrastructure (PKI) ecosystem, particularly, has seen these changes affect it.

PKI is a framework of policies, procedures, and technologies used to create, manage, distribute, use, store, and revoke digital certificates and cryptographic keys. It ensures secure electronic transfer of information for a range of network activities such as e-commerce, internet banking, and confidential email. PKI is foundational to a secure Web.

PKI’s relevance continues to increase in a multitude of industries, from finance and healthcare to manufacturing and beyond. As digital security becomes more omnipresent, organizations are coming to see the role of cryptography in protecting sensitive information and maintaining trust in digital transactions.

These trends have been driven by a number of factors; and will continue to exhibit changes as companies find themselves increasingly online. The boon of Artificial Intelligence (AI) is also having its effect on the PKI space, with automation and regulatory shifts in response to it driving new integrations.

The Effects of Advancing AI and Regulation

AI is making digital security smarter, faster and more efficient. It’s also representing a growing, considerable threat. This isn’t coming as any surprise and is a trend we’ve seen from previous years – but its continued usage is quickly becoming less of a convenience and more of a necessity. Like AI, automating digital certificate management is becoming more popular as it reduces the burden of managing an ever-increasing number of certificates for an ever-expanding online presence for many organizations. And its uses in threat detection and prediction, along with the absence of human error, mean that it’s only set to become more ubiquitous in Certificate management.

There’s also the IoT element: With the expected total of the number of connected IoT devices expected to reach 55.7 billion by 2025 per IDC, AI’s future role in their management will be indispensable. The integration of PKI into IoT is a foundational layer of device security, and it’s through the use of automated platforms that this foundation is made more solid. The ever-increasing numbers of online devices necessitate robust security measures to protect device communication, authentication, and data integrity.

Regulatory and industry standards developments to manage this have been extensive – such as the EU Digital Identity Wallet and eIDAS 2.0, which may revolutionize digital identity management in Europe, and will mark a heavier reliance on PKI to ensure the integrity and authenticity of digital assets. Further initiatives to create a secure digital image ecosystem will gain traction, such as the Coalition for Content Provenance and Authenticity (C2PA) whose focus is on creating technical specifications for establishing content provenance and authenticity to help trace the provenance of media in a world of growing misinformation. As these initiatives gain traction, the demand for scalable and automated certificate issuance will grow, pushing Certificate Authorities (CAs) to provide secure, interoperable solutions.

Rise of Zero Trust Architecture

Part of the resulting changes from these developments has been an increasing shift towards Zero Trust architectures. The rising adoption rates are making PKI a critical component of identity-based authentication and encrypted communication. As this continues, certificates will see more frequent use in the internal verification of users, devices, and applications.

This trend in adoption likely comes out at least partly because of the US Executive Order on Cybersecurity, from May 2021, which mandated a shift towards Zero Trust architectures. A Zero-Trust framework calls for constant verifications, which is where PKI will play a critical role in establishing secure identities that are easily verifiable.

This can be seen in the Gartner report that suggests that more than 60% of enterprises are expected to phase out traditional VPNs in favor of Zero Trust Network Access (ZTNA) by 2025. This transition will result in the reliance on PKI increasing, as it provides a scalable and reliable method for managing secure authentication.

Growth in Cloud-Based Solutions

This is not the only way PKI is needed to secure new ways of doing business. Businesses are increasingly shifting towards cloud-native architectures, and the role of PKI in securing these environments is becoming more critical. Four years ago, Gartner predicted that over 95% of new digital workloads will be deployed on cloud-native platforms by 2025, meaning that securing cloud-based services, microservices and container environments is of critical importance to modern organizations. This is reflected in major cloud providers increasingly integrating PKI and certificate management services into their offerings. By and large that has certainly been the case.

The resulting benefits of cloud-based PKI are numerous. It offers scalability, allowing businesses to manage a large number of certificates with increasing mandating shorter validities without compromising performance. Additionally, the flexibility of these solutions enables organizations to adapt quickly to changing security requirements, ensuring continuous protection of their digital assets. As workloads move onto the cloud, companies will need to keep up with growing trends by making sure their workspaces are secure online by leveraging secure services and container environments.

The Years Ahead for PKI

2024 was quite a year for PKI, and as we look forward to 2025 (and beyond), we are poised to see further shifts in digital security. With continual progression to AI capability and an increasingly expanding digital infrastructure, the importance of securing online identities and workloads will become more and more apparent. This completely excludes the extensive regulatory changes we have seen recently like the EU Identity wallet, and even more cutting edge, such as NIST’s encryption standards for the eventual transition to post-quantum cryptography certificates, signaling a not-too-distant future where we will see a complete shift to the way digital security is conducted.

Considering these changes, PKI will continue to be a foundational element in the broader security landscape, essential for protecting digital identities and securing communications. To maintain a strong security posture, continuous adaptation, and integration of PKI with new technologies are crucial. Organizations should evaluate their current security frameworks and consider how PKI can be integrated or enhanced to meet future challenges. By doing so, they can ensure that their digital infrastructure remains resilient against emerging threats.

##

ABOUT THE AUTHOR

Mohit Kumar 

Mohit is the Vice President of Product Management. He joined GlobalSign in 2018.