Opens in a new tab
vmblog logo 2024 wht (updated)

Torq 2025 Predictions: How GenAI and Hyperautomation Will Reshape SecOps and Threat Landscapes

Share: 

David Marshall | Published: December 16, 2024
vmblog predictions 2025

 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By Leonid Belkind, CTO and Co-Founder at Torq

The cybersecurity landscape in 2025 will be shaped by the transformative power of GenAI and hyperautomation, revolutionizing SecOps operations and defenses. At the same time, these advancements will amplify the capabilities of attackers, creating new challenges for organizations to address. 2025 will bring new challenges to the SecOps space, but new technology and developments that are AI-driven will help us keep pace with the everchanging threat landscape.

Attackers Will Hit SecOps’ Soft Underbelly – With SecOps focused on front-line defense measures, attackers will focus on stack elements and settings that are typically under-protected and less tightly managed. SaaS misconfigurations, access control anomalies, and third-party integrations and gateways are prime examples. With SecOps’ staff overwhelmed and burning out, advanced security automation such as hyperautomation can use GenAI to manage and parse these systems and auto-remediate or escalate threats before they have a chance to take root.

AI Transforms Junior Attackers Into an Existential Threat – In 2025, malicious actors with relatively low technical acumen and proficiency will dramatically benefit from AI. AI will uplevel their skillsets and adversarial capabilities, enabling them to launch high-volume enterprise-wide attacks that were previously the domain of larger-scale criminal organizations. Further, AI will heighten these junior attackers’ social engineering threat possibilities, with multilingual, highly-credible text phrasing when it comes to manipulating people with official-sounding communication.

Every SecOps Organization Will Have a Hyperautomation Lead – GenAI-based Hyperautomation has emerged as table stakes for SecOps. It’s acknowledged across the board as a critical imperative across all organization sizes and verticals. With expanding deployments from every major cybersecurity vendor and partner, SecOps teams will have a critical Subject Matter Expert on hand to deploy, integrate, educate, and interact with vendors.

The End of Fake It ‘Til You Make It Hyperautomation – Hyperautomation was a novel term for much of 2023, but as 2024 unfolded, it went mainstream and was acknowledged by all key analyst firms, and enterprise cybersecurity goliaths. What that meant was countless vendors rebranded legacy SOAR solutions, replete with manual processes and disjointed workflows, as hyperautomation, in an attempt to stay relevant. Going forward, all cybersecurity companies have to build their hyperautomation solutions and practices from the ground up, with native GenAI at the forefront. That means ensuring it’s at the heart of all SecOps processes, as opposed to bolting on old tech to existing SIEM, EDR, or XDR architectures. Further, it’s critical that native GenAI is leveraged, as opposed to offerings from companies specializing in “Fake AI”-in other words, a GPT wrapper that delivers pre-trained output, instead of actual context-specific generative responses.

GenAI Will Dramatically Elevate Autonomous SOC Protection – We will see a quantum jump into a new universe of GenAI in 2025, which will elevate Autonomous SOC capabilities in tandem. SecOps organizations that adopt GenAI-based hyperautomation will benefit from the most advanced LLMs ever, enabling analysts to auto-analyze more events, identify novel threats at the beginning of their cascade of potential impact, rather than after they’ve had a chance to create serious damage. GenAI will also further democratize SecOps, so employees at all levels are able to deploy, manage, and monitor hyperautomation systems through conversational chatbots. What seems simple on the surface will yield the most sophisticated security postures organizations have experienced to date.

As 2025 approaches, the integration of even more AI-powered solutions like hyperautomation will redefine the boundaries of cybersecurity, enabling organizations to achieve unprecedented levels of protection and efficiency, driving ROI and lowering the burden that SecOps teams feel due to the growing talent shortages in the security industry. However, staying ahead will require vigilance, innovation, and a commitment to leveraging these tools responsible to counter increasingly sophisticated threats.

##

ABOUT THE AUTHOR

Leonid Belkind, CTO and Co-Founder at Torq

Leonid Belkind 

Leonid Belkind is the Chief Technology Officer and co-founder at Torq, a no-code security automation platform. Prior to Torq, Leonid co-founded, and was CTO of Luminate Security, a pioneer in Zero Trust Network Access and Secure Access Services Edge, where he guided this enterprise-grade service from inception, to Fortune 500 adoption, to acquisition by Symantec. Before Luminate, Leonid managed engineering organizations at Check Point Software Technologies that delivered network, endpoint and data security products to the world’s largest organizations.