Opens in a new tab
vmblog logo 2024 wht (updated)

Forescout 2025 Predictions: A New Era of Cyber Defense: Predictions for 2025

Share: 

David Marshall | Published: December 23, 2024
vmblog predictions 2025

 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By Ali King, VP of Government Affairs at Forescout

The cybersecurity landscape is set to experience significant changes in 2025 as the U.S. grapples with growing threats to critical infrastructure to include space systems. Among the most impactful developments could be the creation of an independent Cyber Force, redefining how the Defense Department defends against and conducts cyber operations more effectively. This shift calls for fresh thinking about public-private partnership, legal frameworks, and the integration of new talent from diverse backgrounds.

Defending U.S. Critical Infrastructure

With increasingly sophisticated attacks on the OT systems that underpin critical infrastructure, the incoming Trump 47 administration appears poised to take a more hands-on approach. Rather than relying solely on a patchwork of regulatory measures, the administration may look to revamp existing policies that would enable military cyber units to deploy on domestic networks for defense purposes. This move would track with the growing momentum to classify space as critical infrastructure, a nod to the increasing reliance on Space-as-a-Service (SPaaS) technologies for public and government operations. Protecting commercial use satellites and ground systems requires a serious commitment to our cyber defenses, making commercial space assets a key focus for the boarder national security community.

The Emergence of a Cyber Force

“America’s cyber force generation system is clearly broken. Fixing it demands nothing less than the establishment of an independent cyber service,” a report published by the Foundation for Defense of Democracies states.  Unlike conventional military units, a new Cyber Force would leverage a diverse talent pool, opening doors for individuals with the aptitude for, and with existing specialized technical expertise who may not satisfy the requirements for traditional military service members. The emphasis on technical know-how over physical presence reflects a paradigm shift in how national security is conceptualized and operationalized. By teaming up with industry partners, this new service would generate a larger and more diverse talent pool that’s ready to contribute to our national defense.

Transforming Federal Cybersecurity

CISA needs to evolve beyond its 2018 roots to tackle today’s most serious digital threats to the .gov. They should focus more on threat hunting across federal networks, especially in remote operational systems that are overshadowed by the preference for securing traditional IT networks. Addressing these vulnerabilities is critical to strengthening the .gov ecosystem that includes OT and IT networks against increasingly complex cyberattacks from the rise of unsecured, unmanaged IoT devices must be the core focus of the agency.

At the executive level, harmonizing Title 10, 50, and 32 authorities-governing military, intelligence, and National Guard operations-could create a clearer framework for addressing cyber risks. This legal synchronization would empower the White House to act decisively and cohesively in defense of the nation’s digital infrastructure, streamlining our response to cyber threats. Simultaneously, prioritizing the budgets of Sector Risk Management Agencies (SRMAs) and instituting national-level cyber exercises would solidify preparedness and resilience against state-sponsored threats from adversaries like China.

Responding to Escalating Threats

As adversarial cyber campaigns continue to become more prevalent-such as those attributed to groups like Volt Typhoon, Flax Typhoon, Salt Typhoon-the U.S. must double, even triple down on building resilience. National cyber exercises, similar to military war games, will help to identify weaknesses and refine response strategies. Ensuring fiscal support for SRMAs will also enable targeted investments across the most vulnerable sectors, helping to fortify their defenses against evolving threats. For example, Isreal recently conducted a national cyber exercise that included 26 government agencies and 40,000 civil servants.

Bridging the Talent Gap

The establishment of a Cyber Force presents a unique opportunity to expand the potential pool of talent. By decoupling technical expertise from traditional military roles, the DoD can tap into a broader workforce, including civilian cyber specialists, industry veterans, and emerging tech innovators. This approach is designed to maximize the contributions of individuals with the skills regardless of their ability to qualify for combat or physically demanding roles.

By integrating military cyber capabilities with domestic infrastructure defense, establishing a Cyber Force, and fostering robust public-private collaborations, the nation will be better positioned to address the multifaceted threats of the digital age. These advancements will not only enhance security but also redefine the roles individuals and organizations play in the collective defense of critical systems, setting the stage for a safer and more resilient future for America and our partners.

##

ABOUT THE AUTHOR

Ali King 

As a Vice President of Government Affairs at Forescout Technologies, Alison is responsible for the company’s relationships with Congress and the Executive Branch. She leads all legislative functions, federal policy, and strategic partnerships.

Alison holds a Bachelor of Arts in Government and International Relations from George Mason University (GMU), a Master of Science in Conflict Analysis and Resolution from GMU, and a Master of Business Administration from Georgetown University. She is a 2024 Foundation for the Freedom of Democracy (FDD) National Security Fellow and a Senior Fellow at Auburn University’s McCrary Institute.