Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By Tom
Marsland, VP of Technology, Cloud Range
The cybersecurity threat landscape is evolving
at a breakneck pace. With the advent of AI and the growth of the technology,
it’s a wonder CISOs even sleep at night. That said, it’s easy for organizations
to get caught up in the race to implement more cutting-edge security tools and
chase the latest threats. However, around this rapidly changing environment, I
believe many organizations will still struggle to master the fundamentals of
cybersecurity.
2025 will see a significant shift in the
cybersecurity landscape. While the industry has long been characterized by a
proliferation of vendors and a “more is better” approach to security
tools, 2025 will see a greater move towards consolidation. This is driven by a
growing realization that tools alone cannot solve all security problems, and a
more strategic, holistic approach is needed.
The root cause of this shift is that
organizations at the top of their game are realizing that the idea in the
cybersecurity industry today that tools will solve all of our problems, and we
can eliminate people, is a fallacy. There are some things that work well as a
SaaS-based solution, and some things you just need the right people to do the
work. Information security is one where tools help, certainly, but you need
people at the right levels, and companies are loathe to actually invest in
staffing their security teams, which are seen as a cost center, to the right
levels. Instead, they need to understand that security, when done right, is
risk reduction and cost savings.
Let’s look back at Disney this year. In the
case of their breach, Disney seems to have lost sight of the above fallacy –
along with many companies today. The skills shortage isn’t because we don’t
have enough qualified people – it’s because companies are purposely
understaffing their teams to save money, and then switch tools when an incident
occurs instead of actually addressing the root cause here.
I think that in 2025 we will see a shift back
towards people – towards proper training, budgets to support, and these budgets
will be put in place through consolidating tool vendors.
While it may seem counterintuitive, a
surprised number of organizations still fall short on basic security hygiene.
This includes essential practices like vulnerability management, access
control, security awareness training, and data backup and recovery.
Why are these foundational elements still a
challenge? Several factors contribute,
and I don’t see these changing in 2025:
- Resource Constraints: Limited
budgets and staffing shortages can make it difficult for organizations to
dedicate sufficient resources to cybersecurity. - Lack of Prioritization:
Cybersecurity may not be seen as a top priority by business leaders, leading to
inadequate investment and attention. - Complexity: The increasing
complexity of IT environments makes it challenging to implement and maintain
effective security controls.
Some may disagree, and ask for proof, or what
leads to my findings. It’s simple – look at the recent bulletins published by
CISA. They’re all focused on the basics still. Why? Because organizations that
are getting breached are lacking in the basics. Despite these challenges, there
is hope. CISOs can take proactive steps to strengthen their organization’s
security posture by focusing on outcome-driven metrics, the things the Board of
Directors should (or do) care about. CISOs should prioritize measurable outcomes
that demonstrate the effectiveness of their security programs. By focusing on
outcome-driven metrics and continuous improvement, with proper root cause
analysis, a commitment to the basics will only build a more stable foundation
and a more secure future.
##
ABOUT THE AUTHOR
Tom Marsland is a
technology leader and security professional with over 24 years of experience in
the information technology and nuclear power industries. He served over 22
years in the US Navy in the nuclear power and information technology fields,
working in nuclear engine rooms on a myriad of Navy submarine platforms. As the
VP of Technology for Cloud Range, his responsibilities are the Cloud Range
technology stack and service delivery, as well as information security and
enterprise information technology for the organization. He also
volunteers as the Executive Director of VetSec, a 501c3 that helps veterans
find meaningful careers in cybersecurity. He has a bachelor’s degree in IT
security and a master’s degree in cybersecurity. He and his family reside in
the Pacific Northwest, and in his free time, he enjoys backpacking through the
Olympic and Cascade Mountains, enjoying the forested and mountainous outdoors.






