Opens in a new tab
vmblog logo 2024 wht (updated)

BeyondTrust 2025 Predictions: Preparing for 2025 – Key Cybersecurity Trends and Challenges Shaping the Future

Share: 

David Marshall | Published: January 28, 2025

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By Morey Haber, Chief Security Advisor at BeyondTrust

So far this decade, we’ve had everything from high-stakes cyberattacks
and world-stopping technological malfunctions to a global pandemic. As we look
ahead to 2025, we need to contemplate the cybersecurity trends coming into
focus and start planning for those yet to take shape.

For this edition of our annual cybersecurity trend predictions, we’re
sharing our top prognostications for 2025, as well as a glimpse into the key
emergent trends we foresee taking hold in the remainder of the decade.

With so much on the horizon, it’s critical for organizations to stay
vigilant and keep their security strategies tuned in to the latest trends.

Now, let’s delve into what’s on the way in 2025.

AI2 Bursts its
Bubble, Bringing Down the Hype of the AI Threat

The Artificial Inflation (AI) of Artificial Intelligence (AI)-or AI2-has already peaked in 2024. Watch as the bubble
relentlessly bursts across multiple verticals throughout 2025.

While some of the promises of AI have come true, and technology (like
ChatGPT and its plugins) will continue to impress with its capabilities,
AI-based technologies have largely failed to live up to the mountainous hype.

Select markets, tools, and technology are truly benefiting from AI, but
in many circles, the terms “AI-enabled” or “AI-driven” are overused and
inappropriately promised. An implication here is that these terms will continue
to take on more negative connotations that could actually hurt marketing of the
product or capability with which it’s associated.

In 2025, we expect the industry to pull back on the promises,
investment, and hype of new AI capabilities and settle down into what is real
versus marketing noise. We’ll see narrow AI (not Artificial General
Intelligence-this is decades out, at best guess) settle into industry use as a
tool angled for basic security and AI workflows. Some examples might include
automating the creation of products, streamlining supply chain workflows, and
reducing the complexity and skill level needed to perform certain tasks, based
on security best practices outlined by models like ATLAS from
MITRE
.

We can expect to see basic attacks continue their 2024 pattern of
increase because AI lowers the barrier of entry. That said, generative AI will
not substantively increase the frequency of advanced, targeted, bespoke attacks
in 2025.

Planned Obsolescence Forces Electronic Exodus

In October 2025, we’ll see one of the most significant end-of-life (EoL)
announcements since Windows XP. Microsoft has plans to end-of-life Windows 10
(completely and for good-unless you are willing to pay for extended support).
This means hundreds of millions of systems will lack the hardware requirements
for Microsoft’s newest OS and be unable to upgrade to Windows 11. Those systems
will become obsolete, and many will end up in landfill.

Much of the hardware we use today simply cannot be upgraded due to
dependencies on hardware and software security features. Only new computers
with both Secure Boot and TPM will be supported, and able to migrate to Windows
11-unless Microsoft chooses to remove these restrictions (highly unlikely, even
though there are workarounds). Operating systems updates and security patches
will cease to be generally available for these noncompliant systems, which,
consequently, will become increasingly vulnerable over time.

Thus, a flood of perfectly functional, but vulnerable and obsolete
notebooks, laptops, and desktop computers, will go up for sale or recycling in
the second half of 2025. As a result, the hardware market will get a
much-needed boost, including a switch to ARM processors.

We can also expect to see a significant increase in the use of
alternative desktop operating systems, like Linux, Mint, or Ubuntu Desktop, as
organizations and individuals seek to minimize the cost of hardware
replacement.

Clone Wars: Reverse Identity Theft Begets Digital
Doppelgangers

Expect to witness a rise of reverse identity theft, where all the breach
data stolen over years past is improperly merged with additional data and
assumptions of who you really are to create faux personas of your digital
identity.

Almost everyone is aware of the concept of identity theft. Entire
businesses are built on identity threat detection and the protection
of services and financials. However, reverse identity theft is a relatively new
concept. It occurs when your identity is falsely associated with another
identity that is not yours.

Reverse identity theft can happen when someone else uses your email
address or phone number (by mistake or intentionally) to sign up for something,
resulting in all their personal information being sent to you. In a more
advanced form, reverse identity theft can involve the electronic and public
linkage of an alias-or other identity-to your own without your knowledge, for
some nefarious mission.

Threat actors are already merging data incorrectly based on name or
other common fields due to the vast number of data breaches that make this
information available. For people with common names, it can result in faulty
collection claims, errant emails, and other annoyances. For others, it can be a
case of extreme mistaken identity or accusations of having a doppelganger. If
you think this is outrageous, go down the rabbit hole of John Titor and explore
which one of the authors has been accused of reverse identity theft.

Hidden Paths to PrivilegeTM Become the New
Cybersecurity Battleground

In 2025, organizations will face more identity compromises that,
initially appear insignificant at the outset, but represent Paths to PrivilegeTM
that allow an attacker to assume control of significant resources through
privileged escalation. These major threats will metastasize out of seemingly
minor identity issues such as hidden, convoluted, or otherwise non-obvious
trust relationships, misconfigurations, or granting of obscure entitlements.

Attackers will continue to innovate and show enhanced understanding of
cloud permissions, roles, and entitlements that allow them to gain the upper
hand against defenders who weren’t even aware of the risks.

Unfortunately, these attacks will escalate in 2025 and use traditional
attack vectors for exploitation. These will range from misconfigurations to
spray attacks (all preventable), and much more.

The open opportunity for threat actors to gain privileged
access based on low level accounts will lead security professionals to
re-evaluate their hygiene so they can prevent path to privilege attacks
via lateral movement.

Conclusion: Don’t Delay Your Security Preparations

If there’s one trend that has proven staying power, it’s the importance
of preparing for what’s to come. In the words of Hunter S. Thompson, “A
man who procrastinates in his choosing will inevitably have his choice made for
him by circumstance.”

Research continues to show that enterprises with more proactive IT
security postures prevent more threats, identify potential security issues
faster, suffer fewer breaches, and minimize damage from attacks more
effectively than less prepared organizations.

In the coming years, proactivity will involve adapting your security
defenses to resist threats that pose increasing levels of disruption to
security infrastructure itself. With the rise of quantum computing, that may
mean pre-empting threats that don’t even exist yet. However, it also means
pivoting quickly to adapt to security shifts already underway. For instance,
it’s already easier for threat actors to log in than hack in, making identity
security a high priority for today and the years ahead.

##

ABOUT THE
AUTHOR

Morey-Haber 

Morey J. Haber is the Chief
Security Advisor at BeyondTrust. As the Chief Security Advisor, Morey is the
lead identity and technical evangelist at BeyondTrust. He has more than 25
years of IT industry experience and has authored four books: Privileged Attack
Vectors, Asset Attack Vectors, Identity Attack Vectors, and Cloud Attack
Vectors.