Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By James
Mignacca, CEO at Cavelo
The
evolution of AI will dominate next year. While AI technology and its use cases
are still relatively new, we’ll see a transition where AI is increasingly used
to solve real-world problems. Instead of organizations developing their own AI
engines, most will lease AI services from providers like OpenAI, Google, or
Amazon, focusing on applying AI to specific problems.
We’ll
also see AI regulations starting to take shape. These will build on existing
frameworks, addressing discoverability of AI applications across organizations,
updating acceptable use policies, and incorporating AI vendor management into
due diligence checklists. Cyber insurance providers will also begin asking more
targeted questions around AI usage.
AI
adoption is driven by its potential to reshape industries and solve complex
problems. However, as AI becomes more prevalent, malicious uses will also rise.
For instance, unregulated versions of AI tools may enable more sophisticated
social engineering or malware tailored for specific targets. This highlights
the dual challenge of harnessing AI’s potential while mitigating its risks.
CISOs
should prioritize:
- Developing policies
and frameworks for AI adoption and governance. - Conducting due
diligence on third-party AI vendors to ensure compliance and reduce risk. - Preparing for
AI-driven threats by adapting threat models to include AI-based social
engineering and malware risks. - Leveraging
consolidated data from their tech stacks to gain actionable insights and
strengthen defenses against AI-enabled attacks.





