Opens in a new tab
vmblog logo 2024 wht (updated)

Claroty 2025 Predictions: Cybersecurity in 2025 – Critical Sectors at Risk as Legal Challenges and Evolving Threats Demand Urgent Action

Share: 

David Marshall | Published: January 27, 2025

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By Grant Geyer, CSO at
Claroty

As the world becomes increasingly interconnected,
critical infrastructure sectors represent an obvious and unsecured attack
surface area for our adversaries to target. Despite a growing awareness of the
threats posed by state-sponsored adversaries, such as Russia, China and Iran,
many of these sectors remain unaware of the risk and lack the knowledge and
funding to meaningfully secure their digital footprint. At the same time,
broader government efforts to advance cybersecurity legislation and regulation
face new legal hurdles, further complicating the path forward. Looking ahead to
2025, despite governmental actions, the cavalry is not coming to save asset
owners in these key sectors. They must embrace their cyber insecurity and
evolve their strategies to address rising threats, embrace technological
advancements and navigate an ever-shifting legal and regulatory landscape.

Cyber Stagnation in the Water Sector Despite an
Escalating Threat Landscape
 

In 2025, we predict a
continuing  increase in the frequency of
cyberattacks targeting water utilities despite their lack of sophistication.
These attacks will likely exploit long-standing gaps in infrastructure and inadequate
investment in cybersecurity defenses. Adversaries aim not only to disrupt water
supplies but also to undermine public confidence in the U.S. Government’s
ability to safeguard critical resources. Recent government reports have
highlighted these vulnerabilities, yet action remains stalled. The
Environmental Protection Agency’s (EPA) questionable attempts to enforce
cybersecurity standards have been met with strong resistance and the Supreme
Court’s reversal of the Chevron Doctrine further complicates federal oversight.
Unless Congress and industry leaders break the current deadlock, the
consequences could be dire, ranging from disrupted services to significant
public safety risks. 

Regulatory Stagnation and Legal Challenges  

The reversal of the
Chevron Doctrine-a precedent that allowed federal agencies deference in
interpreting vague Congressional language-has created new hurdles for
cybersecurity regulation. This ruling opens the door to legal challenges
against executive branch agencies perceived to overstep their bounds. In the
context of cybersecurity, this could delay critical policies like the Cyber
Incident Reporting for Critical Infrastructure Act (CIRCIA), breach
notification rules and regulations for sectors like transportation and water
utilities. While the federal government has made strides in addressing
cybersecurity risks through legislation and regulation, the Major Questions
Doctrine and other judicial developments may slow progress, leaving critical
infrastructure vulnerable. 

Secure-by-Design
Initiatives Will Force Action by Cyber-Physical System Manufacturers to Produce
More Secure Devices

In October 2023, CISA and many
international partners announced a new initiative on Secure-by-Design for
software manufacturers. While this is not a new concept, the stakes could not
be higher given a number of highly vulnerable and exploitable assets that have
led to major compromises over the past couple of years. CISA has built upon
this work, announcing the Secure-by-Design pledge that has over 200
signatories, including Claroty. However, noticeably absent from the signatories
are cyber-physical system (CPS) device manufacturers. Since that time, CISA has
also issued a Secure-by-Demand initiative to provide
recommended expectations that organizations should expect from their software
manufacturers before, during and after the procurement process. Rounding out
this body of work of “dos” are a set of “don’ts” in the Bad Product Practices Paper. We predict that
this set of initiatives will be further refined and focused in Operational
Technology, creating a set of carrots and sticks that will put pressure on CPS
device manufacturers to drive focused improvements in their technologies. The
expectation isn’t just theoretical: in the November 2024 TSA notice of proposed rulemaking specifically
asks for feedback on incorporating CISA’s Secure-by-Design and
Secure-by-Default principles for Critical Cyber Systems. CPS device
manufacturers need to recognize that the expectation is growing, and leverage
the opportunity to be viewed as eager adopters of this body of work.

Operationalizing Risk Reduction Strategies  

As the cyber-physical
systems (CPS) security landscape evolves, Secure-by-Design initiatives will do
little to secure legacy deployed OT assets. As such, more organizations will
move beyond foundational steps like asset inventories to implement tangible risk
reduction strategies. In 2025, we expect network segmentation to become a
critical focus for organizations aiming to mitigate risks in CPS environments.
This represents a significant cultural shift, as engineering teams have
historically resisted measures perceived to impact operational continuity.
However, organizations serious about risk reduction will recognize the need to
embrace these changes, taking entire classes of risk off the table. 

The Cloud Adoption Tipping Point for Operational
Technology
 

Historically,
industrial enterprises have been reluctant to connect operational technology
(OT) environments to IT systems or the cloud due to concerns about security and
operational risks. In 2025, we anticipate a dramatic shift in this mindset. As
companies recognize the competitive advantages of leveraging cloud-based
services, they will increasingly adopt cloud-delivered cybersecurity solutions.
This evolution mirrors the broader adoption of SaaS-based IT offerings and
reflects the growing understanding that such tools can enhance both operational
efficiency and security. Exceptions to this trend will largely depend on data
sovereignty concerns and regulatory restrictions, but for most organizations,
this shift will yield significant benefits for both engineering and
cybersecurity teams. 

A Year of Transition and Urgency  

The coming year will be
pivotal for the critical infrastructure sectors as they face mounting cyber
threats to CPS environments, regulatory complexities and technological
transitions. From overcoming legal challenges to operationalizing advanced
cybersecurity strategies, organizations must adapt to protect against evolving
risks. Embracing innovations like network segmentation and cloud-based
solutions could mark a turning point, fostering resilience and safeguarding
public trust. However, without breaking the current stalemate in regulatory and
investment efforts, the risks to critical infrastructure will continue to grow,
with potentially severe consequences for public safety and national security.

##

ABOUT THE AUTHOR

Grant-Geyer 

Grant Geyer is Chief Strategy Officer at Claroty, responsible for leading the company?s strategy process, determining possible market opportunities, category adjacencies, and investment theses for value creation. He works with stakeholders in the executive leadership team to determine the best ways to accelerate the execution of the corporate vision. He has had a successful career as an operator in the cybersecurity industry for over 20 years at companies of different stages of growth. He previously served as Claroty?s Chief Product Officer, overseeing the product management, engineering, and research organizations, and was responsible for the company?s product strategy and development. Prior to joining Claroty, he worked as an Executive-in-Residence at Scale Venture Partners, where he assisted the firm in analyzing cybersecurity markets and ventures. Previously, Geyer held the role of Senior Vice President of Products for RSA, responsible for both traditional and SaaS product offerings. Prior to RSA, Geyer served as Vice President at Symantec, which he joined through its acquisition of Riptech. Earlier in his career, Geyer served as a Military Intelligence officer for the U.S. Army. He holds a B.S. in Computer Science from the U.S. Military Academy at West Point and a M.S. in Engineering Management from the University of Maryland, Baltimore.