Opens in a new tab
vmblog logo 2024 wht (updated)

DataBee 2025 Predictions: Five Cybersecurity Predictions for 2025

Share: 

David Marshall | Published: January 21, 2025

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By
Robin Das, Executive Director, DataBee

The
cybersecurity landscape continues to remake itself as new technologies become
available to both security teams and bad actors. There’s always something new
to be aware of, yet as we’ll see, it’s sometimes the known, mundane things that
can be a greater threat than the latest shiny new tool or attack type. Much has
been made of AI, for instance, but is it as amazing as we’ve been led to
believe? Are more tools and greater complexity the best way to address new
threats, or is it time to reassess and scale back?

Here are five
predictions for what’s ahead based on trends, news and client interactions.

Prediction
1: AI moves from hype to reality

2025 the AI
bubble will burst, and the industry will hit what Gartner refers to as “the
trough of disillusionment”. We should expect to see many internally funded
projects killed as the hype dies down. However, we also anticipate seeing a
move for teams to start operationalizing AI for basic security hygiene (AI acts
as a night watchman rather than as a ninja). This will include using AI as a
force multiplier on basic, mundane, repetitive tasks versus acting as a virtual
replacement for the security operations center (SOC).

Prediction
2: Companies will accept that breaches are a when, not an if

Companies
will focus more on better cyber resilience and recovery versus defense, which
will become tablestakes. They will begin moving toward the assumption that
getting breached is the unfortunate default when it comes to an enterprise’s security
posture and look for ways to mitigate and minimize its impact.

Prediction
3: A hiatus on new tools as companies move to simplify their stacks

As part of
cyber technology convergence, companies will move toward fewer platforms as
they try to simplify their tech stacks. They will be focused on maximizing the
ROI from the tools they have rather than buying new ones. At the same time,
tool sprawl will be replaced by data sprawl as the top concern for security and
IT teams in 2025.

Prediction
4: More breaches will come from an organization’s business ecosystem than any
other threat vector

Third-party
risks (such as cloud service vendors, outsourcers and suppliers) will surpass
internal sources of exposure as the biggest driver of enterprise breaches. Such
attacks can have a huge ripple effect, as we saw with the 2020 SolarWinds
attacks, one of the most prominent examples the industry has seen in recent
years.  Overcoming this risk will require
organizations to take a closer look at their vendors, including conducting
vendor-risk assessments that assess potential vendors for history of breaches, security
protocols and compliance with standards – before deploying.

Prediction
5: AI won’t be the biggest threat

We’ll see a
significant rise in the use of AI in social engineering phishing attacks, but
the biggest vulnerability for enterprises – especially to these types of
attacks – will be a lack of basic security hygiene. The AI might get the
attacker in, but their lateral movement inside the enterprise will be because systems
aren’t patched appropriately, or Zero Trust Network Access controls haven’t been
fully implemented. Consequently, organizations will need to strengthen their education
and training-and run it at frequent intervals. They will also need to “pay
down” their cybersecurity technical debt by cleaning up their asset management
systems, implementing multi-factor authentication (MFA) and performing regular software
updates across the enterprise.

Preparing
for what’s ahead

As with so
many new technologies, there is hype and then there’s reality. For instance, AI
holds great promise but isn’t ready to completely take over the SOC analyst’s
job, and it’s only so useful if companies aren’t observing basic cyber hygiene.
In 2025, companies will do well to reduce the complexity of their tech stacks, focus
on a comprehensive data strategy that brings together both enterprise and
security data for better insights into their risk posture, and shift their
mindset to cyber resilience and managing vendor risks.

##

ABOUT THE AUTHOR

Robin-Das 

Robin Das is
the executive director of market growth strategy for DataBee, Comcast
Technology Solutions’ cybersecurity business unit. In this role, Robin is
responsible for defining DataBee’s unique value proposition in the market,
long-term strategy and product vision, and business development opportunities
via outreach to strategic targets, partnerships, alliances and other
investments to continue to drive overall growth. 

The views and opinions expressed
by the individuals herein are their own and do not reflect any official policy
or position of Comcast. These views and opinions are provided for illustrative
purposes only and Comcast makes no warranties, whether express, implied, or
statutory, regarding or relating to the accuracy of such statements.