Opens in a new tab
vmblog logo 2024 wht (updated)

Immersive Labs 2025 Predictions: How We Be Ready to Innovate in 2025 by Combating Fears

Share: 

David Marshall | Published: January 24, 2025

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By Kev Breen, Senior
Director of Threat Research, Immersive Labs

This past year, we
witnessed cyber incidents that left a wake rippling through entire industries,
organizations, and everyday consumers alike. These events ranged from the Change Healthcare breach, which was the largest healthcare data breach to date, to incidents
involving  grounded planes and
tremendously disrupted day-to-day business operations for countless
organizations . For many, these happenings created a sense of fear and distrust
around technology. However, that doesn’t mean our outlook for the new year is
completely bleak.

While we shouldn’t look
to 2025 with rose-colored glasses, the new year presents plenty of
opportunities for cybersecurity leaders and their teams to take advantage of
emerging technologies and gain a new understanding of the cybersecurity
landscape. Above all, it will be essential for businesses to be ready for
whatever the year may bring. Here are my thoughts on the year ahead:

Securing operational technology will be
non-negotiable.

I don’t expect to necessarily see an evolution of
threats, but rather an emphasis on effectively mitigating the already existing
threats. There is typically more focus on physical security or operational
efficiency, so many industrial employees lack the knowledge, skills, and
judgment needed to recognize phishing attempts or suspicious behavior,
increasing the risk of threats, both intentional and unintentional. This is why
education will be the key to preparing for cyber threats.

Beyond the “AI hype train,” it’s the more
overlooked threats that will unleash the most devastating impacts.

We continue to see organizations suffering from
massive ransomware and supply chain attacks year after year – and 2025
will be no different. It is no longer a question of if it will happen to an
organization, but rather when it will happen. This is why threat preparation
and knowing how to respond when the time comes is so crucial. Although these
may not seem as exciting or dangerous, they will continue to drive the vast
majority of costly breaches. 

My colleague, Max Vetter, VP of Cyber at Immersive Labs has a few thoughts on the year ahead based on his
cyber expertise:

GenAI will reduce (and drive up) cyber risks –
organizations need to be ready.

We
now have a clearer picture of how threat actors are utilizing or could
potentially leverage AI. At the same time, DevSecOps teams’ adoption of AI
tools to automate and speed up vulnerability detection will help prevent
exploitable code. I expect that with greater adoption of AI will come increased
cyber threats, and security teams need to remain nimble, confident, and
knowledgeable. In fact, AI upskilling is already required for many teams.
Heading into the new year, security teams must continue to prioritize learning
and analyzing how attackers use and manipulate the technology so that they can
better prepare for when attackers inevitably strike.

The cyber skills gap will expand to more senior
roles.

The
cybersecurity workforce shortage reached a new high of approximately 4.8 million this past year. Not only is there a need for more
junior-level talent, but we are also seeing more and more senior leaders depart
organizations, leaving vacant hard-to-fill spots in the workforce. Skills-first
hiring can make a difference, but addressing the talent shortage will require a
coordinated global effort across both public and private sectors. Additionally,
companies are likely to focus more on upskilling their current teams and
individuals to bridge skills gaps.

Savvy leaders will increasingly ditch
ineffective legacy cyber training.

With
analysts in agreement that traditional cyber awareness training is ineffective,
I expect to see more leaders move away from costly, mind-numbing legacy
training programs. Instead, there will be a need and desire for more effective
hands-on exercising and drills that gives their workforce practice and builds
confidence in their cyber skills.

Dave Spencer, Director of Technical Product Management for Immersive Labs has also been keeping a close
eye on trends this past year and shared how he feels they will transpire in
2025 :

The current upward trend of zero-day exploits
will continue to rise
.

There are a few reasons for this, but organizations
actually have more control over this than they realize. Threat researchers
receive limited kudos and incentives for discovering bugs. Meanwhile, companies
have strict NDAs and pay less than third-party bug bounties. For these reasons,
researchers are less willing to work closely with these companies, and the
companies then lack the speed and agility to detect and resolve vulnerabilities
before they are leveraged by attackers.

Cyber warfare will continue with the current
state of wars and growing global tension.

Nation state-led attackers have two things that no
other type of threat actors have: unlimited time and unlimited budget. This
means they more often than not have the resources and time to successfully gain
access wherever they want. With this said, there are ways to combat cyber
warfare. Organizations in regions with conflict should understand the threats
that impact them. They can do so by conducting regular threat hunts across
their network using the latest threat intel feeds. They should also regularly update
their telemetry with data enrichment based on their assets, use the most
up-to-date techniques, and train their defensive team to be proactive, and
well-drilled on the processes.

AI investments will continue, but demand will
surge for skills where AI falls short.

In 2025, skills in blockchain, SOAR, OT, and
DevSecOps will likely be among the highest in demand, shaping hiring and
workforce development priorities. If security leaders want to strengthen these
areas, they have to make sure they are finding the people that are passionate
about cyber, and giving them the tools and exercising they need to excel.

Regardless of what may
ensue next year, my biggest piece of advice for cybersecurity leaders, along
with Max and Dave’s, is to ensure that your team is ready. While what happens
in the new year is out of our control, we do have a say in cybersecurity leaders
and their teams’ ability to navigate uncertainties, threats, and pressures.
There are several tangible steps to ensure businesses are well-prepared:
ditching traditional training methods, shifting focus to proving cyber
capabilities and improving recruitment and career development.

Bad actors will
continue to capitalize on weak links in organizations’ security frameworks. So,
ensuring we’re ready to face any and all threats is the only way to continue to
succeed in this rapidly evolving landscape.

##

ABOUT THE AUTHOR

Kev Breen is the Senior Director of Cyber Threat Research at
Immersive Labs where he researches new and emerging cyber threats. Prior to his
civilian life Kev, spent 15 years in the military serving as a Radio Technician
and Trunk Comms Specialist before transitioning to a Cyber Security Analyst,
specializing in Malware Analysis. After leaving the military, he continued to
work in Cyber Security running a CIRT team for a defense contractor before
joining Immersive Labs. Outside of his work life, Kev can be found publishing
or contributing to Open Source tools and projects or reading a Sci-Fi book.