Opens in a new tab
vmblog logo 2024 wht (updated)

Intezer 2025 Predictions: Cybersecurity in 2025 – The Rise of Agentic AI, Evolving Threats, and Growing Talent Shortage

Share: 

David Marshall | Published: January 24, 2025

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By
Itai Tevet, CEO & Co-Founder, Intezer

As we enter 2025, the cybersecurity
industry is at a critical crossroad. Fueled by generative AI (GenAI), cyber
threats are escalating in scale and sophistication, pushing security teams to
the brink. At the same time, innovation in AI-driven solutions is ushering in a
new era of defense. In this evolving landscape, we expect agentic AI to
dominate security operations, AI-driven attacks to intensify, talent shortages
to deepen, and Service-as-Software (SaSo) platforms to transform cybersecurity
workflows.

1. The Big Buzzword for
2025: Agentic AI

Agentic AI refers to autonomous systems
that mimic human decision-making to perform tasks, interact with tools, and
adapt to challenges in real time. Unlike static automations, AI agents bring
context, flexibility, and intelligence to critical security operations
workflows-particularly in alert triage and incident investigation, areas where
traditional tools fall short.

By the end of 2025, the majority of
security operations teams will rely at least partially on AI agents as
“virtual analysts” to handle routine and repetitive tasks. These
AI-powered agents will:

  • Triage alerts at scale,
    dramatically reducing false positives.
  • Conduct contextual investigations
    autonomously.
  • Orchestrate responses across
    external systems and tools.

For security operations teams, AI agents
represent a transformative force, extending the capacity of human analysts. By
reducing noise and automating complex decisions, security teams can shift focus
to high-priority tasks like threat hunting, remediation, and strategy.

Gartner predicted that GenAI will
contribute to a 30% reduction in false positive alerts by 2027, but by
utilizing the full potential of agentic AI, Intezer customers are already
achieving a more than 70% reduction. This gap highlights the immense value agentic
AI brings to modern security operations-and it’s just the beginning.

2. AI-Powered Cyber
Attacks: Fighting Fire with Fire

While defenders adopt AI, attackers are
already using the technology to enhance their capabilities. By 2025, I predict
that the majority of cyberattacks will leverage GenAI to automate malware
creation, real-time exploits, and hyper-personalized phishing campaigns.

Gartner has warned that through 2025,
cyberattacks leveraging GenAI will force companies to lower their detection
thresholds, which in turn will generate even more alerts.

This creates a dual challenge for
security operations teams:

  1. More sophisticated attacks require faster, more precise detection.
  2. Lower detection thresholds will flood teams with an even greater
    volume of alerts.

Here, agentic AI becomes indispensable.
By autonomously managing triage and investigation, AI agents help security
teams counter AI-driven threats with AI-driven defense. The bottom line:
fighting AI with AI is no longer optional-it’s essential.

3. The Cybersecurity
Talent Shortage and the Role of AI

While AI agents will alleviate many
operational burdens, their rise presents a paradox: they risk displacing
entry-level roles crucial for developing future cybersecurity talent.

Tasks like alert triage, traditionally
assigned to junior security operations analysts, are now being automated. This
mirrors what’s happening in sales, where AI tools have replaced entry-level SDR
roles, limiting opportunities for newcomers to gain foundational skills.

The cybersecurity industry cannot afford
to let this trend exacerbate the existing talent shortage and rampant burnout.
In fact, according to Gartner’s Top
Trends in Cybersecurity for 2025
83% of IT security professionals admit
burnout has led to security breaches, while 46% of cybersecurity professionals
left their roles in 2024 due to high stress.

To address this, the industry must
rethink its approach to talent development:

  • Hire for potential, prioritizing
    adaptability and growth over rigid experience requirements.
  • Invest in upskilling programs that
    teach AI-augmented workflows.
  • Create structured career pathways
    that ensure talent grows alongside AI adoption.

By pairing AI advancements with robust
training initiatives, organizations can bridge the gap and build a sustainable,
resilient workforce.

4. The Emergence of
Service-as-Software (SaSo)

In 2025, Service-as-Software (SaSo) will
emerge and begin to shift how the enterprise approaches security operations by
transitioning services traditionally delivered by human teams into AI-powered
software solutions. SaSo platforms streamline complex, human-driven security
workflows into scalable, cost-effective software, enabling organizations to
achieve operational efficiency. Tasks like alert triage, investigation, and
cross-tool interaction will be executed autonomously, reducing the need for
extensive human intervention.

Gartner estimates that for every dollar
spent on software, 1.5x more is spent on IT services, representing a massive
opportunity for AI-driven solutions. And in cybersecurity-where 3.5 million
positions remain unfilled-SaSo platforms will act as force multipliers,
reducing costs, optimizing workflows, and empowering strained teams to focus on
critical priorities.

Conclusion

As cyber threats grow smarter and the
talent shortage persists, the cybersecurity industry must adapt. AI agents will
define the next chapter in security operations, transforming security
operations workflows, countering AI-driven attacks, and empowering human
analysts to focus on what matters most.

However, organizations must address the
unintended consequences of AI on talent development. By embracing agentic AI
while investing in training and mentorship, security leaders can navigate 2025
with resilience, efficiency, and agility-ready to meet the challenges of
tomorrow’s cybersecurity landscape.

##

ABOUT THE AUTHOR

Itai-Tevet 

Itai
Tevet is the CEO of Intezer, a leading provider of AI-powered technology for
autonomous security operations. He previously led a government Computer
Emergency Response Team of elite specialists in incident response, digital
forensics, malware analysis, and reverse engineering. His experience led him to
co-found Intezer in 2016, with a mission to research and develop technologies
to transform the way we investigate and respond to cybersecurity incidents.