Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By Jane Veeder, Vice President Solutions at CYGNVS
With 2025 right around the corner, cybersecurity remains one of the most critical focus areas for corporations. The evolving nature of the security industry means businesses must stay ahead of threats by continuously adapting to ensure their operations are secure. From combating cybercriminal surveillance to refining incident response plans and enhancing Board-of-Directors-level involvement, 2025 is destined to be another challenging and transformative year. Below, I will explore key predictions for how organizations may find themselves adapting their strategies over the year.
Moving Beyond SMS/Text for Sensitive Communications
In recent years, cybercriminals have shown their ability to exploit vulnerabilities in traditional communication channels like SMS and text messaging. A recent incident involving major telecom carriers highlighted just how easily sensitive data can be intercepted. With the growing sophistication of cyber surveillance, companies can no longer rely on conventional methods for transmitting sensitive internal communications.
Communicating sensitive information – during a crisis or day-to-day – comes in the form of an Out-of-Band (OOB) communication platform. These platforms are entirely separated from an organization’s primary corporate network. Much like a hurricane bunker that safeguards occupants from the storm outside, an OOB platform provides a secure space for collaboration, ensuring that even the most sensitive messages remain protected from prying eyes.
OOB platforms are valuable for facilitating secure communication within an organization and with external stakeholders such as outside counsel and forensic firms. As organizations face increasingly complex cyber threats, OOB platforms will emerge as a cornerstone of secure communications in 2025. If a company does not already have an incident response platform in place at the corporate level, 2025 should be the year they begin exploring and investing in these technologies.
Enhancing Cyber Incident Response Plans
Many organizations are still struggling to develop and execute effective incident response plans. As we approach 2025, the stakes are higher than ever. Cyber incidents are becoming more frequent and impactful, making it imperative for organizations to prioritize their incident response efforts.
To be ready for the challenges of 2025, companies must focus on these critical areas:
- Foster a Cybersecurity Culture: Preparedness begins with people. Organizations must create a culture where cybersecurity is everyone’s responsibility. This includes regular training, awareness campaigns, and fostering an environment where employees feel empowered to act as the first line of defense.
- Strategic Prioritization: Incident response should no longer be viewed as a technical or operational task but as a strategic imperative. This means elevating its importance within the organization and ensuring it receives adequate resources and attention from leadership.
- Improved Documentation and Reporting: Thorough documentation and reporting are essential for effective incident management. Companies must invest in tools and processes that enable real-time tracking and clear, concise reporting to stakeholders. This level of precision will not only help manage the incident but also support post-incident analysis, reporting, and improvements.
- Incident Response Plan Accessibility: Many companies significantly invest time and dollars building out robust incident response plans and yet still find themselves stumbling on easily accessing them in times of crisis. When they are finally able to access these plans, it can be difficult to follow the steps as they were designed. So often, the IR plans go out the window during a crisis. In 2025, companies should spend as much time building their IR plans as they do to ensure accessibility and actionability in times of crisis. This means having plans stored OOB, accessible on mobile apps, and finally, making sure they include dynamic IR playbooks that are not simply static pieces of paper.
Strengthening Board-level Involvement in Cybersecurity
In recent years, Boards of Directors have become increasingly engaged in cybersecurity discussions and planning. Boards have a critical role to play in ensuring their organizations are prepared to navigate cyber risks effectively. However, the extent and quality of their involvement vary widely across organizations.
As we look to 2025, Board involvement in cybersecurity should be a top priority. To maximize the impact of the Board of Directors in an incident response plan, the security team must focus on:
- Policy Identification: Security teams need to work closely with their Board to identify which specific policies and procedures require their direct input or oversight. This targeted approach ensures that the Board-level time and expertise is directed toward the appropriate activities.
- Cyber Preparedness Exercises: Participation in tabletop exercises and business continuity planning will allow Boards to better understand their organization’s vulnerabilities and the potential impacts of a cyber incident. These exercises not only enhance preparedness but also build confidence among stakeholders that cybersecurity is being managed at the highest levels of the organization.
Preparing for a Secure Future
As cyber threats grow in scale and sophistication, organizations must stay ahead by adopting innovative strategies and adopting a culture of continuous improvement. By embracing secure communication platforms, enhancing incident response plans, and deepening Board-level involvement, companies can position themselves to face the cyber incident challenges of 2025.
##
ABOUT THE AUTHOR
Jane brings over 20 years of insurance experience in underwriting, marketing, and client relationship management at the Fortune 500 companies AIG and Zurich; she began her career at Lloyd’s of London. As Director of Global Client solutions, Jane partners with her customers to help curate their CYGNVS experience on behalf of their policyholders. Jane’s goal is to anticipate her clients’ needs, inspiring trust through her creativity and ability to drive successful outcomes.






