Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By Devin Ertel, Chief Information Security Officer (CISO), Menlo Security
Just a year ago, the cybersecurity world was in a frenzy as the SEC dropped its new reporting requirements, leaving CISOs to decode complex regulations and grapple with unprecedented disclosure timelines. Moving into 2025, the regulatory landscape shows no signs of calming down – in fact, it’s poised to become even more turbulent both within the U.S. and abroad. For companies that operate globally, they will need to adhere to an increasingly complex web of regulations. CISOs must be able to juggle multiple priorities – including compliance, defending against emerging threats and supporting overarching business goals.
Globalized Cybersecurity Incident Reporting
2024 was a year of regulations, including the U.S. National Cybersecurity Strategy announced in May. In 2025, I predict that many other countries will adopt similar policies around reporting cyberattacks and breaches. This means that if you’re leading compliance for a national or global company, you need to figure out all the different reporting requirements for each state and country you do business in. For example, in the U.S., personally identifiable information (PII) protection laws vary state by state, meaning that you will have to comply with each individual state’s regulations. Now imagine this amplified on a global scale, with each country your business touches requiring compliance with different reporting rules.
Complicating this matter further, especially as it relates to PII, is the rise of artificial intelligence (AI). Many products in the market are just embedding AI and “turning it on” without asking permission from users. In many cases, the AI is collecting user data to feed its own algorithms, which could be an incredible breach of various privacy regulations. Companies must rethink their policies as it relates to how AI is used in their products, such as not enabling it by default, having a notice period, and clarifying for users how it’s being deployed and what data is collected. The goal of SEC reporting requirements is a win for the industry and will have ripple effects across all organizations, whether based in the U.S. or not. In the new year, we’ll see a push towards more streamlined and standardized regulations as governments around the globe seek to work together in ensuring transparency and protecting the privacy and security of their constituents.
Contending With AI-Fueled Deepfake Attacks
CISOs must not underestimate the damage threat actors can inflict wielding deepfakes. The CEO of Wiz recently announced his employees were being targeted by sophisticated deepfakes mimicking his voice. Any executive can be impersonated, but those who have many public speaking engagements and a more public presence may be easier to target, because their voices and likeness is more readily available to be leveraged for the creation of deepfakes. Threat actors are continuously developing new ways to weaponize AI, and sophisticated phishing kits are available for sale on the Dark Web, lowering the bar for entry for would-be cybercriminals. Soon, these kits will include more sophisticated tactics including deepfakes, and these seemingly rare examples of high-profile executive impersonations will become much more commonplace.
User education is incredibly important in these types of attacks. CISOs must ensure all employees at their company know, if an “executive” is asking for something abnormal – such as conducting a wire transfer, paying a vendor, buying gifts cards or sharing highly sensitive credentials – they must double check via a trusted form of contact to confirm the ask is legitimate. Whether this is done in the form of a phone call, a text message, an email, over Slack, etc., the ask needs to be verified through an existing and trusted form of communication. For any financial requests, make sure to follow proper procedures and channels and become familiar with the policies within the finance team.
Aligning Cybersecurity with Corporate Goals
In most organizations, the security team has historically been viewed as a restrictive function – limiting what employees can and can’t do, the access they have, what tools can be used, how information is shared both internally and externally, etc. This is often seen by others within the organization as a hindrance – an obstacle to be overcome in the pursuit of achieving company goals. In 2025, CISOs will need to be much more cognizant of aligning initiatives of the security team with the overall business goals and needs. A key part of this shift will be looking for products that naturally provide both a security gain and an improved experience for end users. For example, using biometrics such as fingerprints for Multi-Factor Authentication (MFA) is a way that ease of use and security can join, benefiting the security function and business success.
The CISOs role is shifting, and increasingly these executives are wearing multiple hats. Of course, keeping the organization safe and secure will always be a key responsibility for CISOs, but they must also learn the ins and outs of compliance especially as it relates to cybersecurity incident reporting, and they must be viewed more as a business enabler, supporting the company in reaching overarching business objectives.
##
ABOUT THE AUTHOR
Devin Ertel, Chief Information Security Officer (CISO), Menlo Security
As Menlo’s CISO, Devin is responsible for providing internal cybersecurity guidance and policy insights to both the company and our customers. He is also focused on reducing the company’s risk and security exposure. Devin has over 20 years of experience in cybersecurity. His previous experience includes security positions in several Fortune 100 organizations. During his time with both Mandiant and the U.S Federal Reserve, Devin had hands-on experience mitigating large, high-profile breaches and dealing with highly motivated global threat actors.






