As security and risk leaders look to the year ahead, they face a rapidly evolving and dynamic set of challenges. The implementation of more stringent cybersecurity standards—such as the U.S. Security and Exchange Commission’s (SEC) rules and the EU’s Network and Information Security Directive 2 (NIS2)—has placed boardroom scrutiny at an unprecedented level. Boards of directors are now demanding increased accountability from Chief Information Security Officers (CISOs) and Chief Risk Officers (CROs), setting the stage for a pivotal year in 2025.
Cybersecurity leaders must navigate heightened expectations within the context of shifting geopolitical dynamics, evolving technology landscape, and an increasingly sophisticated and automated set of threat actors. A new administration in the White House may introduce changes to technology mandates and regulations, further complicating efforts.
At the same time, the rapid adoption of artificial intelligence (AI) across enterprises is reshaping the risk landscape. While AI brings transformative potential, it also introduces significant new risks. Attackers, ranging from cybercriminals to nation-state actors, are leveraging AI to enhance the scale, automation, and precision of their operations. This dual impact—AI as both a tool for innovation and a vector for exploitation—demands vigilant oversight.
While no one can predict the future with certainty, insights gathered through collaboration with CISOs, cybersecurity researchers, and industry leaders provide a strong foundation for identifying key trends. At Bitsight, our collective observations highlight five critical areas that will shape cybersecurity strategies in 2025.
1. Critical infrastructure remains a target for nation-state actors
The vulnerability of critical infrastructure continues to be a focal point for nation-state attackers. Recent events, such as the devastation caused by the LA wildfires, underscore the fragility of critical systems. Beyond natural disasters, cyberattacks targeting power plants, water facilities, hospitals, and other essential services pose an equally significant threat.
Over the past two years, there has been a marked increase in nation-state actors targeting critical infrastructure. Jen Easterly, Director of CISA, recently emphasized the persistent focus of adversaries on exploiting these vulnerabilities. Healthcare systems, as evidenced by last year’s attacks on United Healthcare and Ascension Health, are particularly exposed.
Organizations must adopt a comprehensive strategy that includes visibility into both their internal assets and the extended digital supply chain. This approach is essential to addressing third-party risks that are often overlooked but can have catastrophic consequences.
2. AI: A double-edged sword in cybersecurity
AI is both a transformative force and a significant risk multiplier. As AI technologies become more widely adopted, their dual impact will reshape cybersecurity in 2025.
“Digital attacks leveraging AI will exponentially increase, creating renewed focus on enterprise security and digital supply chains,” notes David Casion, Bitsight’s CTO. While AI-enabled tools are accelerating productivity and incident response, they are equally enhancing the sophistication of cyberattacks.
As he explains, the AI tooling landscape is getting a lot of investment and deployments are on the rise. The union of larger context windows, agents, text to action, and other capabilities will enable businesses to derive even more value from AI-enabled productivity tools that can do everything from speeding up invoice handling in the finance department to cutting down on incident response times in the cybersecurity department. “But as AI moves forward rapidly, that tooling can be used for things good and bad,” Casion warns.
AI introduces two primary categories of risk: vulnerabilities within AI systems themselves and the exploitation of AI by attackers. For example, AI-powered phishing campaigns are now more targeted, multilingual, and effective, often bypassing traditional detection methods. To counter these threats, organizations must retrain their teams to understand the shift in attacker capability and consider integration of AI-driven capabilities into their own security programs.