Security Strategy

Preparing for the Security Challenges AheadWhat to Expect in the Next 12 Months

AI-powered attacks, identity sprawl, supply chain risk, and regulatory pressure are reshaping what security programs need to defend. Our perspective on what's coming and how to prepare.

The first quarter of 2025 was off to a great start — for malicious actors. We barely had time to tuck our holiday decorations away when news of major attacks began rolling in.

In the first three months of 2025, cybercriminals stole data from a healthcare organization, affecting 1 million patients. They walked away with $1.5 billion worth of digital currency from a cryptocurrency exchange. They began exploiting fresh firewall vulnerabilities. And that was just a warm-up.

These cyberattacks are part of everyday business for threat actors. But for security teams, business as usual no longer works. Organizations need to shift from a cookie-cutter approach to proactive, unified security that adapts to modern challenges. Here are ten predictions for the months ahead.

1. AI tools get cheaper and more accessible to attackers — and threat actors grow more efficient, accurate, and effective with little investment required.

The "as-a-service" economy in the criminal underground has removed many barriers to entry for new waves of cybercriminals — and AI tools will further enable anyone to exploit weaknesses more effectively with little or no infrastructure required. Generative AI tools improve efficiencies at scale — summarizing reconnaissance data in seconds, writing or improving code, and providing unlimited iterations for fine-tuning phishing emails. As cheap, easily accessible AI tools democratize cybercrime, the ranks of malicious actors will grow — and thrive.

2. AI-driven tactics give rise to next-generation attacks and force organizations to reconsider defense strategies.

A November 2024 Gartner survey found that malicious attacks enhanced by AI emerged as the top overall risk for enterprises for the third consecutive quarter. In the next 12 months, these attacks become commonplace — and top of mind for every SOC and CISO. In addition to crafting flawless phishing emails, malicious actors will scale impersonation attacks using AI-generated deepfakes. To combat the knowledge and speed of AI-based attacks, defenses need to employ AI that has more extensive knowledge than attackers and can match their speed.

3. Nation-states continue to weaponize trust, compromising IT vendors to get access to their customers — accelerating the move to zero-trust security.

Nation-state-affiliated actors are doubling down on supply chain attacks on technology and cybersecurity companies because attacks on IT products and services can give them access to a large number of the vendor's customers. Digital Hands observes significant activity targeting security companies — firewall vendors, centralized management tools, SaaS platforms — and zero-day attacks are often a preferred tactic. One of the most effective ways to negate attacks like zero-days and defend against weaponization of trust is through a zero-trust model.

4. The digital supply chain remains as fragile as ever, pushing organizations toward better resilience.

Nation-sponsored actors aren't the only ones weaponizing trust — and it isn't just security vendors that organizations have to worry about. An estimated 90% of companies are undergoing digital transformation, and the expanded digital interconnectivity contributes to a sprawling attack surface across the entire supply chain. The compromise of the Linux XZ Utils tool is a recent example of the enormous impact one compromised link in the supply chain can cause. Supply-chain attacks are very difficult to detect and mitigate — they pass traditional perimeter defenses, and the SOC has no visibility into the vulnerabilities of their organization's partners and suppliers.

5. Ransomware, extortion-based, and sophisticated malware attacks continue to cause major disruption — and attackers target new vectors.

In 2024, ransomware operators may have had their best year yet, with ransom payouts and the number of attacks breaking records. The convergence of AI tools, the rise in double and triple extortion tactics, increased ROI, growing number of ransomware groups, and the booming ransomware-as-a-service economy will continue to escalate the frequency of large-scale ransomware attacks. Email remains the most successful initial access vector — but expect threat actors to target collaboration tools like Slack and Teams, which don't have robust security tools.

6. Industries providing critical infrastructure and services remain at the top of the hit list.

One of the biggest breaches across all sectors last year was the ransomware attack on Change Healthcare, which reportedly paid a $22 million ransom. The attack impacted more than 100 critical software solutions and disrupted thousands of healthcare providers; it has so far cost parent company United Healthcare more than $3 billion. Healthcare is one of the top-targeted sectors because of the criticality of the services that could be impacted. Other critical infrastructure organizations will be major targets, along with organizations that serve as a conduit to numerous businesses.

7. The rapid adoption of generative AI exposes companies to more data privacy and data loss risk.

Organizations are adopting genAI at an unprecedented pace. Their rapidly growing reliance on these tools — especially when provided by third-party vendors — has outpaced their understanding of security risks. AI systems integrated into daily business functions are also processing large amounts of sensitive data like confidential customer information or intellectual property. Unauthorized access creates a big risk of data breaches and leaks, whether caused by unwitting employees or attackers targeting the organization.

8. Complying with evolving requirements ratchets up the pressure on CISOs, risk leaders, and boards, with resilience rising as a priority.

The regulatory landscape continues its evolution with mandates like the Digital Operational Resilience Act (DORA) in the EU and new state privacy laws in the US. AI's broad access to vast amounts of data is also receiving increased attention from regulatory bodies. Cyber insurance is layering on additional pressure. Organizations will need to keep a sharp focus on complying with policy requirements and evolving controls as their environment changes — and ensure incident response plans align with new risks introduced by AI adoption.

9. The increased role of AI in defense redefines security roles while raising liability questions.

With both attackers and defenders leveraging AI for speed and efficiency, the AI arms race intensifies. On the defense side, outcomes include better response playbooks as AI cuts back on noise, enables analysts to derive faster insights, and frees up time for humans to focus on threat hunting. In the next 12 months, most Tier 1 jobs will go away because AI will be trained to take over tasks like low-level, simple data analysis. As more basic and repetitive tasks are automated, the SOC will have to rethink job descriptions.

10. More organizations seek unified security models to combat the proliferation, sophistication, and speed of attacks.

The bulk of IT security pros' time goes to monitoring security platforms. The SOC simply has too many data portals, too many places to find answers, too many settings to worry about. Whether outsourcing security or handling it in-house, more organizations will implement unified security in the next 12 months. The trade-off to "drag-and-drop" platforms: organizations risk losing 24/7 eyes-on-glass coverage and feeling locked into vendors because they no longer have the staffing or skilled experts to stand up and configure something else.

Get Ahead of the Threats

Against this backdrop of growing cyber threats, security landscape complexity, and regulations, many organizations are seeking strategic guidance and tactical assistance from third-party security experts. MDR delivers unified security to help solve the problem of increasingly understaffed and overworked in-house security teams grappling with an increasingly complex threat environment and attack escalation. An expert MDR partner that combines technology and automation with skilled people and effective processes can be a powerful ally as organizations face new threats in the next 12 months and beyond.

Back to Blog

Ready to Get There First?

Talk to a Cyber Expert