General Atomics

Cybersecurity trends in 2025

Usman Choudhary, Chief Product & Technology Officer, VIPRE Security Group, shares his thoughts on security trends that will likely dominate in 2025.

Image courtesy VIPRE Security Group

Last year saw increasingly sophisticated cybersecurity threats as criminals leveraged all forms of AI to create difficult-to-detect phishing attacks, deepfakes and ransomware incidents. To counter these, organisations adopted AI-driven security solutions including threat detection, automated incident response and intelligent vulnerability management, to protect data and infrastructure.

In 2025, as AI evolves further in sophistication and adoption, alongside the growing burden of data breach costs and regulation – in addition to implementing advanced cybersecurity measures, organisations must prioritise real-world security awareness training.

Combatting AI-powered phishing presents SMEs biggest cybersecurity challenge
In 2025, AI-driven phishing will evolve into a more sophisticated and stealthy threat. Cybercriminals will leverage AI to craft highly personalised attacks using publicly available data and advanced language capabilities, making these scams increasingly difficult to detect. This emerging strategy of threat actors involves multistage attack chains where initial communications appear innocuous, gradually building trust before delivering malicious payloads.

Attackers will specifically target platforms like Microsoft 365 and Google Workspace, exploiting their inherent limitations for credential harvesting. Ransomware actors will develop ‘hybrid’ campaigns that blend phishing techniques with nuanced social engineering, manipulating recipients into unwittingly downloading dangerous files.

Small and medium enterprises (SMEs) are at risk of becoming prime targets due to their limited cybersecurity resources. Criminals will not only directly attack these organisations but also use them as strategic entry points for more extensive supply chain attacks into larger enterprises.

Adoption of AI-driven email drafting tools increasing mis-delivery-related data breaches
Already, misdirected emails have become a critical cybersecurity concern. Potentially, it is the most common cyber incident reported to the UK’s Information Commissioner’s Office (ICO) from a GDPR compliance standpoint.

The rise of hybrid work model and the use of personal devices for work-related tasks often leads to misdirection of email, incorrect file attachments and miscommunication. Auto-complete and auto-correct features in popular email clients such as Outlook and Gmail further exacerbate the risk of misdirected emails, especially as often multiple contacts have similar names.

As the adoption of AI-driven email drafting tools grows in 2025, the potential for data breaches triggered by misdirection increases exponentially. These advanced email writing assistants not only draft content but also suggest recipients based on historical patterns, introducing an additional layer of complexity. The consequences can be severe and costly. A single misdirected email can expose sensitive information to unintended recipients, highlighting the importance of vigilance and careful review in today’s increasingly automated communication environment.

Exploitation of supply chain vulnerabilities through AI-generated malware to increase
The cybersecurity landscape in 2024 witnessed a noticeable increase in the use of malware by cybercriminals to breach corporate networks, leading to widely publicised data leaks and reputational damage for the organisations involved. Likewise, criminals exploited supply chain vulnerabilities to infiltrate systems and cause severe disruptions, highlighting the far-reaching consequences of software integrity failures.  

In 2025, cybercriminals are poised to deploy AI-generated malware to breach both corporate networks and exploit supply chain ecosystems for vulnerabilities. They will leverage AI to develop highly evasive malware to bypass traditional detection methods while also automating vulnerability scanning and phishing. To neutralise these threats, security professionals will need to respond with equally proactive and innovative defensive strategies, including seamlessly integrating zero-trust architecture, embedding AI-powered tools, and implementing rigorous software development practices into their operational workflows.

Mounting data breach costs and regulatory burden drives security awareness training
In 2024, enterprises faced an increasingly challenging cyber threat landscape, as cybercriminals successfully exploited the most advanced technologies, including AI, to breach organisations and cause mayhem. Research shows that the average cost of a data breach reached an all-time high with the global average cost of a data breach estimated at $4.88 million. Human error still remains the number one reason for a successful data breach.

To address this continuously intensifying situation, the regulatory burden is set to increase even more in 2025. The EU AI Act – which has already taken effect – holds significant implications for organisations using AI in their operations, including cybersecurity and privacy. In the US, several states have either enforced or are enacting Data privacy laws in 2025, with all looking to address the collection, use and disclosure of personal data. These laws impose various obligations on businesses, including data protection, breach notification and consumer rights.

The fallout of cybersecurity breaches in 2025 alongside the toughened regulatory landscape will give further impetus and urgency to security awareness training. While technological solutions are of course critical to defend against the constant onslaught of cyber-attacks, employees’ understanding of the threat landscape and vigilance is indispensable for mitigating cybersecurity risk and demonstrating regulatory compliance.

Related

From 66 aircraft to £62.9 billion: The extraordinary evolution of Farnborough International Airshow
Farnborough International Airshow
From 66 aircraft to £62.9 billion: The extraordinary evolution of Farnborough International Airshow
This week, Farnborough International Airshow celebrates 78 years since the first airshow took place. Here's how Farnborough has become a global marketplace for aerospace and defence... and what's next.
Aerospace Defence Space

8 Sep 2026

UK flights disrupted after NATS flight processing system failure
Heathrow Tower.
UK flights disrupted after NATS flight processing system failure
Departures from airports across the UK have been restricted after a technical problem struck the system used by NATS to process flights.
Aerospace

8 Sep 2026

CILT(UK) calls for coordinated UK airports strategy
Heathrow
CILT(UK) calls for coordinated UK airports strategy
In its response to the draft HENPS (Heathrow Expansion National Policy Statement) consultation, the Chartered Institute of Logistics and Transport in the UK (CILT UK) has called for the transformation that has taken place across UK aviation to be recognised with a policy fit for all UK airports, not just Heathrow.
Aerospace

7 Sep 2026

From 66 aircraft to £62.9 billion: The extraordinary evolution of Farnborough International Airshow
Farnborough International Airshow
From 66 aircraft to £62.9 billion: The extraordinary evolution of Farnborough International Airshow
This week, Farnborough International Airshow celebrates 78 years since the first airshow took place. Here's how Farnborough has become a global marketplace for aerospace and defence... and what's next.
Aerospace Defence Space

8 Sep 2026

UK military to practise mobilising 95,000 veterans for war
Soldiers on patrol
UK military to practise mobilising 95,000 veterans for war
The UK will test how quickly it can recall and equip former military personnel as the MoD prepares its 95,000-strong Strategic Reserve for a potential major conflict.
Defence

8 Sep 2026

MBDA opens Poland missile facility as UK defence partnership deepens
MBDA facility Czosnow, Poland
MBDA opens Poland missile facility as UK defence partnership deepens
In an initiative that supports the UK’s commitment to reinforcing NATO’s eastern flank by bolstering Polish air defences, a new facility built with British expertise has been opened in Poland.
From 66 aircraft to £62.9 billion: The extraordinary evolution of Farnborough International Airshow
Farnborough International Airshow
From 66 aircraft to £62.9 billion: The extraordinary evolution of Farnborough International Airshow
This week, Farnborough International Airshow celebrates 78 years since the first airshow took place. Here's how Farnborough has become a global marketplace for aerospace and defence... and what's next.
Aerospace Defence Space

8 Sep 2026

SaxaVord secures £60m funding to expand its launch capability
SaxaVord Spaceport, Shetland
SaxaVord secures £60m funding to expand its launch capability
Operating the only licensed vertical launch spaceport in the UK, SaxaVord is looking to advance its launch capability with fresh funding from the UK Government and private investors.
Space

8 Sep 2026

UK unveils £7.8bn space strategy as threats in orbit grow
View of the UK from the International Space Station.
UK unveils £7.8bn space strategy as threats in orbit grow
The UK will invest more than £3 billion in military space capabilities under a new £7.8 billion strategy covering defence, security and connectivity.
Defence Space

8 Sep 2026

MBDA opens Poland missile facility as UK defence partnership deepens
MBDA facility Czosnow, Poland
MBDA opens Poland missile facility as UK defence partnership deepens
In an initiative that supports the UK’s commitment to reinforcing NATO’s eastern flank by bolstering Polish air defences, a new facility built with British expertise has been opened in Poland.
Chess introduces AI-enabled Low SWaP CHARM50
Low-SWaP-CHARM50
Chess introduces AI-enabled Low SWaP CHARM50
Chess Dynamics has expanded its Vision4ce CHARM portfolio with the introduction of its Low SWaP CHARM50, a new compact AI-enabled edge video processing module which supports growing demand for smart sensors, distributed sensing architectures and low-SWaP ISR applications.
UK firms exposed by simulated attacks on satellites, subsea cables and financial infrastructure
Lockheed martin cybersecurity
UK firms exposed by simulated attacks on satellites, subsea cables and financial infrastructure
How a new FCS exercise brought financial firms and the MoD together to gain a better understanding of modern threats to British financial services and how to better prepare.
Defence Security

8 Sep 2026