Technological research and consulting firm Gartner has announced the top cybersecurity trends for 2025.
The six main trends are influenced by the evolution of generative AI (GenAI), digital decentralisation, supply chain interdependencies, regulatory change, endemic talent shortages, and a constantly evolving threat landscape.
“Security and risk management (SRM) leaders face a mix of challenges and opportunities this year, with a goal to enable transformation and embed resilience,” explained Alex Michaels, senior principal analyst at Gartner.
“Their efforts in achieving both are crucial to support their organization’s aspirations to not only innovate, but ensure their innovations are secure and sustainable in a fast-changing digital world.”
The trends are as follows:
1. Managing Machine Identities
The increasing adoption of GenAI, cloud services, automation, and DevOps practices has led to the prolific use of machine accounts and credentials for physical devices and software workloads, the research firm noted.
However, if left uncontrolled and unmanaged, machine identifies can significantly expand an organisation’s attack surface.
According to Gartner, SRM leaders are under pressure to build a strategy to implement robust machine identity and access management (IAM) to protect against attacks, but it must be a coordinated enterprise-wide effort.
A Gartner survey of 335 IAM leaders, conducted between August and October 2024, found that IAM teams are only responsible for 44% of an organisation’s machine identities.
2. GenAI Driving Data Security Programmes
Most security efforts and financial resources are traditionally focused on protecting structured data such as databases. But with the rise of GenAI, it’s transforming data security programmes, shifting focus to protect unstructured data—text, images, and videos.
“Many organizations have completely reoriented their investment strategies, which has significant implications for large language model (LLM) training, data deployment and inference processes,” said Michaels.
“Ultimately, this shift underscores the changing priorities that leaders must address as they communicate the impact of GenAI on their programs.”
3. Optimising Cybersecurity Technology
According to a Gartner survey of 162 large enterprises, conducted between August and October 2024, organisations use an average of 45 cybersecurity tools.
With over 3,000 vendors in the cyber space, SRM leaders need to optimise their toolsets to build more efficient and effective security programmes, Gartner suggested.
The firm recommends aiming for a balance that procurement, security architects, security engineers, and other stakeholders are satisfied with to maintain the right security posture.
To achieve this, SRM leaders should consolidate and validate core security controls and focus on architecture that enhances portability of data.
Threat modelling and organisational technology drivers such as AI adoption can also be used to assess advanced needs.
4. Being Increasingly Tactical with AI
Gartner highlighted that SRM leaders are facing mixed results with their AI implementations, leading them to reprioritise their initiatives and focus on narrower use cases with direct, measurable impacts.
These more tactical implementations align AI practices and tools with existing metrics, fit them into existing initiatives, and enhance visibility of the real value of AI investments.
“SRM leaders now have clear responsibilities to secure third-party AI consumption, protect enterprise AI applications and improve cybersecurity with AI,” noted Michaels.
“By focusing on more tactical, demonstrably beneficial improvements, they can minimize the risks for their cybersecurity programs and can more easily demonstrate progress.”
Recommended reading
- Arctic Wolf Threat Report: Ransomware As A Service On the Rise
- Deepfake Fraud Explodes 2,000% In Three Years
- NHS Staff Don’t Think They’re Cyber Ready, BT Finds
5. Extending Security Behaviour and Culture Programme Value
Security behaviour and culture programmes (SBCPs) have reached an inflection point for most organisations, the research firm said, with effective leaders recognising the value these programmes bring to improve their cybersecurity posture.
According to Gartner, one of the largest drivers of change in these programmes is GenAI. Enterprises combining the tech with an integrated, platforms-based architecture in SBCPs will experience 40% fewer employee-driven cybersecurity incidents by 2026.
This trend is gaining traction due to increasing recognition that both good and bad human behaviour are critical components of cybersecurity.
As a result, cultural- and behaviour-focused activities have become a prominent approach to address cyber-risk comprehension and ownership at the human level.
6. Addressing Cyber Burnout
Gartner highlighted that SRM leader and security team burnout is a key concern for an industry already impacted by a systemic skills shortage.
Pervasive stress stems from relentless demands associated with securing highly-complex organisations in constantly changing threat, regulatory, and business environments, with limited authority, executive support, and resources.
“Cybersecurity burnout and its organizational impact must be recognized and addressed to ensure cybersecurity program effectiveness,” said Michaels.
“The most effective SRM leaders are not only prioritizing their own stress management, they are investing in teamwide wellbeing initiatives that demonstrably improve personal resilience.”





