The World Economic Forum has released its Global Cybersecurity Outlook 2025 report, which sheds light on the pressing challenges in cyberspace, shaped by geopolitical tensions, cyber-inequity, and technological advancements.
The research unpacks a huge range of cybersecurity concerns, backed with empirical research and high-level surveys.
Below, we’ll unpack some of the key data and insights from the research.
Unpacking the Complexity of Cyberspace
Cyber-space is becoming increasingly intricate due to interconnected factors:
- Geopolitical Uncertainty: Rising global tensions heighten risks of state-sponsored cyber-attacks and espionage.
- Supply Chain Vulnerabilities: Organisations struggle with limited visibility into suppliers’ cybersecurity practices, with 54% of large entities citing supply chain challenges as their top concern.
- Emerging Technologies: Innovations such as AI and genAI introduce new vulnerabilities. Despite 66% of organisations anticipating AI’s significant impact on cybersecurity, only 37% have implemented measures to secure these tools pre-deployment.
- Regulatory Fragmentation: The proliferation of disparate cybersecurity regulations complicates compliance, with 76% of CISOs stating this hinders their resilience efforts.
The Divide of Cyber-inequity
Cyber inequity – essentially, disparities in cybersecurity readiness – continues to grow across industries and regions:
- Small Businesses: Reports of insufficient cyber-resilience among small organisations have surged sevenfold since 2022, now standing at 35%.
- Regional Variations: Confidence in national preparedness for critical infrastructure attacks varies, with 15% in Europe and North America expressing doubts compared to 36% in Africa and 42% in Latin America.
- Public vs. Private Sectors: Public sector organisations are disproportionately affected, with 38% reporting inadequate resilience compared to just 10% of medium-to-large private organisations. Talent shortages further exacerbate this divide, affecting nearly half of public sector entities.
AI’s Transformative Potential in Cybersecurity
Generative AI is simultaneously a tool for defence and a weapon for cybercriminals:
- Social Engineering: Phishing and social engineering attacks increased in 2024, affecting 42% of organisations. GenAI enables criminals to scale and customise these attacks more effectively.
- Deepfake Threats: Advanced deepfake technology has seen a 223% rise in dark web trade, facilitating sophisticated impersonation scams.
- AI Security Gaps: Smaller organisations are particularly vulnerable, with 69% lacking safeguards for AI deployment, perpetuating inequities in cybersecurity readiness.
Ransomware and Cyber-crime Escalation
Ransomware remains the leading cyber-threat, with 45% of respondents ranking it as their top concern. The rise of Ransomware-as-a-Service (RaaS) has democratised access to ransomware tools, increasing attack frequency and sophistication.
Cyber-enabled fraud follows as the second-most critical threat, with organised crime groups leveraging digital tools to target critical infrastructure and social services. According to the report, scam operations based in Southeast Asia have contributed to global losses exceeding $1 trillion in 2024.
The Skills Gap: A Persistent Challenge
The cybersecurity workforce shortage grew by 8% in 2024, leaving two-thirds of organisations struggling to meet staffing needs. Public sector entities face the most acute challenges, with nearly half citing talent shortages as a critical barrier to resilience.
Navigating Regulatory Hurdles
While regulations play a vital role in enhancing cyber-resilience, their fragmented nature creates challenges:
- Compliance Burdens: Organisations face mounting costs and complexities in navigating disparate regulatory frameworks.
- Building Trust: Harmonised standards are essential to reduce compliance burdens and improve global cybersecurity collaboration.
Strategies for Strengthening Cyber-resilience
Organisations must adopt holistic approaches to address evolving risks:
- Expand Risk Management: Treat cybersecurity as a core business risk, not just an IT issue.
- Improve Supply Chain Oversight: Collaborate with suppliers to enhance security visibility and resilience.
- Close Talent Gaps: Invest in workforce training, retention, and development.
- Secure AI Deployment: Implement robust safeguards to protect against AI-driven vulnerabilities.
- Streamline Regulations: Policymakers and industry leaders should prioritise harmonised standards to ease compliance challenges.
Quantum Computing | A Double-Edged Sword
Quantum computing is poised to revolutionise industries with unprecedented computational power, unlocking significant economic and scientific opportunities.
However, this potentially transformative technology also presents pressing cybersecurity challenges, particularly its potential to break public-key encryption – an essential mechanism for securing online banking, government communications, and other digital systems.
While the timeline for realising quantum computing’s full potential remains uncertain, the risks it introduces to cybersecurity are already reshaping organisational strategies.
The report found that 40% of organisations reported proactively assessing quantum threats. A major concern is the “Harvest Now, Decrypt Later” tactic, where malicious actors collect encrypted data today, aiming to decrypt it when quantum capabilities mature.
Despite such threats, many organisations await clearer guidelines and standards from governments and industry bodies.
However, efforts to mitigate quantum risks are underway. The G7 Cyber Expert Group has provided actionable recommendations for governments and central banks.
Meanwhile, the National Institute of Standards and Technology (NIST) has released post-quantum cryptography (PQC) standards, complemented by emerging technologies like quantum key distribution (QKD) and quantum random number generation (QRNG).
Cloud Risks and Supply Chain Vulnerabilities in the Cybersecurity Ecosystem
Interconnected supply chains and the growing reliance on cloud technologies continue to complicate the cybersecurity landscape.
In the WEF’s Cybersecurity Outlook, they identified supply chain vulnerabilities as a primary contributor to cyber-risks. The adoption of cloud services, while offering enhanced security and cost efficiency, introduces unique challenges, such as limited control over configurations and concentrated risk.
A ransomware attack on a major cloud provider, for instance, could paralyse thousands of dependent businesses overnight.
To address these risks, some organisations are strengthening end-to-end supply chain oversight and enforcing secure software development practices.
Regulatory measures, such as the EU Cyber Resilience Act and the NIS2 Directive, aim to enhance cybersecurity standards across supply chains, requiring stricter incident reporting and accountability. However, navigating overlapping regulations and fragmented compliance requirements adds complexity for businesses.
Geopolitical Tensions and the Expanding Cyber Regulatory Landscape
Geopolitical tensions are increasingly influencing organisational cyber-strategies.
According to the report, nearly 60% of respondents acknowledged the impact of geopolitical risks, with some halting operations in certain regions or modifying vendor relationships.
Recommended reading
- Grappling with Cyber Vulnerabilities Despite Legislative Efforts
- IT and Security Leaders Admit Hardware Cybersecurity Gap
- Comment | Get Ready For New Cybersecurity Legislation on Connected Devices
Regulations, including the EU’s Digital Operational Resilience Act (DORA) and the United States’ Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), are driving improvements in cyber-resilience. However, the proliferation of global cyber regulations has also introduced challenges, with 69% of organisations citing complexity and regulatory fatigue as barriers to compliance.
Bridging the Cyber Skills Gap
The cybersecurity sector faces a critical workforce shortage, with an estimated gap of 2.8-4.8 million professionals.
Skills in AI and its application in cybersecurity are increasingly vital, yet 67% of organisations report insufficient investment in AI training.
As such, we must address the widening skills gap by integrating AI capabilities and updating education and training to reflect this nascent threat.
Retention is another pressing issue. Nearly half of cyber-leaders are expected to change roles by 2025, with burnout cited as a key driver. According to the report, to combat this, companies must prioritise workforce well-being and create pathways for non-traditional talent, such as professionals from law, finance, and communications, who can bridge technical and business perspectives.
Speaking in the report’s foreword, Jeremy Jurgens managing director at the World Economic Forum, said: “Following decades of relative stability, the world today is marked by increased geopolitical conflicts.
The fallout of this turbulence in the digital realm – the growing prowess of cyber-criminals, rapid advances in emerging technologies and widening cyber capabilities – have led to a cyberspace that is more complex than ever before.”





