From large-scale ransomware attacks to IT outages to cybercriminal arrests, 2024 was a busy year in cybersecurity. And it’s not likely to slow down or get any easier in 2025. We asked a number of cybersecurity thought leaders for their predictions and trends to watch for the next 12 months. Here’s what they had to say.
MSPs to Face More Legal Action
“My prediction for 2025 is that we will see a surge in legal actions taken against managed service providers by their clients for cyberattacks. I believe that MSPs have received a pass for mistakes related to backups, account security, vulnerability management and configuration management over the last 5+ years. I believe attorneys and insurance carriers are starting to notice more and more and 2025 seems like a good year for the lawsuits to ramp up.” – Chris Loehr, executive vice president and CTO, Solis Security
AI Will Be a Valuable Weapon—for Both Sides
“In 2025, we will witness an unprecedented level of cyber sophistication. Attacks will be more targeted and sophisticated, with cybercriminals leveraging AI, machine learning and automation to outmaneuver traditional defenses. AI will be a double-edged sword; while attackers harness it to identify vulnerabilities and evade detection, defenders will use AI to enhance cybersecurity measures, enabling quicker threat detection and response. Additionally, the collaboration between public and private sectors will be pivotal. Governments, organizations, and security experts will join forces, sharing information and resources to collectively combat cyber threats, making cyberspace safer for everyone.” – Tanja Omeragic, director of technical sales, ConnectWise
Ransomware Becomes a ‘Crime-as-a-Service’
“While I think the above-board reduction may come, I see ransomware growing as ‘crime-as-a-service’ continues to simplify the requirements to get into cyber attacks for profit. There is far too much money to be made with far too little risk of ramifications. A couple hundred million U.S. dollars in the bank for a few potential years in jail (odds are almost zero) is a trade many will make.” – Kevin McDonald, COO and CISO at Alvaka Networks
Robotics Need to Be Better Secured
“Robotics will become a major source of cybersecurity weakness and potential kinetic risks not seen in recent years. The more we inject and allow for robotic animated devices to act autonomously and remotely, the more we will see attempts to subjugate them and uses of them as proxy bad actors.” – Kevin McDonald, COO and CISO at Alvaka Networks
Escalation of U.S. Intervention
“I believe that collaboration with and even international capitulation to U.S. requests for intervention will grow under the new administration. Tolerance for nation state sponsored and government tolerated attacks will drop some. The willingness to cross lines by U.S. and Western allies to just take out threat actors and their infrastructure in unattributed takedowns is likely to increase exponentially. While law enforcement has been busy, many foreign governments have been overtly thumbing their nose at U.S. and Five Eyes nations’ complaints and have even supported their citizens attacking U.S. interests. This is both profitable and supports the goals of weakening U.S. interests, costs billions of dollars that could otherwise be spent on positive improvements and of course just disrupts our lives.” – Kevin McDonald, COO and CISO at Alvaka Networks
MSP Focus Turns to Internal Security, Supply Chains at Risk
“First, breached clients suing MSPs and cyber insurance requirements on the rise will force MSPs to focus on their own security and providing preventative security (left of boom) to clients. Second, threat actors will focus more on supply chain since they hold data and access to many client environments. Third, deepfakes and other AI supported attacks will continue to rise as AI is tuned into stronger weapons. Vendors will need to create ways to identify and stop these updated attacks.” – Nett Lynch, CISO at KraftKennedy
Cyber Insurance Will Play Pivotal Role Helping Clients
“As cyber insurance premiums rise and policies demand stricter compliance, MSPs can play a pivotal role in helping clients meet underwriting requirements. This includes demonstrating compliance, mitigating risks, and ensuring clients are prepared for policy renewals.” – Tim Golden, CEO at Compliance Scorecard
Increased Focus on Privacy by Design
“With regulations like GDPR and anticipated updates in privacy laws worldwide, MSPs must help clients embed privacy by design principles into their operations. This includes conducting privacy impact assessments, integrating privacy into software development and aligning with frameworks like ISO 27701.” – Tim Golden, CEO at Compliance Scorecard
Intensified Regulatory Enforcement and Fines
“Regulatory bodies are expected to increase enforcement of cybersecurity laws, such as CMMC and FTC 3.14, with a focus on stricter audits and leveraging mechanisms like whistleblowing. This will intensify scrutiny on compliance practices across the board. MSPs will face heightened risk of fines and legal actions if they fail to meet these regulatory demands, making proactive compliance a business-critical priority.” – Tim Golden, CEO at Compliance Scorecard
Harder Line Against International Threat Actors
“Russia recently sentenced four cybercriminals who worked for a notorious ransomware-as-a-service group called Revil to significant jail terms. It seems that Russia has drawn a rather hard line between some cybercriminals and others. The potential of blending nation-state threat actors with cybercriminals could have dire consequences for Chinese, Russian, Iran and North Korean (CRINK) actors. Moving away from the due process of the American justice system when it comes to supporting cybercrime indictments, countering these actors and making these cyberattacks a counter-intelligence opportunity would give the Americans a much heavier and aggressive hand to remove cybercriminals and their capability – perhaps even on a permanent basis. The broad strokes of this evolving trend are if America begins to regard ransomware as a form of terrorism sponsored by a state (or non-state actors), then America’s counter-terrorism gloves may come off to spectacularly deal with and put a stop to this trend.” – Ian Thornton-Trump, CISO at Inversion 6 UK
Follow GTIA on LinkedIn. #WeAreGTIA

