Cybersecurity Predictions and Trends to Watch in 2025

By GTIA

Jan 15, 2025

Share this post

From large-scale ransomware attacks to IT outages to cybercriminal arrests, 2024 was a busy year in cybersecurity. And it’s not likely to slow down or get any easier in 2025. We asked a number of cybersecurity thought leaders for their predictions and trends to watch for the next 12 months. Here’s what they had to say.

MSPs to Face More Legal Action

“My prediction for 2025 is that we will see a surge in legal actions taken against managed service providers by their clients for cyberattacks. I believe that MSPs have received a pass for mistakes related to backups, account security, vulnerability management and configuration management over the last 5+ years. I believe attorneys and insurance carriers are starting to notice more and more and 2025 seems like a good year for the lawsuits to ramp up.” – Chris Loehr, executive vice president and CTO, Solis Security

AI Will Be a Valuable Weapon—for Both Sides

“In 2025, we will witness an unprecedented level of cyber sophistication. Attacks will be more targeted and sophisticated, with cybercriminals leveraging AI, machine learning and automation to outmaneuver traditional defenses. AI will be a double-edged sword; while attackers harness it to identify vulnerabilities and evade detection, defenders will use AI to enhance cybersecurity measures, enabling quicker threat detection and response. Additionally, the collaboration between public and private sectors will be pivotal. Governments, organizations, and security experts will join forces, sharing information and resources to collectively combat cyber threats, making cyberspace safer for everyone.” – Tanja Omeragic, director of technical sales, ConnectWise

Ransomware Becomes a ‘Crime-as-a-Service’

“While I think the above-board reduction may come, I see ransomware growing as ‘crime-as-a-service’ continues to simplify the requirements to get into cyber attacks for profit. There is far too much money to be made with far too little risk of ramifications. A couple hundred million U.S. dollars in the bank for a few potential years in jail (odds are almost zero) is a trade many will make.” – Kevin McDonald, COO and CISO at Alvaka Networks

Robotics Need to Be Better Secured

“Robotics will become a major source of cybersecurity weakness and potential kinetic risks not seen in recent years. The more we inject and allow for robotic animated devices to act autonomously and remotely, the more we will see attempts to subjugate them and uses of them as proxy bad actors.” – Kevin McDonald, COO and CISO at Alvaka Networks

Escalation of U.S. Intervention

“I believe that collaboration with and even international capitulation to U.S. requests for intervention will grow under the new administration. Tolerance for nation state sponsored and government tolerated attacks will drop some. The willingness to cross lines by U.S. and Western allies to just take out threat actors and their infrastructure in unattributed takedowns is likely to increase exponentially. While law enforcement has been busy, many foreign governments have been overtly thumbing their nose at U.S. and Five Eyes nations’ complaints and have even supported their citizens attacking U.S. interests. This is both profitable and supports the goals of weakening U.S. interests, costs billions of dollars that could otherwise be spent on positive improvements and of course just disrupts our lives.” – Kevin McDonald, COO and CISO at Alvaka Networks

MSP Focus Turns to Internal Security, Supply Chains at Risk

“First, breached clients suing MSPs and cyber insurance requirements on the rise will force MSPs to focus on their own security and providing preventative security (left of boom) to clients. Second, threat actors will focus more on supply chain since they hold data and access to many client environments. Third, deepfakes and other AI supported attacks will continue to rise as AI is tuned into stronger weapons.  Vendors will need to create ways to identify and stop these updated attacks.” – Nett Lynch, CISO at KraftKennedy

Cyber Insurance Will Play Pivotal Role Helping Clients

“As cyber insurance premiums rise and policies demand stricter compliance, MSPs can play a pivotal role in helping clients meet underwriting requirements. This includes demonstrating compliance, mitigating risks, and ensuring clients are prepared for policy renewals.” – Tim Golden, CEO at Compliance Scorecard

Increased Focus on Privacy by Design

“With regulations like GDPR and anticipated updates in privacy laws worldwide, MSPs must help clients embed privacy by design principles into their operations. This includes conducting privacy impact assessments, integrating privacy into software development and aligning with frameworks like ISO 27701.” – Tim Golden, CEO at Compliance Scorecard

Intensified Regulatory Enforcement and Fines
“Regulatory bodies are expected to increase enforcement of cybersecurity laws, such as CMMC and FTC 3.14, with a focus on stricter audits and leveraging mechanisms like whistleblowing. This will intensify scrutiny on compliance practices across the board. MSPs will face heightened risk of fines and legal actions if they fail to meet these regulatory demands, making proactive compliance a business-critical priority.” – Tim Golden, CEO at Compliance Scorecard

Harder Line Against International Threat Actors

“Russia recently sentenced four cybercriminals who worked for a notorious ransomware-as-a-service group called Revil to significant jail terms. It seems that Russia has drawn a rather hard line between some cybercriminals and others. The potential of blending nation-state threat actors with cybercriminals could have dire consequences for Chinese, Russian, Iran and North Korean (CRINK) actors. Moving away from the due process of the American justice system when it comes to supporting cybercrime indictments, countering these actors and making these cyberattacks a counter-intelligence opportunity would give the Americans a much heavier and aggressive hand to remove cybercriminals and their capability – perhaps even on a permanent basis. The broad strokes of this evolving trend are if America begins to regard ransomware as a form of terrorism sponsored by a state (or non-state actors), then America’s counter-terrorism gloves may come off to spectacularly deal with and put a stop to this trend.” – Ian Thornton-Trump, CISO at Inversion 6 UK

Follow GTIA on LinkedIn. #WeAreGTIA

Related Posts:

By Ashley Watters / Aug 19, 2025

Getting the GTIA Cybersecurity Trustmark (Part 3): Advice from Assured Members

Is the GTIA Cybersecurity Trustmark worth the investment in time, resources and money? Absolutely, according to IT service providers (ITSPs) who have achieved Assured status and elevated their cybersecurity policies and processes along the way.
Group of professionals working together
By Ashley Watters / Sep 26, 2025

Getting the GTIA Cybersecurity Trustmark (Part 4): How to Obtain Employee Buy-In

Providing critical services to companies and supporting organizations with their technology needs is no easy lift and IT service providers (ITSPs) are the support services that keep companies operational. Consequently, ITSP employees often have their hands full keeping up with client demands and responsibilities, leaving little time to work on business-building projects such as the GTIA Cybersecurity Trustmark.