By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Cyber’s defining lessons of 2025, and what comes next | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Cyber’s defining lessons of 2025, and what comes next | Computer Weekly
News

Cyber’s defining lessons of 2025, and what comes next | Computer Weekly

News Room
Last updated: 2025/12/03 at 2:24 AM
News Room Published 3 December 2025
Share
Cyber’s defining lessons of 2025, and what comes next | Computer Weekly
SHARE

2025 was a wild ride for cyber security. The landscape is shifting faster than ever, and several themes stand out when I think about the most important cyber security lessons from the year.

Nation-state risk remains constant. In June, US authorities urgently warned companies to prepare for Iranian cyber attacks. This is just one example of the environment we’re in. Security teams must be ready to defend at a moment’s notice. Threats will mix disinformation and low-level disruption with more sophisticated tradecraft, all of which combined can have destructive consequences.

Human vulnerability is a favourite target of attackers. We continue to see this point proved by the cyber criminal group Scattered Spider, who focused on the insurance sector last June, using classic social engineering techniques to prove that humans are oftentimes the weakest link. If you’re relying only on technology, you’re missing the mark: attackers will always find a way in through people.

AI’s rise pressures us to modernise, but introduces new gaps.  Enterprise adoption of generative AI surged in 2025. Traffic to generative AI sites jumped by 50%, while 68% of employees used free-tier tools, and 57% admitted to pasting sensitive data into them. With this, it’s key to remember that AI-generated exploits and misinformation are already here. The security community needs to zero in on model manipulation techniques like prompt injection and proactively test these AI systems through the eyes of the attackers. Crowd-led testing remains one of our strongest defenses, even across new and evolving attack vectors. Diverse human researchers can catch what others miss.

Accountability is no longer optional. Governance is catching up. Take the Qantas incident as an example. After a breach exposed millions of customer records, the airline tied executive bonuses to cyber security outcomes. Docking CEO pay sends a clear message that the accountability for funding, prioritising, and evangelising security practices sits with the CEO and senior leadership team.

Critical infrastructure remains a soft target. Recent third-party attacks like the cyber disruption at European airports caused by a breach in check-in software last September remind us that the human impact of cyber risk can’t be abstract. Critical infrastructure is a soft target for cyber criminals. Disruptions to services leveraged by millions represent a growing threat. Zero trust and privileged access controls should be non-negotiable in all industries, but especially critical infrastructure, where their security stack is outdated or built on legacy systems.

In 2025, we found that the threats we face are more personal, more technical, more interconnected, and more tied to accountability. When I look forward and consider what 2026 has in store for all of us, I see six major trends emerging or continuing to grow.

  1. Attack sophistication and scale will continue to accelerate.

In 2026, the pace and sophistication of cyber attacks will reach levels that are increasingly difficult to anticipate. Organisations will be less focused on identifying whether attacks come from criminal groups or nation-state actors and more focused on how to respond effectively when an incident occurs.

  1. Critical infrastructure remains a prime target.

Attacks against critical infrastructure will remain a top concern. Hardware security, including IoT devices, pipelines, and water systems, will continue to be key risk areas, requiring organisations to prioritise protective measures across the evolving attack surface.

  1. Security controls must adapt to diversity of attacks.

The variety of attacks will keep expanding, and security teams will need to implement flexible, effective controls that balance access and protection. Ensuring that employees understand how to identify threats and escalate concerns will be critical to maintaining resilience in this complex landscape.

  1. AI confidence can mislead.

In 2026, AI-generated outputs will continue to present information confidently, even when incorrect. As organisations rely on AI for efficiency, reports on threats or incidents may be confidently wrong, creating noise that security teams must cut through to identify real risks.

  1. Human oversight remains critical.

The rise of AI-driven hallucinations, deepfakes, and lifelike synthetic media will make it harder for non-technical users to discern reality from AI-generated content. Organisations will need to foster a culture of human validation and critical thinking, ensuring that teams understand AI’s capabilities and limitations.

  1. Trust and verification will evolve.

With AI changing how information is created and shared, individuals and organisations will need new methods for verifying content. In 2026, security teams and broader stakeholders will face a culture and mindset shift: determining what to trust, what to validate, and how to respond responsibly to AI-driven outputs.

As defenders, we must embrace people-centric security, rigorously test with human insight, and demand leadership that treats cyber security as a business imperative.

Dave Gerry is CEO at crowdsourced cyber security platform Bugcrowd.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Best headphone deal: Save  on the Bose New QuietComfort Ultra headphones Best headphone deal: Save $50 on the Bose New QuietComfort Ultra headphones
Next Article Norton’s AI Web Browser Is Ready to Take on ChatGPT Atlas, Perplexity’s Comet Norton’s AI Web Browser Is Ready to Take on ChatGPT Atlas, Perplexity’s Comet
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Sam Altman issues ‘code red’ at OpenAI as ChatGPT contends with rivals
Sam Altman issues ‘code red’ at OpenAI as ChatGPT contends with rivals
Software
Best Home Theater Gifts for 2025
Best Home Theater Gifts for 2025
News
Second Major Android 16 Update Adds Expanded Parental Controls, AI-Condensed Notifications, More
Second Major Android 16 Update Adds Expanded Parental Controls, AI-Condensed Notifications, More
News
Apple Can’t Escape Dutch App Store Antitrust Lawsuit, EU Court Rules
Apple Can’t Escape Dutch App Store Antitrust Lawsuit, EU Court Rules
News

You Might also Like

Best Home Theater Gifts for 2025
News

Best Home Theater Gifts for 2025

1 Min Read
Second Major Android 16 Update Adds Expanded Parental Controls, AI-Condensed Notifications, More
News

Second Major Android 16 Update Adds Expanded Parental Controls, AI-Condensed Notifications, More

7 Min Read
Apple Can’t Escape Dutch App Store Antitrust Lawsuit, EU Court Rules
News

Apple Can’t Escape Dutch App Store Antitrust Lawsuit, EU Court Rules

3 Min Read
Galaxy Z TriFold: Specs, features, price
News

Galaxy Z TriFold: Specs, features, price

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?