Perspectives

Cybersecurity in 2025 and beyond

Seven Deloitte leaders share their forecasts

What obstacles and opportunities might be in store for your organization? These 2025 forecasts from leaders at the cyber front lines reveal a range of insights and strategies, from the rising threat of Initial Access Brokers to the increasing use of Generative Artificial Intelligence (GenAI) to improve cybersecurity programs.

  • Expand all
  • Collapse All

I expect the sophistication and intensity of cyber threats will continue to increase, as they have year over year. The ever-expanding tech landscape and rise of Adversarial AI, which powers more effective threats at scale, will further accentuate these challenges. Cyber AI will help to combat these trends, with the use of private Large Language Models (LLMs), more targeted Small Language Models (SLMs), and Agentic AI architectures expected to grow in their cybersecurity applications, essentially fighting fire with fire. Cyber as a Service (CaaS) enhanced by AI is expected to reach maturity, with increasing adoption by organizations looking for specialized expertise and cost-effective solutions. AI will help enhance CaaS threat detection, response, predictive analytics, and operational hygiene.

Kieran Norton, US Cyber AI & Automation Leader, Principal, Deloitte & Touche LLP

Organizations should stay ahead of cyber threats using advanced security technologies such as AI-driven threat detection and Zero Trust architectures, to help protect customer data and comply with regulatory standards. Employee, contractor, and other third-party training on the latest security practices will be crucial to mitigate risks associated with human error. Additionally, implementing dynamic consent management systems will empower customers to control their data, fostering transparency and trust. By prioritizing these elements, organizations can build stronger customer relationships and help ensure long-term success in an increasingly digital world.

Sharon Chand, US Cyber Cross-Business Integrations Leader, Principal, Deloitte & Touche LLP

GenAI and other forms of automation will transform traditional identity and access management (IAM) programs, enabling organizations to realize cost efficiency and capability advancements. Additionally, IAM is enabling the secure and effective use of GenAI across the organization. IAM helps address regulatory compliance, data security and privacy, and operational efficiency through role-based access control and strong authentication. Organizations can protect sensitive information by regularly reviewing access rights, defining clear access policies, and educating users.

Anthony Berg, US Cyber Identity Leader, Principal, Deloitte & Touche LLP

Trust-By-Design is an approach to embed safety, security, compliance, and resilience early in the product development process, rather than applied as an afterthought. By anticipating threats and safeguarding data, Trust-By-Design strengthens ethical integrity, trust, and resilience, particularly for AI applications increasingly being utilized by organizations. The approach helps AI systems better address organizational compliance with regulatory standards and withstand evolving risks, while protecting sensitive information.

Vikram Kunchala, US Cyber Platforms and Solutions Leader, Principal, Deloitte & Touche LLP

CISOs are increasingly getting a seat at the broader C-suite table, with more responsibility for organizational resilience. Current approaches to resilience are outdated and insufficient for the modern enterprise, with the greatest risk being stagnation. Convergence across domains is required to facilitate well-orchestrated response and recovery from high-impact events. Start by asking exploratory questions around readiness, prevention, monitoring, and response to those holding resilience roles to get a pulse check on current resilience capabilities. The next step is to align on an integrated governance and engagement model to connect capabilities into a holistic resilience program. To mitigate contemporary risks, what’s needed is a focus on strategically designing and positioning assets and information to improve capacity to withstand and recover quickly from disruptions.

Keri Calagna, US Crisis & Resilience Leader, Principal, Deloitte & Touche LLP

${column-img-description}

For the challenges you can’t predict and the opportunities you can’t pass up.

While the stakes are high for addressing the complex cyber and risk challenges of 2025 and beyond, Deloitte can help you meet your objectives, whether you need assistance with strategy, design, implementation, or ongoing operations. We offer a unified approach to help you tackle obstacles, build new capabilities, and move forward confidently—wherever you are on your journey.

Visit The Current and CISO Brief for timely insights.

Contact Us


Adnan Amjad
US Cyber Leader
Partner
aamjad@deloitte.com
+1 713 982 4825

Kieran Norton
US Cyber AI & Automation Leader
Principal
kinorton@deloitte.com
+1 415 783 5382

Sharon Chand
US Cyber Cross-Business Integrations Leader
Principal
shchand@deloitte.com
+1 773 294 6430

Anthony Berg
US Cyber Identity Leader
Principal
antberg@deloitte.com
+1 404 395 6340

Vikram Kunchala
US Cyber Platforms & Solutions Leader
Principal
vkunchala@deloitte.com
+1 713 982 2807

Keri Calagna
US Crisis & Resilience Leader
Principal
kcalagna@deloitte.com
+1 212 492 4461
Did you find this useful?