Recent high-profile breaches at Marks & Spencer and Co-op are keeping ransomware in the back of people's minds in the UK (unless you're a cyber security professional, in which case it's very much front of mind!). These incidents, however, shouldn't come as a surprise. The NCSC says that ransomware is the most pervasive cyber threat facing the UK and it's leaving a trail of not just financial losses but also very real human impacts.
How should we be preparing for 2025 and beyond?
I've been reading through threat intelligence reports — from Mandiant and Verizon to CrowdStrike, IBM, and Microsoft — to understand what the data says about the threats that we face and what we should be doing about it.
The case for a threat-led approach in 2025
A threat-led security strategy isn't about checking boxes; it's about aligning your defences with the actual tactics, techniques, and procedures (TTPs) of the adversaries most likely to target your organisation.
Generic defences get circumvented. A threat-led approach means:
Focusing your firepower: directing security investments where they will have the greatest impact against the most significant dangers.
Building true resilience: directly contributing to business resilience by protecting your organisation's "crown jewels".
Meeting evolving demands: addressing the growing global regulatory pressure for a demonstrable, risk-informed security posture.
PwC's latest reports show that while cyber security is a top compliance priority for many, only 2% have implemented firm-wide cyber resilience actions despite many anticipating that their budgets will increase. There is a gap between what firms say about cyber security and what they do, and a threat-led strategy closes it by pointing effort at the attacks that are actually happening.
What the data says about 2025
The figures vary between reports, but the same themes keep coming up.
N.B. The reports examined for this article in some cases include data going back to 2023.
1. The identity crisis: your digital front door
Stolen credentials and compromised identities are not just a vulnerability; they are a dominant initial infection vector and a primary method for lateral movement within networks. Reports highlight that a significant percentage of initial access involves valid credentials, and identity-based attacks number in the hundreds of millions daily. Attackers are actively finding ways to bypass multi-factor authentication (MFA).
So what? Focus on Identity and Access Management (IAM). Prioritise widespread adoption of phishing-resistant MFA (think passkeys, FIDO2), implement proper Privileged Access Management (PAM), and embed Zero Trust principles across all environments. Fast response to identity-related threats is no longer optional.
2. Vulnerabilities: the evergreen gateway
Exploitation of known vulnerabilities — whether in internet-facing systems, cloud configurations, or Operational Technology (OT) and edge devices — remains a top entry point for attackers.
So what? Implement Threat-Led Vulnerability Management (TLVM) and Attack Surface Management (ASM). This means prioritising patching not just on severity, but on active exploitation and business criticality. Consistent and timely patching across all systems, including OT where feasible, alongside secure configuration management, is what matters.
3. Expanding blast radius: third-party and supply chain risks
Your organisation's security is increasingly tied to that of your partners and suppliers. Breaches originating from compromised vendors, or vulnerabilities in software components (including open-source), are doubling in frequency and impact. Despite this, many organisations still conduct minimal reviews of their immediate supplier risks.
So what? Elevate third-party and supply chain risk to a core business concern. Mandate continuous vendor risk management. Embed cybersecurity requirements directly into contracts and procurement processes. Build secure software and actively prepare for hardware supply chain risks.
4. AI cuts both ways
Generative AI is already being weaponised by adversaries for more sophisticated phishing, fraud, malware development, and influence operations, significantly expanding attack surfaces. Simultaneously, organisations are investing heavily in AI for defensive capabilities. Interestingly, early in 2024, NCSC made predictions about GenAI in the short term being a vector to amplify existing threats before then creating new attack surfaces and new threat vectors. More than a year later, I think they got it about right.
So what? Invest in detection for AI-driven attacks. Establish AI governance for both offensive and defensive use cases. Adopt AI-powered security tools where they improve SOC efficiency, threat hunting and predictive analysis, and promote AI literacy and awareness of AI-generated deceptive content (deepfakes, sophisticated phishing) across your organisation.
5. Ransomware is persistent yet evolving
While some reports suggest that the volume of successful ransomware attacks against enterprises is stabilising, the overall threat activity and initial compromises related to ransomware remain extremely high and are potentially increasing in terms of encounters. The methods of extortion are also evolving, moving beyond just encryption to data theft, DDoS attacks, and victim harassment.
So what? Preparation is what counts. Think immutable and well-isolated backups, comprehensive and regularly tested incident response (IR) plans, and a clear understanding of evolving extortion methods. Focus on building the resilience to not just recover from an attack, but to withstand its full impact.
6. Humans are still the first line of defence
As technological defences improve, humans remain a primary target. Phishing continues to be the dominant method for initial access, and social engineering plays a significant role in a vast majority of breaches.
So what? Invest in continuous, adaptive security awareness training. Conduct realistic phishing simulations — including those leveraging AI-generated lures and deepfake awareness. Foster a strong, blame-free security culture where reporting suspicious activity is encouraged and rewarded. Moreover, security awareness training should aim to promote good behaviour; reducing false or benign security alerts, allowing your security operations centre to focus on genuine threats.
A roadmap for 2025: five priorities
Here are the five priorities I took away.
Strengthen your digital identities. Attackers are going after credentials. This means urgent action on phishing-resistant MFA (think passkeys!), robust Privileged Access Management (PAM), and embedding Zero Trust principles deeply across your organisation. The goal: make stolen credentials obsolete as an attack vector.
Build proactive, threat-led vulnerability and exposure management capabilities. Move beyond basic patching. Implement Threat-Led Vulnerability Management (TLVM) and Attack Surface Management (ASM) to continuously identify and remediate the vulnerabilities that attackers are actively exploiting. This includes your critical OT environments and cloud configurations. Those with a military background will have heard of the OODA loop (Observe, Orient, Decide, Act). The theory is that the quicker you can get around that loop, the bigger your advantage on the battlefield. Crucially, you need to be getting around the OODA loop quicker than your adversaries. This is becoming increasingly relevant in the world of cyber security.
Elevate third-party/supply chain risk to a core business risk. Your security is only as strong as your weakest link. Mandate continuous vendor risk management. Embed cybersecurity requirements directly into contracts and procurement processes. Demand transparency through Software Bills of Materials (SBOMs) and prepare for risks throughout your software and hardware supply chains.
Prepare for AI-driven threats and use AI for defence. AI is already helping attackers run more sophisticated and widespread attacks. Invest in capabilities to detect them, establish AI governance, and adopt AI-powered security tools where they improve your defences. Promote AI literacy across your workforce.
Reinforce board-level cyber governance and CISO empowerment. None of this works without top-down commitment. Ensure clear board accountability for cyber risk, with regular and informed oversight. Integrate CISOs into strategic business planning and decision-making processes, and empower NEDs to actively probe and challenge the organisation's cyber posture and resilience measures. This isn't about compliance; it's about building holistic, firm-wide cyber resilience.
Summary: the evidence behind each priority
The table below pulls together the key data points from the reports that support each of the five priorities.
| Strategic priority | Key actions for boards / CIOs / NEDs | Supporting evidence (key reports and findings) |
|---|---|---|
| 1. Strengthen your digital identities | Prioritise phishing-resistant MFA, PAM, Zero Trust principles, continuous identity monitoring. | Mandiant (stolen credentials 16% of initial access), CrowdStrike (79% of initial access attacks malware-free), IBM (30% of intrusions involve valid credentials), Microsoft (over 600M identity attacks daily; focus on MFA bypass), ENISA (identity compromise key). |
| 2. Build proactive, threat-led vulnerability and exposure management capabilities | Implement TLVM, ASM, timely patching (including OT), secure configuration management. | Mandiant (exploits #1 initial infection vector at 33%), Verizon DBIR (34% surge in vulnerability exploitation), ENISA (exploitation of vulns prime initial access; OT security gaps), Microsoft (unmanaged devices key ransomware risk). |
| 3. Elevate third-party / supply chain risk to a core business risk | Mandate comprehensive, continuous vendor risk management; embed cyber requirements in contracts; manage software supply chain risk. | Verizon DBIR (third-party involvement in breaches doubled to 30%), PwC (35% of leaders rank as high concern), UK Gov Survey (only 14% of businesses review immediate supplier cyber risks), ENISA (supply chain attacks critical), Microsoft (nation-states target supply chains). |
| 4. Prepare for AI-driven threats and use AI for defence | Invest in AI-attack detection, AI governance, AI-powered security tools, AI literacy. | CrowdStrike (GenAI driving significant increase in vishing), IBM (attackers using AI for phishing), PwC (67% of security leaders state GenAI has increased attack surface), Microsoft (attackers use AI for phishing, fraud; AI enhances SOC), ENISA (AI for influence ops, malware). |
| 5. Reinforce board-level cyber governance and CISO empowerment | Ensure clear board accountability; integrate CISOs into strategy; NEDs to probe cyber posture; build firm-wide resilience. | UK Gov Survey (board-level cyber responsibility down), PwC (only 2% firm-wide resilience; CISOs not key in business), ENISA (complexity challenges governance), Microsoft (need for top-down accountability; few orgs have robust resilience). |
What have I missed?
The main downside to basing a security strategy on threat intelligence in the way laid out in this post is that looming threats that have not yet materialised are missed. An example being quantum computing and the need for post-quantum cryptography — something I have written about previously.
Is there anything else that gets missed? I'd love to hear your thoughts.
References
- CrowdStrike (2025). 2025 Global Threat Report.
- ENISA (2024). ENISA Threat Landscape 2024.
- GOV.UK (2025). Cyber Security Breaches Survey 2025.
- IBM (2025). X-Force Threat Intelligence Index 2025.
- Mandiant, Google Cloud (2025). M-Trends 2025 Report.
- Microsoft (2024). Microsoft Digital Defense Report 2024.
- PwC (2025). Global Digital Trust Insights 2025.
- PwC (2025). Global Compliance Survey 2025.
- Verizon (2025). Data Breach Investigations Report (DBIR).
