1. AI-powered phishing and social engineering
AI is changing the cybercrime game. Attackers are now using AI to write personalised phishing emails and messages that mimic trusted contacts or executives. These hyper-targeted scams are difficult to detect and can trick even vigilant employees into sharing credentials or transferring funds.
The rise of groups like Scattered Spider, a collective of English-speaking hackers using social engineering and SIM swapping, has shown how effective these tactics can be. Recent attacks on major retailers, including Marks & Spencer and Adidas, have highlighted the devastating financial and reputational impact of such breaches.
Mitigation tips:
- Implement multi-factor authentication (MFA) across all systems.
- Regularly train staff to recognise phishing attempts and verify unusual requests.
- Deploy AI-based email filtering and behavioural analytics tools.
2. Supply chain attacks
As businesses increasingly rely on third-party vendors and cloud services, supply chain attacks have surged. Cybercriminals target less-secure partners to infiltrate larger organisations. The World Economic Forum reports that 45% of organisations expect to face significant cyber-attacks on their supply chains by this year; and this report was written months before the recent wave of high profile attacks.
3. Ransomware-as-a-Service (RaaS) and data extortion
Ransomware attacks have evolved into a service model, enabling even low-skilled hackers to launch devastating attacks. Groups like LockBit offer RaaS platforms, allowing affiliates to deploy ransomware and share in the profits.
These attacks often involve not just data encryption but also threats to leak sensitive information, increasing pressure on victims to pay ransoms.
Mitigation tips:
- Maintain regular, secure backups of critical data.
- Implement endpoint protection and intrusion detection systems.
- Develop and regularly update an incident response plan.
4. Deepfake technology
Deepfake audio and video are emerging as powerful tools for cybercriminals. These convincing forgeries can be used to impersonate executives, authorise fraudulent transactions or spread disinformation. According to Pinar Alpay, "three years ago, deepfake attacks were only 0.1% of all fraud attempts we detected, but today, they represent around 6.5%, or 1 in 15 cases. This represents an increase of 2137% in the last three years.”
As deepfake technology becomes more accessible, businesses must be vigilant against this sophisticated form of social engineering.
5. Insider threats and human error
Despite technological advancements, human error remains a leading cause of data breaches. Insider threats, whether malicious or accidental, pose significant risks. A large proportion of data breaches are due to human error. According to this article by InfoSecurity magazine, human error contributed to 95% of data breaches in 2024.
The M&S incident, where attackers deceived IT staff into resetting passwords, highlights the vulnerability of human factors in cybersecurity.
Mitigation tips:
- Implement strict access controls and the principle of least privilege.
- Conduct regular security awareness training for all employees.
- Monitor user activity for unusual behaviour.
6. Regulatory compliance: navigating new requirements
The UK's proposed Cyber Security and Resilience Bill aims to strengthen national cyber defences by expanding regulatory requirements for businesses. The legislation will introduce mandatory compliance with established cybersecurity standards and practices to ensure essential cyber safety measures are being implemented.
Organisations will need to demonstrate adherence to these standards through regular audits and reporting.
7. Cloud security challenges
The widespread adoption of cloud services introduces new cybersecurity challenges. Misconfigurations, weak credentials and lack of visibility can expose sensitive data to threats.
According to CrowdStrike’s 2024 Global Threat Report, a 75% increase in cloud intrusions was observed during 2023, mostly rooted in weak credentials and misconfigurations.
Mitigation tips:
- Implement strong authentication and encryption for cloud services.
- Regularly audit cloud configurations and access permissions.
- Use cloud security posture management tools to detect and remediate vulnerabilities.
Cyber threats in 2025 are more sophisticated and pervasive than ever.
By understanding these risks and implementing proactive measures, businesses can enhance their resilience and protect their assets. Investing in cybersecurity is not just a defensive strategy, it’s a commitment to the trust and confidence of customers and partners. One of the easiest and most proactive ways to achieve this is through training.
Final thoughts: How can businesses prepare for cyber threats in 2025?
Cyber threats in 2025 are more sophisticated and pervasive than ever. Only if businesses understand the exact nature and cause of certain risks can they be prepared to protect themselves.
Investing in cybersecurity is not just a defensive strategy, it’s a commitment to the trust and confidence of customers, investors and partners.
We support organisations with bespoke, benchmarked workforce upskilling across AI and data readiness, as well as a range of other areas, including:
- cyber awareness and resilience
- project delivery
- compliance and audit readiness
- leadership and management
- and much more
Our fully managed and structured learning and development programs empower your workforce to perform with high levels of confidence, judgement, and accountability.
Contact us today for a free consultation and team skills gap analysis.
—
Discover your team's training needs in a free 30 minute consultation
Find out how we can help
Talk to one of our dedicated learning and development account managers so we can understand more about your business
Read more about workforce upskilling
Closing the Skills GapUpskilling vs Hiring: The Real Cost of Closing a Technical Skills Gap in 2026
Hiring looks simple but rarely is the cheaper option. And I've done the hard work for you: compared the real costs of recruiting versus upskilling, explained why retention improves when you invest in your people, and shared four questions to help you choose the right path for your team's skills gap.
Read More
Closing the Skills GapHow to Build the Internal Business Case for a Workforce Upskilling Program
Winning budget for upskilling means proving it beats hiring on cost and speed, tying training to certification pathways, and measuring capability uplift - not course completions - against real business outcomes like reduced delivery delays, fewer audit findings, and better retention.
Read More
Closing the Skills GapBeyond Course Completion: How to Measure ROI in Learning and Development
Course completion rates prove content was consumed, not capability gained. This guide sets out a practical framework for measuring L&D ROI: benchmark skills before training, set role-based targets, validate with external certifications, and report progress to the managers accountable for results.
Read More
Cloud & MicrosoftMicrosoft Copilot Readiness: The Skills Your Team Needs First
Before rolling out Microsoft Copilot, teams need four capabilities: AI fluency and prompt skills for users, administration training such as AB-900 for deployment, security fundamentals like SC-900 to govern data access, and manager oversight to set usage standards. Together these prevent oversharing, wasted licences, and stalled adoption
Read More

