Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationcybercrime-service-ecosystemai-enabled-threat-activityphishing-campaign-intelligence

Evolving Cybersecurity Threats and Organizational Preparedness in 2025

Updated 2mo agoFirst seen Oct 7, 20255 sources

Geopolitical instability, rapid technological advancement, and persistent skills shortages are fundamentally reshaping the cybersecurity landscape for organizations worldwide. According to a PwC report, 60% of executives now rank cyber risk investment among their top three strategic priorities, driven by concerns over political instability, trade disputes, and shifting alliances. Despite this heightened awareness, only about half of surveyed organizations feel very capable of withstanding cyberattacks on common vulnerabilities, and a mere 6% report preparedness across all vulnerabilities, highlighting significant exposure through legacy systems and complex supply chains. The financial impact of breaches remains severe, with over a quarter of respondents experiencing incidents costing at least $1 million in the past three years, disproportionately affecting large enterprises and technology-driven sectors. Spending on cybersecurity is increasing, with 78% of organizations expecting budget growth, yet only 24% are channeling more resources into proactive measures such as monitoring, testing, and training, indicating a continued reactive posture. The ENISA Threat Landscape 2025 report underscores the professionalization of cybercrime, the convergence of criminal and state-aligned actors, and the rise of hacktivist groups leveraging ransomware for both ideological and financial gain. Ransomware remains the most disruptive threat across the EU, with groups adopting decentralized operations, double- and triple-extortion tactics, and exploiting regulatory compliance fears to pressure victims. The proliferation of Ransomware-as-a-Service (RaaS), public leaks of builder tools, and the emergence of access brokers have lowered barriers to entry, fueling a diverse and persistent threat ecosystem. Weak authentication practices persist in many organizations, with passwords and SMS codes still dominant despite their vulnerability to phishing and credential theft. A significant portion of employees have never received cybersecurity training, and outdated policies further exacerbate risk, as personal and professional security habits often overlap, creating additional attack vectors. The adoption of stronger authentication methods, such as device-bound passkeys, remains limited, and resistance to multi-factor authentication is common due to perceived complexity. The use of AI in both attack and defense is accelerating, with AI-generated phishing campaigns and adaptive malware becoming more prevalent, while defenders also leverage AI for predictive threat detection. The overall picture is one of rising threat sophistication, uneven organizational preparedness, and a pressing need for sustained investment in proactive security measures, workforce training, and the adoption of advanced technologies to build resilience against an increasingly complex cyber threat landscape.

Share:
Evolving Cybersecurity Threats and Organizational Preparedness in 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 13, 20262mo ago

PwC reports U.S. firms see cyber risk outpacing response capability

PwC published findings from a March survey of more than 600 U.S. executives showing cybersecurity had become one of the top business risks shaping corporate strategy, while only a small minority felt their organizations could manage that risk effectively. The report also highlighted increased technology and AI spending since January 2025 and growing concern over cyberattacks and regulatory uncertainty.

PwC: Cybersecurity Risk Outpaces Corporate Ability to Manage
Oct 7, 20259mo ago

PwC releases Global Cyber Risk Trends 2026 report

PwC published a new report describing how AI, quantum computing, geopolitics, legacy systems, supply chain exposure, and skills shortages are shaping cybersecurity strategy. The report says many organizations are increasing cyber investment but remain underprepared, with spending still largely reactive.

Oct 6, 20259mo ago

Help Net Security highlights persistent weak authentication practices

Help Net Security published coverage on the ongoing risks posed by outdated authentication habits in organizations, indicating continued concern over weak authentication practices. No earlier event date is provided beyond the article's publication date.

ENISA publishes Threat Landscape 2025 report

ENISA released its Threat Landscape 2025 report, outlining major cybersecurity trends and threats observed across the European threat environment. The report was discussed in media coverage published on 2025-10-06.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Organizations
2 linked
PricewaterhouseCoopersIndustrial Cyber
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Evolving Cybersecurity Threats and Organizational Preparedness in 2025 | Mallory