Top 5 Cybersecurity Challenges of 2025: Insights from SANS at RSAC Conference

Listen to this Post

Featured Image
As cyber threats continue to evolve, the landscape of cybersecurity challenges is expanding beyond technical concerns to address broader organizational and leadership issues. At the RSA Conference 2025, SANS Institute shared its top five cyber threats that businesses need to brace for in the coming year. These challenges not only emphasize the growing sophistication of cyberattacks but also highlight the need for coordinated responses at every level of an organization. In this article, we explore these key threats and analyze the implications for businesses in 2025.

The Top Cyber Threats Identified by SANS at RSAC 2025

The SANS

1. Authorization Sprawl in Cloud Environments

The first major cyber threat identified is what SANS faculty member Joshua Wright calls “authorization sprawl.” This issue arises particularly in cloud and Software-as-a-Service (SaaS) environments where users are granted excessive permissions. Attackers exploit these permissions by stealing authorized user credentials and gaining easy access to an organization’s network. One group utilizing this tactic effectively is Scattered Spider, which uses browsers to navigate undetected within cloud infrastructures. The solution lies in implementing browser endpoint controls, increasing visibility across cloud environments, and improving logging practices to ensure swift incident response.

2. ICS Ransomware Attacks

Ransomware attacks targeting critical infrastructure are becoming a severe concern. Tim Conway, technical director at SANS, warned that automation in Operational Technology (OT) environments is creating vulnerabilities that cybercriminals can exploit. The increased reliance on automation means that a single cyberattack could shut down vital services. To mitigate this, Conway advocates for closer coordination between IT and OT teams and the development of resilient systems capable of continuing operations even during a cyberattack.

3. Nation-State Attacks on ICS Systems

Nation-state actors, like those behind Volt Typhoon and Salt Typhoon, are increasingly targeting industrial control systems (ICS) with the intent to cause real-world disruption. Conway emphasized that organizations must move beyond traditional malware defenses and prepare for kinetic threats that could affect operations on a massive scale. Improving visibility into control systems and developing robust contingency plans are critical to defending against these advanced persistent threats.

4. Missing Forensic Data from Cloud Logs

Many organizations still fail to capture essential cloud logging data, leaving them in the dark when it comes to tracking and mitigating attacks. Heather Mahalik Barnhart of SANS highlighted that without these critical logs, organizations struggle to identify threats and build effective response strategies. The solution is to improve incident response maturity by ensuring systems are configured to capture high-fidelity data and by continuously training teams to work in data-constrained environments.

5. Regulatory Constraints on AI in Cybersecurity

While cybercriminals are leveraging AI to launch sophisticated attacks, defenders face significant regulatory hurdles. Privacy regulations like the GDPR prevent cybersecurity practitioners from using AI effectively across their organizations. SANS’ Rob T. Lee stressed the need for the cybersecurity industry to educate policymakers and regulators about the benefits of AI in defense, advocating for a balanced approach to AI governance that doesn’t hinder the ability to combat AI-driven threats.

What Undercode Says:

The cybersecurity landscape is at a critical juncture, where organizations must adopt a holistic approach to address the multi-faceted challenges of 2025. The increasing reliance on cloud services, automation in critical infrastructure, and the widespread use of AI in cyberattacks demand a more integrated and proactive response. Businesses need to recognize that cybersecurity isn’t just a technical problem; it’s a strategic issue that requires leadership at all levels.

One of the most significant takeaways from the SANS report is the growing complexity of cyberattacks, particularly in cloud environments and critical infrastructure. Authorization sprawl in cloud services and ICS ransomware attacks show that traditional methods of security are no longer sufficient. With the proliferation of cloud services, organizations are inadvertently opening doors to cybercriminals by granting users excessive permissions.

The risks associated with ICS ransomware attacks also underscore the need for cross-functional collaboration between IT and OT teams. Security breaches in industrial control systems can have real-world consequences, from power outages to disruptions in critical services, making this an urgent issue for organizations with industrial operations.

Regulatory constraints around AI use in cybersecurity also pose a significant challenge. While attackers freely leverage AI, defenders are constrained by privacy regulations that limit their ability to use AI effectively. This regulatory gap is a double-edged sword, as it prevents organizations from fully utilizing AI in defense while enabling adversaries to exploit it for cyberattacks.

The common theme across these threats is the need for businesses to adopt a comprehensive cybersecurity strategy that integrates technical, operational, and leadership components. As cyber threats become more complex, the response must be equally sophisticated, with a focus on visibility, agility, and cross-functional coordination.

Fact Checker Results:

  1. The threat of authorization sprawl in cloud environments is real and poses a significant risk to organizations. The solution suggested by SANS, such as improving visibility and deploying endpoint controls, aligns with industry best practices.
  2. Ransomware attacks on critical infrastructure are a growing concern. The recommendation for IT-OT collaboration is supported by numerous case studies of successful cybersecurity strategies.
  3. AI regulation in cybersecurity is a contentious issue. While regulations like GDPR pose challenges, there is growing advocacy for a more balanced approach to AI governance.

Prediction:

As we move into 2025, businesses must embrace a more agile and integrated approach to cybersecurity. The threats identified by SANS highlight the need for organizations to adopt cutting-edge technologies while overcoming regulatory constraints. Cloud environments will continue to be a major target for cybercriminals, and organizations will need to evolve their security strategies to keep pace with emerging threats. The rise of AI-driven attacks will push companies to rethink how they approach both security and compliance, leading to a shift toward more proactive defense measures.

References:

Reported By: www.darkreading.com
Extra Source Hub:
https://www.instagram.com
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram