Categories
Top 5 challenges for the cybersecurity specialist
In 2025, Information Security department employee will certainly not be out of work: new threats are emerging, attacks on businesses are intensifying, the digital hunt for data is on. Information is now as much an asset as tangible valuables and has become just as coveted. And there is only one barrier between a hacker and a company – a cybersecurity specialist. What are the most pressing issues? What gives a cybersecurity specialist nightmares? Let's talk about it in our article today.
Some statistics
In 2025, cumulative data of all mankind will reach the huge figure of 175 zettabytes (which means that after the figure 175 you have to add another 21 zeros!). This is historic high and huge field of activity for fraudsters. In 2023, damage from cybercrime worldwide reached $8 trillion, and by 2025 it could reach $10.5 trillion.
The number of cyberattacks on businesses, consumers and governments is difficult to estimate because not all incidents are reported. Experts have come to the conclusion that approximately every 39 seconds there is the cyberattack in the world. And by 2031, this figure will increase even more: approximately every 2 seconds.

In short – there will always be jobs in cybersecurity.
Top 5 problems
Software Supply Chain Attacks
Perhaps no cybersecurity trend over the past few years has been more serious than the wave of Software Supply Chain Attacks. How it works. Fraudsters gain access to the system not directly, but through an attack on the supplier of the software product that an organisation uses. This can be done through compromising software updates, forging certificates to sign code, inserting malware particles into software, connecting to pre-installed malware on devices and so on. The most famous case in the open source world in recent years: hack of software vendor SolarWinds, which allowed fraudsters to infiltrate hundreds of companies in the US and gain access to 4/5 of the wealthiest Fortune 500 companies, including Apple, Walmart, Amazon and others.
Experts predict that the situation will only get more complex and by 2025, 45% of global organisations will be affected by supply chain attacks in one way or another.
What can a cybersecurity specialist do against such attacks?
Various ways of coping are used:
- implementation of word-anchors to detect fraudsters, so-called Honeytoken. In other words, it is fake confidential information that, when interacted with, alerts a specialist in OIB receives a warning about likelihood of an attack;
- implementing secure privileged access management, as accounts with this status are priority for fraudsters to attack;
- staff training on digital hygiene standards, countering phishing attacks, targeted social engineering, malware attacks, clickjacking and more;
- implement Zero Trust Architecture, which assumes that all network activity is malicious by default and that access to intellectual property is only allowed with strict selection through security policies;
- minimise access to data and conduct internal audits of employees and suppliers with access.
Generative AI
Another cybersecurity pain point is application of artificial intelligence, specifically Generative AI.
Generative AI or Generative Artificial Intelligence is a relatively new type of AI that enables the creation of new audio, video and photo content unlike anything else. Artificial Intelligence is in constant state of learning new things and can be applied to many industries, especially where content needs to be personalised, visualised and enhanced. Or create new content that promotes an idea, including fraudulent content. Already today, up to 53% of hackers use Generative Artificial Intelligence in their activities.
The increase in mentions of words "AI" and "GPT" on darknet forums in 2025 is also indicative of the increased AI-based threat. More than 800,000 posts with these words, indicating high interest in the topic, even considering that none of the cyber campaigns so far have been carried out entirely by AI. And the key word here is yet. It's important for a cybersecurity specialist to realise that drive to implement GenAI is currently outpacing the industry's ability to understand security risks these new capabilities will bring.
Plus, features of Generative AI have made it the world's best source of dipfakes, offering 100500 variations of deception if you want to. You can create a video, audio with any message from any known person or targeted acquaintance of the potential victim. For companies, you can imitate the orders of managers or responsible colleagues.
How do you combat Generative AI products? Firstly, use your due diligence. Not all AI-assisted content generation services create their product perfectly. You can tell by the lag or inconsistency of facial expressions, voice, gestures what is artificially done and what is natural.
Secondly, there are the sufficient number of paid and free services that perform automatic reconciliation of content and give an answer where artificial intelligence technologies were used and where they were not.
"The human factor"
Surprisingly enough, it is employees in a company that are one of the most dangerous threats to Information Security. Up to 70% of all information leaks are caused by employees intentionally or unintentionally leaking data. This can be a common mistake in online communications, planned insider activity to leak data, or "falling" for the phishing trick. It doesn't matter. There is threat and something needs to be done about it. We wrote more about insider trading in our previous article.
Ransomware
Ransomware is another nightmare for a security specialist, because basically, if it happens, there are only two options: pay up or hope for backup. Scammers of this type are particularly fond of demanding ransom for cryptocurrency information. All the more reason to go beyond the transparency of the Bitcoin (BTC) blockchain. Digital money offers several dozen anonymous currencies that cannot be traced at all by movements between owners (like Monero (XRP), Zcash (ZEC), Dash (DASH) and others, which helps hackers well and a cybersecurity specialist in no way.
IoT as security threat
The Internet of Things or IoT is not just the Amazon Echo in your home. The Internet of Things is much broader and includes smart door locks, smart security systems, clocks, smart fire alarms, virtual assistants and much more. What are the dangers of the internet of things? These objects too can act as targets for attack, especially if they are involved in mission-critical operations. According to the research, the top 3 threats from the IoT are distributed between: attacks on devices for critical operations (33%), lack of qualified personnel to ensure Information Security of Internet of Things (IoT) objects (32%), protection of confidential information on the Internet of Things (31%).
The headache for a cybersecurity specialist is then summed up in a simple example: the more IoT devices that appear in enterprise loop, the more security problems arise.
Of course, it is impossible to limit problems to just this list. We need to add DDoS attacks, social engineering, vulnerability of cloud services, phishing, malware and much more. The world is becoming more and more digitised and dependent on the Internet. And protection of all this data is vital, which is what the Information Security professional is committed to providing.
Protect your data with Anexet DLP system!
Don't let leaks jeopardise your reputation and business. Anexet DLP solution effectively prevents unauthorised access, controls the transfer of sensitive information and provides complete control over corporate data.
Ensure your company's security and privacy today!

















