Episode 145: 2025 Cybersecurity Predictions H2 Review — Pt 1
In episode 145 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager begin their mid-year review of 12 Center for Internet Security® (CIS®) experts' cybersecurity predictions for 2025.
Here are some highlights from our episode:
- 01:14. Verizon's Data Breach Investigations Report as a source of enlightenment and humility
- 02:28. The use of generative artificial intelligence (GenAI) to finely tune phishing emails
- 06:31. Cyber threat actors' Darwinian efficiency in adopting new technology
- 07:50. Policies, oversight, and compliance in slowing defenders' adoption of technology
- 10:30. The two-sided, dynamic challenge of managing supply chain risk
- 18:23. Cybersecurity as a strategic business investment in protecting revenue
- 20:40. The value of partnerships in determining rational social expectations for cybersecurity
- 26:45. Rapid recap of several of our 2025 cybersecurity predictions
- 28:43. Designing technology with human awareness to create a culture of responsibility
- 32:29. The need to rethink what "connected" means in our complex world
Resources
- 12 CIS Experts' Cybersecurity Predictions for 2025
- Episode 117: 2025 Cybersecurity Predictions from CIS Experts
- 2025 Data Breach Investigations Report
- 2024 DBIR Findings & How the CIS Critical Security Controls Can Help to Mitigate Risk to Your Organization
- Episode 119: Multidimensional Threat Defense at Large Events
- How to Construct a Sustainable GRC Program in 8 Steps
- Society of Information Risk Analysts
- Reasonable Cybersecurity
- Episode 135: Five Lightning Chats at RSAC Conference 2025
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.