Top security challenges introduced by AI include new threats, new attack surface, and new compliance requirements

Netwrix has released its annual global 2025 Cybersecurity Trends Report based on a global survey of 2,150 IT and security professionals from 121 countries. It reveals that 60 percent of organisations are already using artificial intelligence (AI) in their IT infrastructure and 30 percent are considering implementing AI.

  • Sunday, 27th April 2025 Posted 2 weeks ago in by Phil Alsop

Research shows that AI has impacted organisations’ security posture. 37 percent of respondents say that new AI-driven threats forced them to adjust their security approach, 30 percent report the emergence of a new attack surface due to the use of AI by their business users, and 29 percent struggle with compliance since auditors require proof of data security and privacy in AI-based systems.

“Today’s AI-driven business processes are vulnerable to a host of new threats that security teams must be prepared for,” says Jeff Warren, chief product officer at Netwrix. “The data shows a rise in security incidents that are identity-driven and infrastructure-focused. Indeed, identity-driven attacks are likely to dominate even more, with crafty new ways to bypass MFA, abuse of machine-to-machine identities like service accounts and tokens, AI-powered deepfake voice and video phishing, and even synthetic identity creation at scale.”

“AI workloads trained on proprietary enterprise data represents intellectual property and are attractive targets for cybercriminals, says Dirk Schrader, VP of security research at Netwrix. It is important to secure data across the entire AI lifecycle, from ingestion to model training to monitoring API endpoints for any signs of prompt injection, abuse or model leakage. Finally, security teams should apply Zero Trust principles in the world of AI: assume every interaction with the AI system, internal or external, could be malicious, and enforce strict authentication, least privilege access and continuous monitoring.”

In this year’s survey, we investigated incidents that demanded a dedicated response from security teams, rather than those that were automatically detected and remediated. Based on this definition, 51 percent of respondents confirmed experiencing a security incident in the past 12 months. The number of organisations reporting no impact from security incidents is shrinking rapidly, from 45 percent in 2023 to just 36percent in 2025. 75 percent of respondents reported financial damage due to attacks — a significant increase from 60 percent in 2024. The number of organisations estimating their damage at $200,000 or more nearly doubled, from 7 percent to 13 percent.

“Direct breach costs are well understood, but more subtle costs include intellectual property loss, product development delays, and reputational damage, which are all hard to quantify but can be devastating, especially if innovation is essential to the business model,” added Warren. “Breaches damage brand trust, and customer churn often peaks when the time comes to renew the contract – well after the immediate crisis seems resolved.”

Board expands collaboration with Microsoft

Posted 1 day ago by Phil Alsop
Board is expanding its collaboration with Microsoft, reinforcing its commitment to use AI-driven innovation, deepen its Microsoft Azure integration,...
New program provides real support and real solutions designed to deliver real AI impact for partners.

UiPath recognises Fast Track Partners

Posted 5 days ago by Phil Alsop
Global partners are recognised for establishing their commitment to ushering in the agentic era for customers with early access to the UiPath...

StorMagic launches Global Channel Partner Program

Posted 5 days ago by Phil Alsop
Three-tiered structure empowers partners to deliver budget-friendly, simple on-site virtualisation solutions and capitalise on the VMware transition.
Barracuda Networks has unveiled powerful next-generation threat detection capabilities fueled by multimodal AI.

Sectigo Joins Pax8 Marketplace

Posted 5 days ago by Phil Alsop
Company fast-tracked by Pax8 to help MSPs remove the complexity behind SSL/TLS certificate management, reducing the risk of business outages for...

Nutanix and Pure Storage partner

Posted 5 days ago by Phil Alsop
Combined benefits of Nutanix Cloud Platform with Pure Storage FlashArray to provide flexibility, security, and scale with the high-performance needed...
Schneider Electric designated a Vendor Champion in Canalys’ new report for channel management leadership, among only six other vendors.