Cybersecurity Predictions for 2025: Platforms, Convergence and the Future of Risk Management – Predict 2025
Fernando Montenegro, vice president and practice lead, cybersecurity at Futurum, highlights key trends for 2025 in the cybersecurity space: security platforms, the evolution and convergence of application security with cloud security, the evolution of third-party risk management, and more.
Ready to stay one step ahead? Download the full report for expert insights and strategic guidance: https://bit.ly/41dbc2a
Transcript
Hello, I'm Fernando Montenegro and I recently joined Futuro Research as vice president and practice lead for cybersecurity research. You may have seen the video from my colleague Krista case, so this is a bit of a compliment to that. I also encourage you to check out our ebook.
We want to highlight several crucial areas for the security landscape in 2025. First up is the discussion around security platforms. We emphasize the, the very nuance discussion to be had about what is actually a platform and how do you consume one.
We typically think of a conversation as a dichotomy between platform versus best of breed, but we think that have actually evolved into a much more complex decision matrix besides choosing on functionality, pricing, et cetera. We argue that there are now at least three dimensions that people should consider. The first one is, do we buy it as a platform or as a point product?
Do you consume it and uh, as a product and then you have to integrate it yourself? Or is it integrated into a platform? Which one evolves quickly?
Which one how gives you more, uh, faster time to value? The second conversation is, are you buying something that is best of breed versus quote unquote good enough? Of course, we all want best of breed, but that comes at a cost.
So how can organizations choose with where they want to pay for a premium versus where good enough is? Well, good enough. Lastly, you have the, the, the topic of how do you consume it, how you do, how do you deliver it?
Is it something that you're choosing to buy from a vendor directly or is it something that you are working with a service provider or a channel partner on? Each of these dimensions have pros and cons, and you have to evaluate based on specific organ organizational requirements. We argue that a cybersecurity becomes much more strategic.
These types of decisions become much more tied to an economic angle to them, and we have to frankly just navigate what the economic trade-offs are between these choices. Another key area for us for 2025 is the evolution in the convergence of application security with cloud security. Now, cloud security best practice in general is encouraging us to use more automation and infrastructure as code, as principles, and that by itself fits really well with how application security already works.
Also, the developers that are typically outputting, uh, front end code H-T-M-L-C-F-F, JavaScript or backend code go Python, no, what have you, they are also very comfortable creating Kubernetes configurations in yml or helm charts or cloud formation templates with cloud formation or Terraform, et cetera. So it's not that big of a jump to include those configurations into the software supply, uh, pipeline. This alignment is really interesting because it creates this proximity between consuming application security and cloud security functionality.
That being said, this convergence is also interesting because we have to rethink how teams are structured, how responsibilities flow from one to another. So that's another area that we're looking at. Third area I want to highlight is this evolution of third party risk management.
We think that modern third party risk management is much more about the addressing both the business level risks as well as the technical risks across your value chain. So this includes evaluating, for example, security libraries or cloud posture or SaaS components that you're using as well as vendor reliability, financial reliability, et cetera. The challenge of here is how do you as an organization maintain this complex, uh, information set on first party, second party, third party, first party relationships?
So it's really interesting. One more point I want to, uh, mention before you wrap up, and that is that there are quite a few security areas that actually are very good at spanning multiple domains, if you will. We all talk about AI security, for example, as one of these, but that said, we think there are other areas.
Ransomware response and, and uh, and protection for example, is one of those. It's not just an endpoint security issue, just like it's not a only a data security issue, it actually flows into a bigger conversation around risk management and cyber resiliency. Also, secure access service edge implementations, right?
They themselves are interesting because they span from network security to cloud security, data security and so on. All of these are really interesting areas that require us to look at them with different perspectives and, uh, from different lenses. As we look into these in 2025, we here at, uh, at Tuum are paying very close attention to the needs of all the stakeholders in this, in this area.
As I get to wrap up, I want to thank you very much for your attention and I want to encourage you to do three things. First of all, if you can please review Crystal Case's video for some other cyber predictions, please review our ebook for a complete set of predictions from cybersecurity and other areas, and also I want you to stay connected with for term research. com.
I often like to say, I mean, there is never a dull day in the fiber security industry, so thank you very much for your time and I wish you all a great day.



