Futurum Research Presents Cybersecurity Trends with Fernando Montenegro
Futurum Research acts as an information broker, connecting technology buyers, sellers, investors, and other stakeholders to provide decision support and insights into the cybersecurity landscape. Their research, led by Fernando Montenegro and with contributions from analysts like Krista Case, encompasses both qualitative and quantitative methods, including a recent survey of over 800 decision-makers across various global markets. This survey, conducted between February and April 2025, focused on understanding organizational changes and perspectives on different cybersecurity fields, with a significant emphasis on senior leadership.
The research identified four major trends shaping cybersecurity in 2025: the pervasive influence of AI, the expanding and increasingly complex attack surface, a significant move towards security platforms, and the evolution of data protection into broader resilience strategies. Organizational trends indicate that cybersecurity is gaining executive visibility, with frequent reporting to senior leadership and a notable increase in security budgets driven by modernization efforts, risk management strategies, and regulatory compliance. When evaluating vendors, product effectiveness and capabilities remain paramount, but total cost of ownership and integration with existing tools are increasingly critical factors. The survey also highlighted challenges in vendor evaluation due to the crowded and noisy cybersecurity marketplace.
Key findings across specific cybersecurity domains reveal several insights. Cloud security incidents and data breaches were the most reported incidents, leading to data loss and operational downtime. In application security, talent shortages and legacy application debt are major challenges, with application development teams often leading security efforts. Cloud security sees stronger ownership by security teams in multi-cloud environments, with a preference for cloud provider-native security solutions. Data security initiatives are increasingly leveraging AI/ML for threat detection and focusing on data security posture management. Endpoint security remains stable, primarily providing telemetry for security operations, while identity management is a “new hotness,” especially concerning non-human identities and rising costs. Risk management and security operations are becoming the central nervous system for modern security, with a focus on improving context derivation and incorporating cloud security into SecOps. Network security emphasizes automation, NDR, and micro-segmentation for zero-trust implementation. Lastly, while optimism about AI’s role in security is high, Futurum stresses the need for education regarding AI’s actual capabilities and limitations in replacing human analysts.
Presented by Fernando Montenegro, VP and Practice Lead. Recorded live at Security Field Day 13 in Santa Clara, CA on May 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/futurum-research-presents-cybersecurity-trends-at-security-field-day-13/ or visit https://techfieldday.com/event/xfd13/ or https://FuturumGroup.com for more information.
Transcript
It's an honor to be here. I've, I've, I've, I grew up in my career watching Tech Field day events, right? From the earliest networking events all the way through.
Now being here, it's just like, I, I, I still not thinking straight. Now as we begin, I'm going to talk about some of the, some of the research that we've, that we've recently done. And I want to emphasize, first of all, that it's more than just me.
I am, I'm, I lead our cybersecurity practice, but we have other analysts as well. Uh, major shout out to Krista ca. I think she's been at a textile delegate as well, right?
Uh, Krista does phenomenal work on, on data and identity. So some of the, the insights here from her, but also other analysts and other research teams within futu, like, uh, I, uh, uh, Tom and I, and, and, and others are on like a shared community of security practitioners, uh, uh, where we share research topics and, and so on and so forth. Now, what I'm going to talk about is, has to do with some of the research that we just released, the cybersecurity decision maker, but also a little bit broader about our research, uh, overall.
Now, before we get started, one of the things I wanted to talk about is what we are bringing to the table of analysts. Like, uh, I get the question all the time. What does our research look like?
And what I like to tell people is that industry analysts are fundamentally information brokers, right? We're sitting between four major groups. We're sitting between technology buyers, technology sellers, uh, investors and other stakeholders.
And each of these groups, they take actions. They, they have questions, and they come to us for some of those questions. So, buyers may want to know what are sellers up to?
Uh, uh, sellers want to know what are buyers up to, and investors want to know what's hot and what's not. So, uh, I like to say that we're not a, um, uh, we are bringing to you a different perspective. We're bringing to you an additional insight for basically decision support right now.
Sorry, with that outta the way, we'll take a look today at just a few things. We have, uh, I wanna talk about our qualitative and our quantitative research. So we'll take a look at our four major trends for 2025 that we have identified.
Then we'll go into the survey that we, that we just produced. We'll tie it to some, uh, looking forward type of research, and then we'll, we'll, we'll wrap up with some, something around strategic framework. Now, who here knows of, uh, a guy named George Box?
Does the name ring a bell? George Box? So, George Box is a statistician, and he has, uh, it, it's attributed to him, I think it's his, he has a saying, uh, that is, uh, that leads him to be, in my opinion, the patron saint of, uh, of industry analysts and statisticians worldwide, which is, all models are wrong, but some are useful.
4 or whatever, but it's more what are we looking at the directionally right, and be, because this is a survey and surveys for those who do statistics are, uh, very good instruments for some questions, but they do have potential issues. So, again, let's take this directionally, this was a survey that we run twice a year, and, uh, we actually ask about 90 questions overall. Uh, we field that approximately a little over 800 responses, 849, I think in some cases, and we field it across major markets, north America, uh, north and South America, emea, Asia, et cetera.
We did, uh, we did focus on what we call decision makers. So in the interest of time, I don't have the, the, the statistic breakdown of the demographics, but it leans about 60%, 65%, uh, senior decision makers, fee level titles, et cetera. And, um, only about 10% practitioners, give or take, and those would be more on the security side.
Anybody who was not security or it, we, we qualified them out. We also qualified out on people not involved in decisions. Uh, we also qualified out on very, very small companies under a hundred employees.
Right now, the latest data was collected somewhere between February and March, actually to February and April. But, uh, March is fine enough, and we use it to guide some of our high level questions in terms of, um, we, we ask on different areas about how the organization is changing, how people are looking at different, uh, uh, at different fields. Before we get to the survey, though, qualitatively, I talked about our four key trends, and if I had to ask people to guess, uh, what, yes, of course, ai, right?
So we we're looking at four major trends influencing our research throughout the year. Those four major trends are ai, ai, ai, right? Uh, I'm not a Luddite about ai, by the way.
I, I strongly believe in it, but I think we should have a very clear conversation about AI and security, but we'll, we'll leave it for later. We are looking at the expanding attack surface and, and, uh, our presenters mentioned attack surface before. Now we look at attack surface in two ways.
One of them is that the attack surface is not only growing in terms of, uh, number of entities being mentioned, but it's also growing on cognitive complexity. We're asking people to look at more things. Your security analyst is now being asked to look at fast logs, and they're being to ask that identity logs, and they're being asked to look at, oh, yeah, EDR logs too.
Sure, why not, right? The, the, the other trends is this large movement towards security platforms, and we'll have more to say about that. And then the fourth one is, uh, uh, Krista primarily, she does a lot of work on, on data protection.
And, uh, we are calling out the fact that these vendors are now doing a lot around evolving data protection, backup and recovery type stuff, more into resilience. Those are the four major trends. So without further ado, I'm already late.
Let's look into some of the, the trends. So first of all is organizational topics, and I do apologize if, um, if font size is are small. Jack, I did, I remember your comment, but I am trying to get as many things as as possible.
One thing I'll say is that, um, the broader comment here is that cybersecurity now wears who? These anties, we ask practitioners, what do you do? Uh, uh, again, 90 questions we had, I, I, a lot of them died on the cutting room floor, right?
Uh, what they say in the, about the, in writing, you kill your darlings. It's absolutely true, because we had to drop some questions. But fundamentally, a couple of things are really interesting.
Number one, we are seeing very frequent reporting. We ask people how, how often do you report to senior leadership? Monthly or quarterly is the majority of responses, as you can see here.
The other question we asked was, okay, wonderful. Uh, what's happening with your budgets? This was asked again, February, March timeframe, and we see that, um, the number of people indicating a increase is, uh, uh, significantly larger than those indicating a decrease on those on, in that case, we asked a follow-up question, sorry, for the small slides, what is driving that growth?
And what was interesting is that the majority, or we ask people to rank one, two, or three, where, uh, uh, whether that was their number one factor, number two, number three, and then we add the totals, right? So cybersecurity modernization efforts and risk management strategy came in as the, as the, of the top two digital transformation, not too far behind. And, uh, regulatory slash compliance requirements not far behind that.
So I find this, uh, interesting in the context that it points to security teams being more proactive about what they're doing, right? It also points to a longer trend that we've seen and that we, we we're calling out, which is this much closer interaction between cybersecurity teams and the rest of the organization, the lines of business, et cetera, particularly on the compliance side. Right?
Now, this was on organizational design. We asked where, okay, you are now, so you, you again, uh, I saw, I saw the reaction, I'm sorry. We have a lot of these.
We ask people, where is, uh, uh, your selecting vendors, how, what is going on into selecting your vendors? And the question here was about what are the factors that you use? Product effectiveness and capabilities was the top choice fair, right?
But right after that, vendor security certifications, total cost of ownership, and, uh, integration with existing tools, I'd ask people to keep those two factors in mind. Total cost and integration. They come up again and again and again on across pretty much every area.
When we ask, interestingly, when we ask people, what is change? What is a challenge for you when you are evaluating our vendors, right? What comes up most often is, yes, it's difficult to come, rapid markets, technology challenges, and the, to, to assess the complexity of integration, right?
There is too much noise. We were having a conversation as a team, uh, before recording here, and someone mentioned, oh, there's 4,000, uh, uh, vendors in cybersecurity. It is an extremely noisy marketplace, and that shows up again and again in some of this research.
In retrospect, my strategy of having two charts per slide was probably something I should have revisited. We asked the, the topic number three was about security platforms, right? We were talking, I mentioned that it's one of the transfers, and we keep seeing this.
We, uh, we ask, do, what do people prefer? And the ones in in red are those planning some sort of consolidation versus the ones in, uh, teal, whatever, call it that is, uh, are actually preferring to increase a vendor count. Now, this is not to say that it is, uh, definitive, but there is a slight preference for people doing vendor consolidation.
We can go on a debate here, but I think that fundamentally from an economic perspective, uh, you can, you can get some benefits from, from security platforms as opposed to point products. And that seems to be, uh, that approach seems to be resonating when we ask people, what are you expecting out of security platforms? What comes up is integration and operational efficiency as the top choice and total cost of ownership.
People are expecting lower costs there. Right? Now, one of the things when you talk about security platforms is that people are gonna say, oh, does that mean we're going to come down to one?
Is there going to be one to rule them all? I would argue that, that that is, uh, that's a negative, that the strawman type of argument in the context that we do see elsewhere in industry, not cybersecurity, but we see this move towards platforms elsewhere, and I think that this is part of a broader revolution of cybersecurity towards that level of maturity. Fernando, who was the target survey participant?
This research, Uh, it varied between, uh, so we asked, uh, I, I can show later if you want, but we asked, uh, uh, senior security, senior executives, senior IT executives, uh, mid-level IT executives, mid-level security executives, and, uh, technology, uh, analysts and security analysts within companies, right? Okay. So kind of like director and above direct, Uh, director and above, manager and above, okay.
Right? And this is the, the, the, the thing about kill your dollar, kill your darlings, right? Because I don't have the, the breakdowns on the slides.
We can go look into them in in more detail if you want, because I think Tom alluded to that on the other presentation. There is absolutely disconnects between senior leadership and, and elsewhere, right? In terms of what they expect, uh, from some areas.
And what about the industries? Uh, industry definition, it was a broad set of industries. We did not, one of the fact controlling factors we did was we asked for, uh, no more than 15% on any one industry.
So, uh, there's about 20 of them, give or take right now. These are high level numbers. We can dive into industry specific numbers.
We try, like I said, we try to stay within 15, uh, no more than 15%. Like I, we've had other surveys where we had it respondents at like 40%. No, that doesn't, that doesn't work.
I'm sorry. When we look into, um, the kind of incidents that people reported, one of the statistics we published, not published here, but one of the statistics we, we've, uh, came up was that we asked how many significant incidents they had over the past 12 months, and approximately 80% of people said they had at least one, right? Uh, um, again, survey data is, uh, directional.
When we ask what was wrong, people report to cloud security incidents and data breaches of the most common ones, or more people ranked cloud security incidents and data breach in their top five than anything else. Data breach was interesting. It, it came, a noticeable number of people ranked it as a number one type of incident and the outcomes, uh, data loss and compromise and system operational downtime above other things.
Now, this is what we had in terms of high level survey. This is a sample size 849. When we go into area specific findings, what we did with the survey was that we took the 800 people and we routed them to different areas.
So the sample size drops, so it's about one 10 in most cases, one 11 in some. But, um, so we, again, sample sizes, drop margin of error goes up, but, uh, but it's still directional here. We ask, so on application security, right?
We, for each one of those areas, I have one chart and then some observations that, that, that look better as text than, than than actual charts. But, um, we asked key challenges in application security, shortage of talent and security, debt in legacy applications. Those came up as, as most prevalent.
Uh, AI starts to make a play here, but not as much. What's interesting about application security, and I mentioned collaboration muscles, is because it's one of those areas where we asked participants, how well do security teams work with your application development teams? And the majority of them said that, uh, I should close to the majority of them said that it's application development teams leading the actual application security efforts, which some security oversight.
This is intro. Why does this matter, right? Because particularly when we talk to those trying to get security tooling into organizations, they go, oh, I'm going to sell to the ciso.
No, you shouldn't be selling to the ciso. You should be talking to your, uh, to your application development teams because they are the ones who are likely doing this. And then going to security and asking for, Hey, we like this.
We want to use this. Can we use this? Please?
Right? What's interesting, I said, uh, uh, a fluid funding model is that when we ask practitioners, okay, great, who's paying for this? Then it's a lot more distributed.
About 30%, give or take said that it's actually coming from security and about 30% sage coming from app dev and around 30% sage coming from the line of business. So it's, that's why I say fluid, right? One of the areas that I'm trying to pay attention to is product security, the difference between product security and application security.
And we continue to see that growing in importance as a, as a general topic, right? It's an area that we do want to pay a little more attention to going into the second half. And then, uh, that platform conversation comes up again with a number of, a number of vendors, a number of respondents indicating they want to buy application security from a security vendor.
And then, and a number of them asking from their application platform, so not endorsing anybody here, but GitLab, GitHub, those kinds of, uh, of, of environments. That's an application security on cloud security. We see security teams playing more of a stronger, uh, having a stronger role as compared to application security.
Here we have 34% of security teams indicating they outright own cloud security end to end, and some, uh, of course some level of, of sharing with somebody else. 4 on average cloud service providers. Uh, the, the, the major spend with the major cloud provider is usually very, very close to 60% or up.
And one of the thing here is that it's very clear that people indicate a preference for, I want to buy my cloud security from my cloud provider. I don't want I, I'll buy it from a third party, of course, but my preference is the, the provider in terms of key challenges. They indicated integration comes up again between secur, legacy security controls, misconfiguration and cost management, right?
I've been doing this elsewhere for, for a few years, and cost management, it's usually one of the top three. Everybody wants to do cloud, but it gets expensive really quickly for data security. This is more Crispus area than mine.
A couple of things that, that pop up ai, this is where, uh, top initiatives for data security utilizing AI and machine learning for threat detection pops up here. And in terms, what I found interesting here is that public, uh, or post quantum cryptography is seeing a little bit of a, of a, of an uptick. We noticed this at RF at, at the RSAC conference.
I have to learn to say RSAC now that we, we rebranded, right? And, um, uh, data security posture management's an interesting area in the context that it sits somewhere between is it a cloud security function or is it a data protection function? Our respondent in indicates primarily they're looking at this as a data protection conversation as opposed to a, as opposed to a cloud security one, right?
And this is interesting because it's similar to other movements we've seen around, uh, CSPM, for example, cloud security, posture management, and cloud security, uh, and, and cloud workload protection, kind of folding into security operations a little bit. Would you normally expect to see low TCO as just a tiny little sliver of their concerns? Your bottom one?
Uh, no. I would, I would expect, I would expect, but, but These are just more important. People indicated this is more important, yes.
But, but you're right. I, I, I, mm-hmm. It did pop up a little.
Hmm. You know, when it comes to endpoint security, it's an area that's mostly stable, right? I used, I started in endpoint security, and we've sort of moved mostly towards, it's very clear that, or the majority or large number indicators, it's owned by IT security takes a little bit of it.
We've done endpoint serve primarily to give, uh, primarily to, to give telemetry to security operations. What's next? I, I would argue that we are seeing a little bit of an uptick in, um, endpoint technology, particularly secure browsers if an area that that's popping up a little bit, but, um, not enough to make it significantly into the, into the number of here.
And, um, that preference for platform comes up as well. Identity management. I call it the new hotness in the context that anything to do, if, if you ask people one thing about Gentech, it's, yes, I said that, I'm sorry, uh, about, uh, Gentech ai, people have been paying attention to how do you do identity for those agents.
Uh, it's one of those, one of the areas people are looking at, non-human identity, et cetera. It does, um, it, uh, we, we did notice that people are looking at those differently. IAM dedicated, I a a teams are much more likely to have more ownership of human identities, and they're leaving the non-human identities more to the, to more as an IT concept, right?
Almost like a secret that you're, that you're going to manage. And, uh, the same thing about costs pops up as well. Riving costs, 30% of people ranked, uh, riving costs on identity as their one to three choice.
They didn't want to reproduce the entire chart. Here we're almost done risk management and security operations. That is, we've started to calling it the central nervous system for, for security, for modern security.
This is both in the context of yes, fims and soars and XDR run the world, but also the perspective that we have a, um, goes back to the trend about the attack surface. We've been asking people to do more. We've been asking SOC teams to improve how they derive context from things, not only from a, not only from a a numbers perspective, but also from an m and a perspective.
We've all seen that, um, that, uh, Palo Alto moved their, uh, uh, what used to be Prisma Cloud a few months ago, they moved Prisma Cloud into Cortex Cloud. So now it's part of security operations. Google or Alphabet announced their intent to acquire with, uh, in our opinion, that's not a cloud security deal, that is a security operations deal because they're trying to fold it under security operations.
So this is popping up in terms of, um, this is popping up in terms of asking security teams to do a lot more just wrapping up network security. I call it stable, but complex in the context of it's relatively well understood. Um, many organizations have a central network security team, uh, that owns network security.
Uh, 30% indicate some shared ownership between networking teams and security teams. And, uh, uh, a sizable chunk prefer, say they prefer a platform approach. One of the things that I found interesting is when we ask people what are their key priorities, uh, network security automation pops up, uh, as dev, NDR and, and segmentation, right?
So we go back to we are, uh, we we're trying to get more context. We're trying to automate things better, and, uh, we're trying to implement zero trust. I would argue from an editorial perspective that zero trust finally found its place in the world with micro segmentation, right?
Uh, it, it's, it's the right mindset for that, and that's one of the areas that we have seen an, an uptick in is microsegmentation, I did not mention until now, our friend's ai. So yes, that AI thing here, we just ask practitioners, how do you feel about a particular question, right? Do you agree?
Do you not agree? And, and so on. You would not, you will not be surprised to say that, uh, significant number of people agree or strongly agree with things that, uh, oh, look that, uh, uh, that they have the, the, the necessary expertise to in, to investigate AI security instance.
This seems to be, uh, very optimistic, I would argue, right? Uh, AI is top of mind for people, and they want to jump in, and they have, and they have been doing that, and it's our job as guides to illustrate some of that and say, look, there, there is about 61% of people who, who agree to some level that you can have AI tools replace SOC analyst. I'm not so sure.
So there's a lot of education that, that we need to be doing very, very quickly. I want to wrap up with a couple of things. One of them is, I'm not sure if anybody here read the report, the cyber hard problems, that the National Academies, that it was National Academy of Science Engineering, they just published, and I'm bringing this up to your attention because a, I'm writing about it for our upcoming research, but also because I think it's a very interesting glimpse into what are people going to be concerned with over the next, let's say, 24 to 36 months, right?
The, this is, uh, this is an effort that was, uh, initially started in 1995, and they refreshed it just now with what are the key problems that cybersecurity overall has in the context of the modern world, if you will. Uh, you have the link here to the, it's a, it's a free download. It's a, it's a, uh, uh, an instrument to help policy conversations.
What I find interesting here is that we feed the same topics all over the place. Risk assessment, security development, supply chain, economic incentives, and so on. I want to wrap up with a, um, I want to leave you with just a couple of, um, I like to, just a suggestion.
I like to think about how do we plan for what's next, right? How do you navigate change in my professional career? Two things that have helped me are two mental models, right?
I'm not sure who here is familiar with the FIN framework or widely maps, right? Uh, the connecting framework is about how do you understand the relationship between cause and effect for a particular problem? And then from there, what actions should you take?
This is particularly useful in the context of what are we automating, right? Whereas something like worldly maps, it's a whole other conversation is about the evolution of technology, right? Something that begins as a, as a very nascent technology nobody ever heard of, to something that becomes more mature to something that becomes com commonplace to something that becomes commodity, right?
How do you manage that technology change? We can talk more about that later on. I do want to wrap up with high level recommendations.
From a technology perspective, we are asking people, you should be leaning heavily into ai, not so much because you want to jump into the hype, but because you want to be able to explain to people what's actually possible and what's not possible, right? Data security, IM and SecOps are key areas that there are particularly hot right now, and as it, as it came up on the survey, uh, time and time again, integration efforts, automation integration are important areas from the business perspective, getting closer to what the business actually needs from a strategy perspective. I mentioned the, the, the two frameworks, uh, widely maps have the concept of doctrine, which is what is the right choice to use in any particular scenario.
I think it's interesting, and then what situational awareness is we all consume way too much content, right? I think that the challenge has shifted from an acquisition of content to a curation of content.