版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領(lǐng)
文檔簡介
BCG
PRINCIPALINVESTORSANDPRIVATEEQUITY
AICreatesNewCyberRisks.ItCanHelp
ResolveThem,Too
ByBradenHolstege,
ClarkO’Niell
,
ColinTroha
,
VanessaLyon
,
AlexAsen
,YixingSu,SeanMitchell,Shai-LiRon,andHelenRhee
ARTICLEJULY30,20258MINREAD
AI
hasledtoawiderangeofnewapplicationsandsolutionstotransformbusinesses,butforchiefinformationsecurityo?cers(CISOs)andtheorganizationstheyprotect,italsocreatesnew
vulnerabilities.Infact,AI-poweredattacksarenowthemainissuekeepingCISOsupatnight.Asaresult,companiesareadjustingtheircyberbudgets—andinmanycasesincorporatingAI-enabledsolutionstokeeptheirorganizations,customers,anddatasafe.
?2025BostonConsultingGroup1
?2025BostonConsultingGroup2
BCGandGLCrecentlysurveyedCISOstounderstandtheirconcernsandprioritiesinanever-changingcyberrisklandscape.(See“AbouttheSurvey.”)TheresultsshowthatAI-poweredcyberattackshaverisentobecomethetopconcern,upfrom?hplacelastyearandcitedby80%ofCISOsinthesurvey.(SeeExhibit1.)Persistentconcernslikecloudrisk,third-partysecurity,andendpointprotectioncontinuetoholdsteady.
AbouttheSurvey
Toconductthesurvey,BCG’s
CenterforLeadershipinCyberStrategy
—alongwiththe?rm’sPrincipalInvestorsandPrivateEquityandTelecommunications,Media,andTechnologypractices—recentlypartneredwithGLG,aresearch?rmthat
primarilyservesthe?nancialindustry.Thesurveydrewresponsesfrommorethan300CISOsacrossgeographicmarkets,companysizes,andindustries.Wealso
segmentedrespondentsbasedontheircybermaturitytoidentifyhowleadingorganizationssetthemselvesapart.(Thisfollowssimilaranalysesin
2024
and
2023
.)
?2025BostonConsultingGroup3
Otherkey?ndingsinclude:
.ToprepareforAI-poweredattacksandevolvingcyberthreats,CISOsexpecttocontinue
increasingspendacrosscybercategories,especiallyinthreatintelligenceandapplicationsecurity.Overall,budgetswilllikelygrowbyabout10%thisyear,inlinewiththeincreaseinpreviousyears.
.CISOsareshowingstrongerinterestinadoptingnewcyberfeaturesfromexistingvendorsinsteadofnewvendors.
Our?ndingshaveclearimplicationsforallstakeholders.CISOs,C-suites,andboardsneedto
remainvigilantagainstthegrowingrangeofcyberthreats.Cybersecurityvendorsneedto
continuallyre?neandupdatetheiro?erings.Andinvestorsneedtoensurethatthecybersecuritycompaniesintheirportfoliocontinuetodevelopproductfeaturesandcapabilitiestoaddressthechangingcyberthreatlandscape.
TheRapidRiseofAI-EnabledThreats
Inourresultsfor2025,AI-poweredattackshavebecomethetopCISOconcern,withasharp19-
pointincreaseoverlastyear.Thatre?ectstherapidevolutionofAIoverall,creatingmorecomplexandunpredictablerisksthatmanycompaniesarestillstrugglingtounderstand.
Within
GenAI,
thebiggestconcernamongCISOsarethreatsthatexploitsocialengineering,citedby62%ofrespondentsasamajorconcernorcriticalthreat.Organizationshaveseenasurgein
automated,Gen-AIpoweredattacks,whichareincreasinglyeasyforattackerstoexecuteandcanbeextremelye?ectiveatdeceivingemployees,partners,orcustomers.Asonerespondentputit,
“We’veseenpersonalizedattacks,atspeedandatscale,targetingbothemployeesandcustomers.WeknowtheonlywaythiscanbedoneiswithGenAItools.”
CISOsarealsohighlyconcernedaboutAI-enabledfraudschemes,leakageofsensitivedataduringtheuseofGenAItools,andAI-assistedexploitationofknownvulnerabilities—allcitedbymore
thanhalftheCISOsinoursurvey.(SeeExhibit2.)
?2025BostonConsultingGroup4
CompaniesaretakingactiontomeettheAIthreat,butsomearestrugglingtokeeppace.
Speci?cally,CISOspointtoincreasinginvestmentsincyberawarenesstrainingandthreatintelligenceasthetoptwomeasuresagainstGenAIthreats.
BolsteringexistingcybertoolswithnewGenAIcapabilitiesisalsoatoppriority.MostorganizationsplantoadoptGenAI-drivencyberfeaturesfromexistingvendors(insteadofstartups),withhalf
expectingtoincreasetheirbudgettoadoptGenAI-cyberfeaturesandtheotherhalfexpectingtoadoptGenAIfeatureswithinthecurrentbudget.
Ontheotherhand,eventhemostcyber-matureorganizationsinoursamplearelaggingon
protectingtheirGenAIbusinesssystemsfromattack,withonly30%havingimplementedorpilotedcybersolutionsspeci?callytoprotectGenAI-relatedsystems.
ContinuedChangesinProductandVendorPriorities
Lookingatshisinproductsandvendors,threatintelligenceandapplicationsecurityproductshavebecomeincreasinglyubiqitousoverthepasttwoyears.Inbothcategories,citedadoptionrateshaverisenfromarangeof50%to60%in2023tonearly80%in2025.
?2025BostonConsultingGroup5
Areaslikezero-trustnetworkaccess,datasecurity,identityandaccessmanagement,andthreatintelligenceallshowprojectedspendincreasesof10%ormore.Regardingthreatintelligence,forexample,asorganizationsfacecontinueduncertaintyfromunknownthreats(especiallyfrom
GenAI),theyarelookingtogetasmuchintelaspossibleonwhatmightbecomingtheirwayandhowtoproactivelydefendthemselves.
Incontrast,CISOsexpecttospendlessonbaselineservicessuchasgovernance,risk,and
compliance,mobilethreatdefense,andbackupandrecovery—manyofwhicharebundledintobroadero?erings.(SeeExhibit3.)
Similarly,theconsolidationamongvendorsnotedinpreviousyearscontinuesthisyear.Acrossmostcyberproductcategories,farmoreCISOsexpecttoconsolidatethanexpandvendors.
Comparedtothesurveyresultslastyear,applicationsecurity,datasecurity,anduni?edendpoint
managementarethethreeproductcategorieswhereCISOsexpressedsigni?cantlyhigherinterestinconsolidation,potentiallydrivenbyvendors’platformstrategy.(SeeExhibit4.)
?2025BostonConsultingGroup6
Spendprioritiesareoneareawherethecybermaturitygapisnoteworthy.Advancedorganizationsinoursampletendtobemoreforward-lookinginhowtheyidentifyrisksandprioritizeinvestments.Speci?cally,theyarefocusedonriskssuchasAIthreatsandevolvingprivacydemands,alignedwithpotentialfuturethreatsandtheevolvingregulatorylandscape.Incontrast,less-mature
organizationslagonfoundationalinfrastructuresecurityandundervalueareassuchasmulti-cloudanddatacentermigration.(SeeExhibit5.)
?2025BostonConsultingGroup7
GrowingCyberBudgets
Inarecent
BCGsurveyofITbuyers,
aboutone-fourth(28%)expectanoveralldecreaseinIT
budgets,primarilyduetotari?-relatedcostpressures.YetCISOsseecyberbudgetsasrelativelyinsulatedfromreduction.CISOsexpectcyberspendtoincreaseby9%inthenext12months,
slightlylowerthanCISOs’expectationslastyear(11%).(SeeExhibit6.)What’smore,nearly80%expect
tari?s
tohavenochangeoronlyaslightshiincybersecuritybudgets.
?2025BostonConsultingGroup8
ThereareseveralpotentialexplanationsforwhyCISOsexpectcyberbudgetstoholdup.Oneis
thatcutscouldstillbecomingbutCISOssimplydon’tknowaboutthemyet.Anotheristhat
companiesaretakinga“waitandsee”approachtocostreductionsoverall,especiallygiventhe
uncertaintyaroundtari?sinthe?rsthalfof2025.Yetanotheristhatcompaniesseethecritical
valueofcybersecurityandarecontinuingtoincreasetheirinvestmentasthethreatenvironmentescalates.
TheBottomLineforStakeholders
Our?ndingshaveclearimplicationsforallstakeholdersin
cybersecurity
,fromC-suitesandCISOstovendorsandinvestors.
PrioritiesforCISOs,C-Suites,andBoards.Organizations,fromtheboardtotheCISO,should
increasinglyfocusoncybersecurityoutcomes.Giventheevolvinglandscapeofcyberthreats,
companiescannota?ordtorelax.ThatisparticularlytrueforAI-empoweredattacks,which
increasinglyrelyonsocialengineeringandfraudandareextremelycheaptoproduceconvincinglyandatmassivevolume.Althoughcostisafactorinassessingvendors,CISOsshouldfocusmoreoncybersecurityreturnoninvestment(ROI)thanpricealone—andremainabreastofconsolidationandotherdevelopmentsinthevendorlandscape.
PrioritiesforCybersecurityVendors.Forcybersecurityvendors,our?ndingsunderscorethe
importanceofcontinuallyrevisingandupgradingtheirproductcapabilities,especiallyregarding
GenAI-drivenfeatures.Whiletherearestillnichesforpointsolutionstosucceed,enterprise
customersshowaclearpreferenceforvendorconsolidationandacquiringnewcapabilitiesthroughadd-onmodulesandbundleso?eredthroughcurrentproviders.Accordingly,vendorsshouldaimto
?2025BostonConsultingGroup9
growthroughupsellingandcross-sellingtoexistingcustomersorattractingnewcustomersonthestrengthoftheiroverallplatform.
Inaddition,cybervendorsshouldcontinuetoemphasizethereliabilityandresilienceoftheir
solutions,bothwithintheirR&Dandproductdevelopmentlifecycleandasadi?erentiatingfeatureintheirgo-to-marketstrategy.
PrioritiesforInvestors.Forprivateequity?rmsthatcurrentlybackcybersecurityproviders—orseekto—ourdatashowsthefundamentalresilienceofthesector.Economicandgeopolitical
uncertaintyispushingcompaniestoscalebackITinvestments,butcybersecurityremainsa
budgetarypriority.Thatsaid,investorsneedtomakesurethecybercompaniesintheirportfoliocontinuetodelivervalue—throughfactorssuchastheoverallbreadthoffeatures,AI-related
innovation,andabedrockabilitytoprotectcompaniesfromevolvingcyberthreats—ratherthantryingtocompeteoncosts.InvestorsalsoneedtoworkwiththeirportfoliocompaniesonhowtobuildamarketingmessagearoundROItocustomers,todriveadoption.
Thegrowingscopeandcapabilitiesofbadactorsmeanthatallstakeholders—CISOs,boards,
vendors,andinvestors—cannotrest.AI,includingGenAI,isfuelinganeweraofcyberthreats,butotherdevelopmentsanddisruptionsarecoming.Our?ndingsshowthedegreetowhich
cybersecurityvendorsaremeetingthesechallenges—andthestepsthatCISOsaretakingtokeeptheircompaniesandcustomerssafe.
?2025BostonConsultingGroup10
Authors
?2025BostonConsultingGroup
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 2026年中北大學(xué)招聘備考題庫及一套答案詳解
- 2026年北京國科科服控股有限公司招聘備考題庫帶答案詳解
- 2026年吉安市文化傳媒集團有限責(zé)任公司公開招聘勞務(wù)派遣工作人員5人備考題庫及答案詳解1套
- 2026年北京數(shù)智星通科技有限公司招聘備考題庫及完整答案詳解一套
- 2026年四川大學(xué)教育培訓(xùn)部業(yè)務(wù)崗工作人員招聘備考題庫附答案詳解
- 2026年廣大附中南沙實驗學(xué)校招聘小學(xué)數(shù)學(xué)教師(編外)的備考題庫有答案詳解
- 2025年佛山市三水區(qū)殯儀館編外人員招聘備考題庫含答案詳解
- 2026年南昌市灣里管理局公開選調(diào)事業(yè)單位工作人員24人備考題庫及完整答案詳解1套
- 2026年北京中科格瑞科技發(fā)展有限公司招聘備考題庫及1套參考答案詳解
- 2026年制藥行業(yè)的電氣傳動控制系統(tǒng)設(shè)計
- 云南師大附中2026屆高三高考適應(yīng)性月考卷(六)思想政治試卷(含答案及解析)
- 建筑安全風(fēng)險辨識與防范措施
- CNG天然氣加氣站反恐應(yīng)急處置預(yù)案
- 培訓(xùn)教師合同范本
- 2026年黑龍江單招職業(yè)技能案例分析專項含答案健康養(yǎng)老智慧服務(wù)
- 2025年5年級期末復(fù)習(xí)-25秋《王朝霞期末活頁卷》語文5上A3
- (2025)70周歲以上老年人換長久駕照三力測試題庫(附答案)
- 定額〔2025〕1號文-關(guān)于發(fā)布2018版電力建設(shè)工程概預(yù)算定額2024年度價格水平調(diào)整的通知
- 鋼板樁支護工程投標(biāo)文件(54頁)
- 國家職業(yè)技能標(biāo)準(zhǔn) (2021年版) 無人機裝調(diào)檢修工
評論
0/150
提交評論