Dear readers — security theater does not equal actual security.
2025 was yet another wake-up call: a direct shot in the face of every organization that thought their firewall from 2015 would save them. AI went from a boardroom buzzword to an easy, accessible weapon for both attackers and defenders. Nations got more serious about technology, healthcare systems got hammered, and somewhere a CISO is still explaining why “we’ve always done it this way” isn’t a security strategy.
Here’s the uncomfortable truth: most organizations are fighting 2025 threats with 2015 tools. And it’s costing them everything.
The attacks that defined 2025
Bybit. In February, the Lazarus Group pulled off the largest cryptocurrency theft in history, stealing $1.447 billion worth of Ethereum. Over 596 suspicious domains were detected targeting Bybit customers.
Microsoft SharePoint zero-days. State-linked hackers exploited two critical vulnerabilities (CVE-2025-53770 and CVE-2025-53771) in what became known as “ToolShell.” By the time Microsoft patched in July, 396 SharePoint systems had already been compromised.
Jaguar Land Rover. Described as the most economically damaging cyberattack to hit the UK in history. A September hack delayed car production for months, hitting suppliers so hard that some went out of business — the UK government stepped in with a £1.5 billion bailout. Disruption is often more valuable to attackers than stolen data.
Coupang. Data was stolen for five months before anyone noticed. By the time it was discovered, 33 million customers’ information had been compromised, and the breach led to the CEO’s resignation.
China’s surveillance leak became the largest known data breach in the country’s history — over 4 billion user records. Iran’s Bank Sepah lost 42 million customer records (~12 TB) to a collective demanding $42 million in Bitcoin.
The pattern? Attackers aren’t just breaking in anymore. They’re staying for months, taking everything, causing maximum disruption — and organizations only discover the breach when it’s far too late.
The numbers don’t lie
Organizations faced an average of 1,876 cyberattacks in Q3 2024 — a 75% year-over-year increase that accelerated into 2025. Phishing attacks have risen 4,151% since ChatGPT’s public release, and AI-generated phishing emails now achieve a 54% click-through rate versus 12% for traditional phishing. More than half of people can’t tell the difference.
93% of US healthcare organizations experienced an average of 43 cyberattacks over the past year. The average data breach now costs $4.9 million; healthcare breaches cost $9.77 million. By 2027, cybercrime is projected to cost the global economy $24 trillion.
What actually improved
Over 86% of organizations have begun moving to Zero Trust; the market reached $38.37 billion in 2025. Companies that complete all Zero Trust pillars are twice as likely to avoid a reported incident. Consistent use of AI and automation saves an average of $2.2 million per breach, and MFA — when actually implemented — blocks over 99% of identity-based attacks.
The uncomfortable truths nobody wants to say
Security is still treated as a cost rather than a business enabler — only 28% of companies embed security controls in transformation initiatives from the start. The talent shortage is worsening, with an estimated 4.8 million unfilled positions worldwide. And speed is still prioritized over security: spending on generative-AI initiatives outpaced security budgets by 2.6× in 2025. Organizations are building AI systems on insecure foundations.
What actually works
- Treat cybersecurity as a business imperative, not an IT problem — organizations that do are 69% less likely to experience advanced attacks.
- Implement Zero Trust like you mean it. Full implementation drops incident rates from 66% to 33%.
- Embrace AI for defense — thoughtfully, understanding both the benefits and the risks.
- Fix the basics. MFA, encryption, patch management, access controls. Sophisticated tools won’t save you if the fundamentals are broken.
- Build security into procurement. Your security is only as strong as your weakest vendor.
- Invest in people, not just tools.
Security is at a turning point. The game changes when we stop treating it as a checkbox and start treating it as what it actually is — the foundation everything else is built on.
Stay secure,
A
Sources & references (selected)
Accenture — State of Cybersecurity Resilience 2025 · World Economic Forum — Global Cybersecurity Outlook 2025 · Verizon DBIR 2025 · IBM Cost of a Data Breach 2024 · ISC2 Cybersecurity Workforce Study · Checkpoint Research Q3 2024. The full reference list is on our Substack.