2025 Cybersecurity Predictions: How did we do?

Nov 5 2025

Every industry has their it’s-that-time-of-year-again rituals, and the cybersecurity industry is no different. The spring ushers in RSA, August is Hacker Summer Camp, October brings with it Cybersecurity Awareness Month — and, before we know it, it’s the end of the year and we’re once again making our “predictions” of what lies ahead. 

A wise young man once said, “Life moves pretty fast. If you don’t stop and look around once in a while, you could miss it.” In our space, a whole lot is moving fast. To see clearly, it's certainly important to take a moment to step away from the noise and look outward.

Many experts offer their predictions for the coming year, but how many stop to look back at how their vision for the current year fared? With that in mind, let’s take a look at the predictions Rapid7 experts made for 2025. 

A look back

Prediction: "Greater visibility will act as a life preserver for security teams treading water across an increasingly complex attack surface."

The importance of unified visibility, attack surface management, and exposure insight has become a leading theme in industry trends reports in 2025. The exposure management market is growing strongly, projected to hit ~$10.9 billion by 2030, which is up from ~$3.3 billion in 2024. Managed Detection and Response (MDR) adoption is also surging; the MDR market reached USD 4.19 billion in 2025 and is forecasted to keep growing fast. 

Rapid7 customer New Zealand Automobile Association (NZAA) offers a real-world example of this trend. Before working with Rapid7, NZAA’s cybersecurity tools were fragmented and disjointed. This lack of a unified approach reduced visibility and slowed down threat responses. Now, with Rapid7’s MDR service, NZAA has a partner that can provide 24/7 support, centralized visibility, and predictable data usage — all with transparency and scalability.

This is just one example of the evidence we’ve seen that security teams are acting to consolidate disparate tooling and connect proactive exposure risk management with reactive detection and response capabilities. As a result, these teams and their organizations are shifting holistically into a confident, resilient security posture.

Prediction: "To thrive in a world where regulatory change is an ongoing concern, SecOps should prepare for both the predictable and the unpredictable."

Regulatory change is indeed accelerating. For example, the EU's Cyber Resilience Act was passed in 2024, with application phases extending toward 2027.

The UK announced the Cyber Security and Resilience Bill in 2024 to extend cyber obligations on organizations. Security operations teams have had to deal with both "expected" regulatory shifts (like NIS2, SEC rules) and unexpected mandates or cross-jurisdictional tensions.

Many organizations are now incorporating compliance readiness, threat modelling for future rules, and flexible architectures. Moving forward, SecOps should expect even more scrutiny over how operations are designed and architected, as well as how insights are shared and with whom.

Prediction: "Cybercriminals will increasingly exploit zero-day vulnerabilities, expanding potential entry points and bypassing traditional security measures to deliver more ransomware attacks."

Zero days have continued to rise in prominence. Since 2023, Rapid7 has observed many notable zero-day-enabled ransomware and supply-chain attacks (e.g. MOVEit exploit, Cleo File Transfer, GoAnywhere MFT, Scattered Spider). 

Attackers are investing in zero-day toolchains, and zero-day brokers are emerging in dark markets (i.e., "exploit-as-a-service" trends). See our Initial Access Brokers Report for more detail.

Rapid7 Q2 2025 Ransomware Trends Analysis research highlights that threat actors are using zero days more often, especially in critical or targeted operations within sectors like services (21.2%), manufacturing (16.8%), retail (14.1%), healthcare (10.3%), and communications, and media (10%). 

In Q3 there were several instances of cybercriminals continuing to leverage zero-day exploits as initial access vectors during their ransomware campaigns. For example, CVE-2025-61882 affecting Oracle E-Business Suite was exploited in the wild by CL0p. The trend of cybercriminals exploiting zero-day vulnerabilities continues, as does the recurrence of not only the same cybercriminal groups, but also the same products being targeted over time (e.g., the file transfer product GoAnywhere MFT). 

A look ahead

2025 has certainly pushed security teams to their limits with an increasingly complex attack surface, accelerating regulatory changes, and a persistent rise in zero-day exploits and ransomware attacks. The ongoing talent gap and the struggle to bridge the divide between technical and business leadership have further compounded these challenges, making it crucial for organizations to prioritize visibility, proactive exposure management, and actionable threat intelligence.

What will 2026 bring? Take a look ahead with our experts: Register now for Rapid7’s Top Cybersecurity Predictions webinar.

Read more

Recommended Jobs

Staff AI Engineer

19 Chichester St, City Centre, Belfast, United Kingdom, BT1 4JB Product & Engineering
As a leader in cybersecurity, Rapid7 is expanding our global AI footprint and is looking for a passionate Senior AI Engineer to join Rapid7’s AI Centre of Excellence. The  AI centre of excellence is on a mission to use AI to accelerate threat inve...

Senior AI Engineer

19 Chichester St, City Centre, Belfast, United Kingdom, BT1 4JB Product & Engineering
As a leader in cybersecurity, Rapid7 is expanding our global AI footprint and is looking for a passionate Senior AI Engineer to join Rapid7’s AI Centre of Excellence. The  AI centre of excellence is on a mission to use AI to accelerate threat inve...

Account Executive, Enterprise (Illinois)

Remote Location, IL, United States, 62701. Remote Location, IN, United States, 46201 Sales & BD
Rapid7 is seeking a highly motivated  Enterprise Account Executive in Greater Chicago.  About the role: This is a field sales role covering a set territory of Enterprise accounts. Current residence in the Greater Chicago area is required.   Abou...

Account Executive, Commercial

Austin, TX, United States, 78701 Sales & BD
Rapid7’s Commercial Sales organization in Austin is seeking an Account Executive to join the team. You will serve as a strategic partner for clients in your assigned geography, helping them achieve a more secure digital future. In this quota carry...

Account Executive, Federal

Remote Location, VA, United States, 23218 Sales & BD
Rapid7’s Federal Sales organization is seeking an Account Executive to join the U.S. Federal team. This is a rare opportunity to join Rapid7 and serve as a strategic partner for named Federal Civilian accounts, helping them achieve a more secure d...

Senior Manager, Technical Support

Water Street, Tampa, FL, United States, 33602 Technical Support
We are looking to add a Senior Manager of Technical Support Engineering to lead a team of technical engineers, enhance our operational processes, and elevate our customer experience. Rapid7 is a hybrid company, the expectation for this role is 3...