Cyber Security Insights October 2025

Cyber Security Insights October 2025

Written by Bryan Altimas
Portraits of bryan altimas from riverside court consulting in his office at bureau in design district with and without clients, 14th november 2022 photography by fergus burnett accreditation required with all use 'fergusburnett.com
Photography by Fergus Burnett fergusburnett.com

Cyber security threats have evolved dramatically in 2025. As AI advances AI powered threats are emerging. AI powered defence is also developing rapidly. However, the more traditional risks remain and need managing. This month we look at:

  • The expanding insider threat. In 2025 insider threats are more complex, subtle, and often unintentional.
  • Shadow AI: The growing threat no one in your business is owning.
  • The missing link in cyber security is culture and ethics.

The Expanding Insider Threat

In 2025, the insider threat has evolved. And if your organisation is still only looking inward for malicious employees, you're missing the bigger picture.

The traditional image of an insider threat a disgruntled staff member downloading sensitive data on their way out the door is outdated. Today, insider threats are more complex, subtle, and often unintentional.

The insider threat

The Fake Employee

Adversaries don’t just exploit access they exploit assumptions. HR vetting, procurement workflows, and academic partnerships all become potential infiltration vectors.

Are you sure your remote interview using Teams and Zoom is actually interviewing a real employee? Nation state sponsored attacks from North Korea have successfully managed to get fake employees recruited into the technology sector. They then extract intellectual property (IP) to North Korea. Evidence shows this has been so successful in the tech sector it is now being widened to other sectors.

Someone on Payroll Sells Access

Using stolen identities to access organisations has been prolific in 2025. The last few months has seen employees selling their access credentials.

Someone on payroll sold their login. That’s it. That’s the breach.

It’s not about how good your firewall is. Or how clever your EDR is. If an employee chooses to sell their keys to the kingdom you are in trouble before your tools even blink.

And we’re not just talking about disgruntled tech staff. Some of the compromised accounts were low-paid workers, contractors, and even interns.

Economic pressure. Remote work. A lack of visibility. All of it fuels this new threat.

“Your CEO Is on a Video Call” Except They're Not

A meeting suddenly appears in your calendar at very short notice with the CEO.

The engineering consultancy Arup was hit by a highly sophisticated scam involving deepfake video calls. During the meeting, staff were instructed to transfer transfer $25m in 5 separate payments. And they did. Because why wouldn’t they? The CEO asked on a video call.

Except the CEO was never there.

This isn’t deepfake audio anymore. This is real-time deepfake video conferencing. And the tech is frighteningly good.

If your people aren’t trained to spot the signs or empowered to question “authority” in high-pressure situations you’re a sitting duck.

What These Cases Prove

The insider threat has evolved. You are now facing:

  • Fake employees who steal.
  • Insiders who sell, not steal.
  • Deep fake video calls with management who command, not code.
  • Attackers who exploit trust, not technology.

Cybercrime has moved into the grey areas of psychology, economics, and AI-enabled deception.

And the old playbook password policies, VPNs, endpoint controls is not enough. Even zero trust must evolve.

How to Respond

Here’s what scaling businesses must do to stay ahead:

  • Meet employees in person.
  • Deploy behavioural anomaly detection tools that flags unusual logins, access times, locations and data transfers. Not all insiders look suspicious until they act.
  • Monitor what is available about your organisation on the dark web. Threat intelligence should include checks on credential marketplaces.
  • Rebuild your access strategy. Least privilege isn’t a suggestion it is mandatory. Regularly audit permissions, especially for dormant and shadow accounts.
  • Implement deepfake-resistant processes. Anything financial or sensitive should not be validated by video alone. Unexpected urgent meetings with senior management should be separately validated. Multi-channel confirmation must become standard.
  • Train staff on deepfakes and social engineering. Make it clear: If something feels off, it probably is. Foster a culture where questioning seniority is a strength, not insubordination.
  • Establish a rapid-reporting mechanism. Employees need a frictionless, blame-free way to report suspected credential compromise or unusual requests.

One Final Thought

Insiders are not always villains. Sometimes they are victims of coercion, fraud, or desperation. Other times, they are targets of cutting-edge fake media attacks.

Either way, the impact is the same: your data, your reputation, your money gone.

So ask yourself:

  • Do you really know your team members?
  • Could someone in your organisation be selling their credentials right now?
  • Would your team know if your CEO on a video call… wasn’t really your CEO?

If those questions make you uncomfortable, that’s a good thing. Discomfort sparks action.

And action is what we need.

Are insiders your biggest threat? DM me the word "insider" to understand and mitigate your insider threat.

Shadow AI: The Growing Threat No One in Your Business Is Owning

You have heard of Shadow IT unapproved apps, tools and cloud services used without IT's knowledge.

Now meet its more dangerous cousin: Shadow AI.

And if you think it’s not happening in your organisation it is already too late.

Shadow ai

What Is Shadow AI?

AI used in your business that:

  • Has not been approved
  • Has not been risk assessed
  • Is not monitored
  • Is quietly handling sensitive data

Examples?

  • A team feeding client data into ChatGPT to summarise reports
  • A junior analyst using Midjourney to draft creative content for a regulated brand
  • Developers plugging in open-source AI models to speed up internal tools with no security vetting
  • Executivess testing “automated decision-making” tools on HR or customer data

None of it logged. None of it governed. None of it secure.

And it’s growing faster than your policies can keep up.

Why This Is a Real Business Risk?

Shadow AI is not just a tech issue. It’s a data protection, reputational, and regulatory problem waiting to explode.

Here is why it should worry you:

  • IP Leakage: Staff are feeding proprietary strategies, code, and contracts into third-party tools. That data could be retained, reused, or leaked without your consent or visibility.
  • Model Bias and Ethics: Teams may be using AI tools that make decisions on hiring, lending, or prioritisation without understanding how biased or flawed those models are.
  • Regulatory Risk: Under GDPR, you are still the data controller even if a team sends personal data to an AI API you never approved. You own the fallout.
  • Security Exposure: Many free or low-cost AI tools have poor security hygiene. Some are already being exploited in the wild.

Let’s not forget AI generated content can be confidently wrong, offensive, or discriminatory. If it goes out under your brand, you own it.

Why Shadow AI Happens

People are not trying to cause harm. They are trying to get work done faster.

They see AI as a competitive edge. In many cases it is.

But without guardrails, they end up:

  • Sharing data they shouldn’t
  • Relying on outputs they do not question
  • Building processes you cannot audit
  • Making decisions you cannot defend

All under the radar of governance, IT, legal and compliance.

What Smart Businesses Are Doing Now

Admit it is happening. Stop pretending you can block it completely. Start by discovering where AI tools are being used across the business formally and informally.

Create a simple AI Use Policy. Not a 40-page PDF. A one-pager that explains what is allowed, what is not, and when to escalate.

Implement AI tool reviews. Like vendor due diligence, but for AI models and services. Look at security, data handling, model risks and usage terms.

Train teams. Help staff understand the risks especially around data leakage, decision-making, and hallucinated outputs. Teach them how to ask better prompts and spot when something looks wrong.

Log usage. If teams are using AI tools, track it. You can’t govern what you don’t know exists.

Build secure alternatives. If you want to stop Shadow AI, offer secure, approved, and well-supported AI solutions internally.

Final Word

Shadow AI is not a rogue actor in a hoodie. It is your top performing team trying to move faster. It’s your intern trying to impress. It’s your executive team experimenting without realising the risk.

You do not stop Shadow AI by banning it. You stop it by governing it, the same way you would any powerful tool.

And if you’re not sure where to start? DM me the word "shadow". We help scaling businesses get control of their AI risk before it controls them.

Culture & Ethics: The Missing Link in Cybersecurity

You can spend millions on technology. Deploy the latest AI tools. Hire certified talent.

And still suffer a catastrophic breach.

Why? Because cybersecurity is not just a technical challenge. It involves people. It starts and ends with culture and ethics.

Culture & ethics in cyber

Culture Eats Firewalls for Breakfast

Peter Drucker famously said:

“Culture eats strategy for breakfast.”

In cybersecurity, culture eats policies, frameworks and controls and sometimes, your business continuity.

An organisation with a strong culture of ethics, accountability and psychological safety is far more likely to:

  • Detect issues early
  • Report anomalies quickly 
  • Resist phishing and manipulation 
  • Take data protection seriously every day, not just during training week

Ethics: The Compass Behind Every Click

You don’t need to be in the ethics department to be ethical. You just need to have clarity: What’s right? What’s wrong? What’s acceptable? What’s not?

The absence of ethical guidance creates ambiguity. And in cyber security, ambiguity is deadly.

Strong ethical foundations:

  • Prevent shadow IT, shadow AI and poor data handling
  • Encourage whistleblowing without fear
  • Reduce compliance theatre 
  • Foster responsible AI and data use

Psychological Safety is Cyber Safety

If your team is afraid to admit mistakes, they won’t report them. If they're ridiculed for clicking a phishing link, they’ll hide it.

Cybersecurity thrives when people feel safe to speak up.

  • Psychological safety (a term coined by Dr Amy Edmondson) is linked to faster incident response and stronger collaboration. 
  • Google’s Project Aristotle found psychological safety was the #1 predictor of high-performing teams including IT security and operations.

What Strong Cybersecurity Culture Looks Like

Not pinging your staff with another 20-minute learning module. Not forcing a once-a-year training during Cyber Awareness Month.

But embedding security into how your team works, talks, and decides every day.

  • Security is part of onboarding, not just training 
  • Mistakes are shared and learned from, not punished 
  • Leaders model secure behaviour no shortcuts 
  • AI decisions are explainable, fair, and challengeable 
  • Data handling expectations are clear and lived

From Compliance to Trust

Ethical, secure culture isn't a checkbox exercise. It’s a competitive advantage.

In sectors like healthcare, finance, and professional services, trust is your most valuable asset. Lose it and clients, regulators and investors will lose confidence in you too.

What You Can Do Today

  • Audit your culture not just your controls 
  • Talk to your people understand what is unclear, risky or ignored? 
  • Create safe channels to report incidents and unethical behaviour 
  • Champion ethical leadership, it starts at the top 
  • Align AI use with your values and not just your roadmap

Final Word

You can’t firewall your way out of a culture problem. But you can lead your organisation to a safer, stronger future by building a culture where security and ethics are everyone’s responsibility.

Not just the CISO’s. Not just IT’s. Everyone’s.

Have you spent hard earned money on cyber security tech and still been hacked? Let’s talk. We help organisations align cybersecurity, ethics, and business strategy. Because compliance is the minimum. Trust is the goal. DM me the word "ethics".


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right