Cyber Security Insights December 2025

Cyber Security Insights December 2025

Written by Bryan Altimas

How did we get here, writing the last Cyber Security Insights of 2025? This year seems to have passed by in a flash. Probably because cybersecurity risk and threats have evolved rapidly during the year.

I am not going to do the norm for this time of year and make my predictions for 2026. This year the threat actors have got rich by stealing identities and access credentials. Why change what is working? Companies holding the front door open for threat actors and allowing them in with valid access credentials will continue in 2026.

This month we will talk about:

  • The double edged sword of AI in defence and attack. As with all technology, AI is used to attack as well as defend.
  • Cyber security risk is business risk. A cyber attack impacts the company across the supply chain, finance, operations, marketing and risk, every department of the company.
  • The human side of incident response and burnout of the team.

I wish you all a merry Christmas and a happy New Year free from cyber incidents.

AI: The Double-Edged Sword Cutting Through Cybersecurity

AI isn’t just powering your business growth. It is also powering your enemies.

That is the stark truth facing every organisation right now from scaling fintechs and e-commerce players to global healthcare and legal teams, every organisation who generates and stores data.

In cybersecurity circles, we have always known that AI would transform the threat itself.

The Brain Behind the Breach

AI is not just a business tool. It’s been weaponised.

Attackers are building AI-powered phishing kits that adapt in real time to your tone of voice. They’re crafting deepfakes to bypass onboarding or identity checks. Deepfake videos are already holding rapidly arranged meetings with the "c-suite" to commit fraud. And they’re using automated vulnerability scanners that operate faster than most patch management cycles can handle.

These are just some of the ways threat actors are using AI:

  • WormGPT specifically built to write malware, and find exploits.
  • FraudGPT a black-hat alternative to ChatGPT, used to craft highly convincing phishing emails and fake landing pages, built to help cybercriminals commit fraud.
  • Deepfakes used in c-suite impersonation scams and recruitment fraud.
  • LLMs trained on exploit databases which enables attackers to build proof-of-concept code in minutes.
  • DarkBert is trained on data on the dark web enabling threat actors to quickly query compromised data to identify vulnerabilities, malware and ransomware, for example, to design and execute cyber attacks.

We are not just facing more attacks. We are facing more convincing, more automated, and faster-moving attacks.

What This Means for Businesses Like Yours

This is not theory. It is exposure and vulnerability.

Your attackers no longer need to be skilled coders. They just need prompts.

Meanwhile, your team may still be relying on:

  • Staff awareness training from 2021 or at least ignores the threat from AI
  • Siloed security systems that create separate alerts for login location and identity validation, for example.
  • Perimeter security that assumes trust
  • Vendor assessments done once a year
  • Slow manual response processes

All of which are sitting ducks in an AI-accelerated threat landscape.

AI for Defence But With Eyes Wide Open

Yes, AI also helps us detect patterns, automate response, triage incidents, and hunt threats.

But let’s not pretend we’re ahead.

If your AI use in cyber defence is limited to what came pre-packaged in a tool and is business focused … And your governance doesn’t account for the business risks AI introduces (bias, hallucinations, model drift, shadow AI, for example) and ignores the cyber security risks such as synthetic data abuse, deep fakes, model manipulation, data poisoning… Then you're not building resilience. You're building blind spots.

AI can help, but only with:

  • Proper controls over prompts, training data, and model access
  • Human-in-the-loop validation
  • Clear roles and accountability across IT, compliance, legal, and risk
  • Testing business technical controls
  • Cyber security threat testing for social engineering, deepfake, and LLM manipulation

What Needs to Happen Next

If you're a CISO, CTO, COO or Head of Risk reading this here’s my candid advice:

  • AI risk now Not just how you are using AI internally, but how your vendors are.
  • Assume attackers are using AI against you and audit your detection and response capabilities accordingly.
  • Bring AI under your governance umbrella ethical, legal and technical. Don’t leave it to IT and your cyber security team.
  • Shift from prevention to resilience You will be breached. AI will only speed that up. The question is: how fast can you bounce back?

Final Thought

AI is no longer a future threat. It's today's reality on both sides of the battlefield.

You don’t have to fear it.

But you do have to understand it, govern it, and build a cyber strategy that reflects the new speed and scale of risk.

AI has changed the game. Time to change the rules you’re playing by.

A conceptual, amusing digital illustration depicting a double-edged sword seamlessly transitioning from a glowing AI microchip on one side to a sharp, menacing blade on the other, poised to cut through a tangled network of digital data streams and abstract cybersecurity symbols. The colour palette is a striking contrast of vibrant, futuristic blues and greens for the AI side, against dark, ominous purples and reds for the attacking blade, symbolizing the dual nature of AI in cybersecurity. The style is sleek and modern with a touch of dramatic lighting to emphasise the tension between protection and threat.
AI generated image depicting the double edged sword of AI in cyber security

Cyber Risk Is Business Risk

It’s not just an IT problem. It never was.

Let’s stop treating cybersecurity like a back-office bolt-on. Or a cost centre. Or worse a line on the risk register that’s “covered by IT.”

In 2025, cyber risk is business risk.

It’s a reputational risk. A legal risk. A compliance risk. An operational continuity risk. And increasingly a deal-breaker. Just ask M&S and Jaguar Land Rover.

The Reality Today

When an attack hits:

  • Operations stop
  • Revenue stops
  • Investors lose confidence
  • Clients lose confidence
  • Suppliers do not get paid until operations start up
  • Regulators investigate
  • Trust evaporates

Just ask any business caught in the wake of a ransomware attack or supply-chain breach where the incident started with a compromised access credential, one compromised endpoint or one missed patch, and ended with:

  • Lost clients
  • Delayed or lost investment or even delayed IPOs
  • Fines under GDPR or NIS2, DORA, or any other regulation
  • Investigations and future increased scrutiny from regulators
  • Public apologies to the press
  • Internal sackings and external lawsuits

None of that is "just IT".

Why This Mindset Shift Matters

Boardrooms are waking up, especially in the wake of M&S and JLR. Smart CEOs and CFOs aren’t asking, “How secure are we?” They’re asking, “What happens to our business if we get hit?”

The stakes aren’t theoretical:

  • GDPR, DORA, NIS2, EU AI Act fines are calculated as a percentage of global revenue.
  • Cyber insurance providers are tightening terms, raising premiums or pulling out altogether.
  • Major clients, especially in finance, legal, healthcare and other regulated industries demand proof of cyber resilience before signing contracts.
  • Regular banking finance and funding rounds include due diligence on security posture.
  • Mergers & acquisitions now include due diligence on security posture.

Insecure = uninvestable. Insecure = uninsurable. Insecure = unreliable.

Cyber Belongs on the Board Agenda

If you are an established business or a business scaling fast, big client deals in the pipeline, heavy on data or cloud here's what I would tell your leadership team:

  • Cyber risk is a strategic risk. It belongs in the same breath as supply chain, financial controls, or ESG.
  • Your security posture can win or lose deals. Enterprise clients now assess your risk posture before they onboard you.
  • Security maturity is now an indicator of business maturity. If your board, ops and legal teams can’t speak cyber, that’s a red flag — not just for attackers, but for partners and buyers.
  • A good breach response plan is a growth enabler. Because resilience is now a KPI.

What Business Leaders Should Be Asking

  • What would a breach cost us operationally, reputationally, legally?
  • Who’s responsible for cyber risk at the top table?
  • Do we treat cyber as a project, or as a capability?
  • When was the last time we tested our incident response, really tested it?
  • Have we mapped our third-party exposure and dependencies?
  • Does our AI or automation strategy introduce new risks we have not accounted for?

Final Thought

The question isn’t if you'll face a cyber incident.

It’s whether your business is designed to survive it, recover from it and still grow.

If your cyber strategy is still locked in IT… It’s time to unlock it.

Move cyber out of the server room. Bring it into the boardroom.

Your growth and your survival depends on it.

A whimsical, conceptual illustration depicting cyber risk is business risk. The image depicts a stylised boardroom where a large, comical, but ultimately harmless, digital padlock is shown to be the sole anchor for a precarious skyscraper representing a business. The skyscraper is tilted at an amusing angle, with tiny figures of executives looking concerned but not panicked, suggesting the inherent instability of relying solely on IT for cyber security. The background is a soft gradient of blues and greys, with subtle circuit board patterns integrated into the clouds, symbolising the interconnectedness of cyber and business risks. The overall aesthetic is clean, modern, and slightly cartoonish, emphasizing the absurdity of treating cyber risk as solely an IT issue.
AI generated image for cyber risk is business risk

It’s Not Just Tech.

Incident Response Burnout Is a Business Risk.

When a breach hits, most companies rush to recovery mode..

But few stop to ask: What’s happening to the people responding to it?

  • The CISO who hasn’t slept in 36 hours
  • The wider incident response team managing cleanup and customer calls and vendor escalations all at once whilst working 18 hour days
  • The person handling comms from legal, PR, the board and regulators
  • Do not forget the impact on the person who may have made a mistake letting the attack happen

This isn’t just a technical fire. It’s a human burnout crisis.

And it’s costing you far more than you think.

The Human Cost of a Cyber Incident

Breaches are messy. The pressure is immense. But if your plan assumes:

  • Your team will “just respond”
  • Your tech stack will “show the logs”
  • Your leadership will “handle the noise”

…you are already behind.

What I’ve seen in incident response projects:

  • People are exhausted physically and emotionally
  • The pressure on incident response teams is immense
  • Decisions get made emotionally, not strategically
  • Communication is fraught between tech, ops, legal, comms
  • Post-incident fallout lingers for months (or years) — even after systems are back up

You patch the systems. But do you patch your people?

The Burnout Risk You’re Not Seeing

This is a governance issue not just an HR one.

  • Cognitive fatigue
  • Physical fatigue
  • Prolonged exposure to high pressure recovery
  • Staff churn = loss of institutional memory
  • PTSD-like symptoms = real-world consequence for repeat responders

The worst part? Most teams don’t talk about it.

They “white-knuckle” their way through the breach, then quietly burn out.

Or leave.

When Talent Walks, So Does Your Resilience

Your tools won’t save you if the humans behind them are already at breaking point.

If you're understaffed, undertrained, or unsupported that’s not resilience. That’s luck running out.

Burnout during or after breach isn’t just unfortunate. It’s a strategic weakness.

It shows your leadership didn’t plan for human limits. It proves your incident response is reactive, not resilient. It signals to regulators, clients and investors that you are unprepared.

How to Build Human-Centred Incident Response

Plan for fatigue. Build escalation paths, handover options, and team rotation into your IR plan.

Include wellbeing in your governance. Appoint a “human ops” lead during an incident someone to manage workloads, check-ins, and rest.

Debrief honestly. Not just what failed technically but what failed operationally, emotionally, and communicatively.

Run real simulations. Not just tabletop. Stress-test the humans, not just the tech.

Support after the breach. Time off. Psychological safety. Recognition. Lessons learned and not blame assigned.

Final Thought

When the breach hits, tech can help.

But people carry the load.

If you don’t build governance that protects them, supports them, and designs for their limits your incident response isn’t secure.

It’s a crisis waiting to happen.

Cyber resilience isn’t just about systems. It’s about sustainable response capacity built on human strength, not burnout.

A conceptual and amusing illustration symbolising the immense human toll of incident response burnout. The image depicts a cybersecurity professional, portrayed with exaggerated exhaustion, juggling multiple chaotic elements: glowing red alert icons, stacks of paperwork representing legal and PR demands, and a cascading flow of data streams. The background is a dimly lit, high-pressure environment, perhaps a war room, where the individual is surrounded by intangible pressures. The style is illustrative with a touch of dark humour, using a colour palette of muted blues and greys punctuated by urgent reds and oranges to convey stress and fatigue. The framing is a medium shot, focusing on the overwhelmed individual.
AI generated image depicting an overwhelmed incident responder heading towards burnout

Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right