Introduction
Do you feel like your organisation is caught between increasingly complex cybersecurity threats and the latest landmark regulations, such as NIS2, DORA, and the EU AI Act? Many companies are at this point right now, realising they need not only robust defence but also resilience.
To help you face both security threats and legal requirements, we explore the five most pressing cybersecurity trends. You will learn about the challenges associated with each trend and see how Google Cloud’s advanced security solutions can help you overcome them. Additionally, we outline Devoteam’s approach to making the most of these tools.
5 Cybersecurity Trends in 2025
Based on 2024-2025 observations and projections, we have identified 5 key Cybersecurity trends:

Let’s dive deeper into each of these trends.
Trend 1: Evolving Ransomware/Extortion
The Challenge
Ransomware has morphed into a multifaceted extortion threat, employing tactics far beyond simple
encryption to include data exfiltration, public leaks, denial-of-service attacks, and direct harassment. These attacks severely impact operational availability, data confidentiality, business continuity, and organisational reputation. The regulatory pressure is intense, with NIS2 and DORA mandating robust business continuity and disaster recovery (BCDR) capabilities, while GDPR imposes strict breach notification requirements following data exfiltration.
Google Cloud’s Response
To counter ransomware attacks, Google Cloud offers a formidable suite of security tools. Google Security Operations (SecOps) enhances the detection of ransomware activity through sophisticated log analysis and enables rapid, automated responses to contain threats effectively, helping meet NIS2/DORA’s stringent incident reporting timelines. Proactive defence is bolstered by Google Threat Intelligence (GTI) and Mandiant, which deliver crucial insights into ransomware tactics, techniques, procedures (TTPs), and active threat actors, enabling preventative measures and informed incident response. Mandiant’s expertise proves invaluable in post-attack recovery and resilience building. Foundational to recovery is Google Cloud Storage coupled with robust Backup and Disaster Recovery solutions, essential for restoring data and operations, directly addressing NIS2/DORA BCDR requirements. Furthermore, Data Loss Prevention (DLP) capabilities help detect and block the exfiltration of sensitive data – a key component of double extortion tactics.
Devoteam’s Enhancement
Devoteam translates these powerful Google Cloud tools into effective, tailored defences. Our experts configure and manage SecOps, GTI, Mandiant, and DLP within our dedicated SOC, ensuring optimal performance and rapid response. We design and implement comprehensive BCDR strategies aligned with NIS2 and DORA requirements. With our Security Assessment Accelerator, we proactively identify the most common vulnerabilities exploited by ransomware groups. The SecOps Jumpstart Accelerator, on the other hand, is specifically designed to help organisations quickly deploy and configure Google SecOps, accelerating advanced detection and threat response.
Use Case: Servinform Strengthens Security and Streamlines Operations
Servinform, a prominent Spanish business process management firm, needed to upgrade its security infrastructure to meet evolving audit and regulatory demands. Collaborating with Devoteam, Servinform implemented Google SecOps (Chronicle SIEM and SOAR) to centralise security event management and automate threat responses without replacing existing tools like CrowdStrike EDR. This integration enhanced control and visibility over their security landscape, both on-premise and in the cloud.
The key outcomes? Optimised incident response times, streamlined compliance processes, and reduced reliance on external parties for security management. Servinform now benefits from a more robust and efficient security posture, is better prepared for future cybersecurity challenges, and has ongoing plans to refine threat detection and response automation further. Read the full story
Trend 2: Identity as the Epicentre
The Challenge
Identity, encompassing both human and non-human credentials, has become the primary battleground for cyberattacks. Compromised credentials, often obtained through sophisticated phishing, social engineering, MFA bypass techniques, or exploiting misconfigurations, grant attackers initial access and facilitate lateral movement. Regulatory frameworks recognise this criticality: NIS2 and DORA mandate strong identity and access management
(IAM), GDPR links access control failures directly to data breaches, and the EU AI Act requires secure access mechanisms for AI systems.
Google Cloud’s Response
Google Cloud directly addresses identity risks through multiple layers:
■ Identity and Access Management (IAM) provides fine-grained resource access control, enforces
least privilege principles, and ensures robust role management — all essential for NIS2, DORA, and
GDPR compliance.
■ Chrome Enterprise Premium extends protection to endpoints and browsers with context-aware access controls aligned to Zero Trust principles, enhanced phishing and malware protection, and security for both managed and unmanaged devices.
■ Security Command Centre (SCC) continuously monitors and identifies misconfigurations, excessive permissions, and identity-related risks across the cloud environment, offering early detection and actionable remediation recommendations.
■ Google SecOps strengthens detection by identifying anomalous login behaviours and privilege escalation
attempts.
■ Mandiant Threat Intelligence delivers continuous insights into emerging identity-focused attack techniques and threat actor behaviours.
Devoteam’s Enhancement
Devoteam ensures Google Cloud’s identity security tools are deployed as part of a unified strategy. We design compliant IAM frameworks, configure Chrome Enterprise Premium for secure, context-aware access, and fine-tune SCC to detect misconfigurations and identity risks. By integrating Google SecOps and Mandiant into our SOC workflows, we enable proactive detection and response to identity-focused threats.
Trend 3: Intensifying Risks in Cloud & Connected Ecosystems
The Challenge
The shift to the cloud and the proliferation of interconnected devices (IoT, OT, Edge) dramatically expand the potential attack surface. Cloud misconfigurations remain a primary cause of breaches. Meanwhile, software supply chain attacks and vulnerabilities in third-party components pose significant threats to the entire ecosystem. Regulators are responding, with NIS2 and DORA emphasising third-party risk management (TPRM) and supply chain security. The GDPR holds organisations accountable for their data processors. Frameworks like ISO 27001
and NIST demand controls for cloud environments and supplier relationships.
Google Cloud’s Response
Google Cloud offers powerful tools for managing risk across complex environments. Security Command Center (SCC) serves as a central hub, providing unified visibility and control over the security posture across Google Cloud. It continuously identifies misconfigurations, manages vulnerabilities (including within cloud-native components like containers), and detects threats, directly supporting NIS2/DORA requirements for risk management and supply chain security oversight. Robust IAM controls limit the blast radius if a component is compromised. Meanwhile, Data Loss Prevention (DLP) safeguards sensitive data residing in cloud storage or databases like BigQuery. Google Cloud also actively addresses software supply chain risks through initiatives like Assured Open Source Software (Assured OSS).
Devoteam’s Enhancement
Devoteam provides the expertise to navigate cloud and ecosystem complexity securely. Our consultants leverage the Security Assessment Accelerator to ensure secure cloud configuration from the outset. We implement and manage SCC to provide clients with unified risk visibility and actionable insights. Devoteam advises on and helps implement comprehensive TPRM strategies aligned with NIS2 and DORA expectations. Additionally, the company has a deep expertise in securing cloud-native applications and architectures against emerging threats.
Trend 4: Strategic Imperative for Cyber Resilience
The Challenge
The prevailing wisdom in cybersecurity now accepts that preventing 100% of attacks is an unrealistic goal. Consequently, the strategic focus has shifted towards cyber resilience. The ability to prepare for, withstand, respond to, and recover from incidents swiftly and effectively embodies an “assume breach” mindset. This is no longer just best practice; it’s a regulatory mandate. NIS2 and DORA explicitly require comprehensive resilience strategies encompassing risk management, robust incident handling, effective business continuity and disaster recovery (BCDR), and regular testing (including Threat-Led Penetration Testing under DORA). GDPR also supports resilience through its requirements for ensuring data availability and restoration capabilities.
Google Cloud’s Response
A robust technological foundation for creating cyber resilience is a core part of the Google Cloud platform. Google SecOps is central to effective detection and response, enabling security teams to identify and react to incidents faster. Mandiant brings world-class incident response expertise and threat intelligence, along with TLPT capabilities crucial for meeting DORA requirements. Security Command Center (SCC) facilitates continuous monitoring and ongoing risk assessment, vital for maintaining a resilient posture. Foundational recovery capabilities are provided by Google Cloud’s Backup and Disaster Recovery services.
Devoteam’s Enhancement
Devoteam operationalises resilience using Google Cloud tools. We work with organisations to design and implement comprehensive resilience strategies covering the full lifecycle. It includes preparation, protection, detection, response, recovery, and adaptation. Our dedicated SOC provides 24/7 monitoring and expert response capabilities. Devoteam conducts readiness assessments, develops tailored incident response plans, performs necessary testing (including TLPT where required), and offers Managed Services for the ongoing management and continuous improvement of cyber resilience.
Trend 5: AI in Cybersecurity — How to win the battle against AI-Powered threats
The Challenge
Artificial Intelligence presents a paradigm shift in cybersecurity, acting as both a potent weapon for attackers and a powerful tool for defenders. Adversaries leverage AI to increase the scale, speed, and sophistication of attacks, automating vulnerability discovery, crafting hyper-realistic phishing campaigns, and generating convincing deepfakes. This offensive use of AI directly challenges existing security controls and incident response timelines mandated by regulations like NIS2 and DORA. Simultaneously, AI enhances defensive capabilities through advanced threat detection and automated response. However, securing AI systems themselves is critical, facing scrutiny under GDPR (regarding data used for training and potential breaches), ISO/NIST frameworks, and most notably, the EU AI Act, which imposes strict security, robustness, and governance requirements on high-risk AI systems.
Google Cloud’s Response
Extensive use of AI strengthens Google Cloud’s defences. Simultaneously, Google provides tools to secure AI deployments. Google SecOps, Google Threat Intelligence (GTI), and Mandiant all incorporate sophisticated AI and machine learning algorithms for advanced threat detection, predictive intelligence (understanding AI-driven attack patterns), and automated response orchestration. These capabilities are crucial for outpacing AI-powered threats. Additionally, Chrome Enterprise Premium helps protect users from AI-generated phishing and malicious web content.
Devoteam’s Enhancement
Devoteam provides the expertise to use defensive AI effectively and navigate the complexities of securing AI systems. Our teams are skilled in deploying and managing AI-powered security tools like Google SecOps, maximising their threat detection and automation potential. We advise organisations on secure AI development and deployment practices, ensuring alignment with the EU AI Act and other relevant standards. Furthermore, Devoteam leverages AI within its own SOC operations for enhanced threat hunting, anomaly detection, and accelerated analysis.
Conclusion
To sum up, the five trends detailed in this article represent a fundamental shift in cybersecurity. Meeting these challenges effectively means closing the gap between having security technology and having an optimised security strategy.
Google Cloud provides the engine, Devoteam provides the expertise to drive it. By leveraging our accelerators, managed SOC services, and deep consulting knowledge, we ensure that Google’s powerful security tools are deployed for maximum impact. We help you translate the complex requirements of NIS2 and DORA into a practical, resilient, and manageable security program.
Cyber Threats Are Evolving. Your Defence Must Too.

The regulatory landscape is getting more complex, and cyberattacks are more sophisticated than ever. Are you prepared to navigate both? Download your free legal guide to cybersecurity with Google Cloud.
- Proactively mitigate emerging cybersecurity risks.
- Achieve and maintain compliance with regulations like NIS2, DORA, EU AI Act and GDPR.
- Move from a reactive to a proactive stance against emerging threats..
- Optimise security operations to increase efficiency and reduce alert fatigue.

