in an era of AI and tightening regulation Driven in part by the rapid rise of artificialintelligence (AI), the variety and intensityof cybersecurity threats to organizations Today’s bad actors have access to increasinglysophisticated methods—including deepfakes anddomain generation algorithms (DGAs)—posing agrowing challenge for businesses to anticipate anddefend against. At the same time, chief informationsecurity officers (CISOs) and their teams must In Q1 2025, CSC commissioned independentresearch among CISOs, chief information officers(CIOs), and other senior IT professionals tounderstand more about their current concerns. We setout to understand evolving cyber threats, the currentstate of IT security budgets, how cybersecurity Our study found almost three quarters (70%) ofrespondents believe that security threats will increasein the year ahead; almost all (98%) predict anincrease in the next three years. Almost nine in 10 There’s no doubt that CISOs will continue to be challengedby security threats. Our job is to keep developing better OUR EXPERTS Ihab ShraimChief Technology Officer,CSC’s Digital BrandServices Nina HrichakVice President ofEMEA AccountManagement, CSC's Mark EgglestonCSC Chief Information Mark FleggSenior Director of Technology,Security Products andServices, CSC's Digital What CISOs are saying: A snapshotWe surveyed 300 CISOs, CIOs, and heads of IT in Q1 2025 and found that cybersecurity threats are materialrisks that are becoming more challenging. Domain and DNS threatswill dominate the threat landscape The top three security threats in 2024 were cited as: 4.Ransomware and malware5.Social media cyber attacksand defamation6.Phishing and social Domain and domainname system (DNS) Cybersquatting DDoS attacks The top three expected threats over the next three years are: Ransomwareand malware4.DDoS attacks5.Social media cyber attacksand defamation6.Phishing and social Domain andDNS hijacking The adoption of outsourcing servicesfor cybersecurity is widespread but AI will have a significant impact oncybersecurity Almost nine in 10 (87%) believe that DGAs powered byAI pose a threat. Almost half our respondents said they mainlyuse in-house systems, processes, and staff, butoutsource to specialists to a limited degree. Just under a fifth (18%) in-source exclusively. The vast majority (97%) said they’re concernedabout giving AI-based third-party systems access tocompany data. Almost a third (30%) outsource to specialists butalso use in-house resources. Cyber threats areevolving—and only CISOs face a rising tide ofever-more sophisticatedcyber threats. Worse, theypredict the level of security Almost one in 10 (9%) of our respondents saidthe risks presented by cybersecurity threatswere “critical” in 2024. Three fifths (58%) ratedthem as significant, meaning that two thirds(67%) thought risks were material. A further “CISOs have needed to deal with hugeperiods of transition, so it’s understandablethey feel the risks are so serious,” says Mark Flegg, senior director of Technology,Security Products and Services, CSC's “As organizations began moving core systems away from in-house,on-premise infrastructure to the cloud, they opened up their ITenvironments to new threats. A perfect example is subdomainhijacking, or subdomain takeover, which wasn’t as much of aconcern 20 years ago—when firms ran their own data centers and The risks presented by cyber threatswill worsen in the months andyears ahead, said our respondents.Almost three quarters (70%) expectan increase in 2025, with 5% sayingthe rise will be “significant;” 98% “What we’re seeingis that attacks suchas ransomware don’thappen in isolation,and that bad actorscan then go on to steal The rise of powerful AI-based capabilities means somedomain-related threats are becoming more potent.For example, cybercriminals can use AI to scan for Meanwhile a big challenge for CISOs is that most of thethreats they have always faced are still causing problems,while the list of new potential attacks and methods Mark EgglestonCSC Chief Information Security Officer Cyber threats are growing more sophisticated, oftencombining multiple techniques to improve their chancesof success. Many begin with some form of socialengineering, sometimes paired with a tactic like lookalike Other examples include DNS tunneling to bypasssecurity measures and transmit malware across anetwork, or compromising a third-party supplier’s system Domain-related threatsdominate CISOs’ concerns. The top three security threats last year were named by respondents ascybersquatting, domain and DNS hijacking, and DDoS attacks. Only 22% said they have the “right tools” in place. It’s clear that CISOs feel theycould do more to counter domain-based threats—and the need to strengthenresources is becoming more critical. Three-quarters said they were"somewhat confident" about theircompany's ability to mitigatedomain attacks; just 7% said theywere "very confident."