HomeSecurityWhere should cybersecurity teams prioritize?

Where should cybersecurity teams prioritize?

During the Google Cloud Next 2025 it was said that cybersecurity teams need to adapt their approachesso they can respond more effectively to today's ever- changing threat landscape.

Where should cybersecurity teams prioritize?

The constant changes are due to four main factors:

  • Growing volume of criminal groups
  • Rising geopolitical tensions resulting in more attacks between states
  • New regulations on cybersecurity and data protection
  • Emergence of artificial intelligence and other technologies

Matt Rowe, Chief Security Officer at Lloyds Banking Group, said that because of this situation, “everything we do in terms of cybersecurity work has to change.”

Where should cybersecurity teams focus to protect their organizations?

Safety / Blind spot protection

Sandra Joyce, VP of Threat Intelligence at Google, explained that cybercriminals tend to target the “visibility gap” in organizations. That is, they target devices that often don’t support security tools like EDR. These include firewalls, virtualization platforms, and VPN solutions.

See also: Cybersecurity: The 10 mistakes you should avoid in 2025

“Threat actors identify blind spots and target those areas mercilessly,” the executive noted.

This tactic has been used by Chinese state hackers, who typically exploit zero-days in network and edge devices.

“This means security leaders need to consider zero-days across their entire technology stack,” Joyce added.

However, securing these devices directly is difficult. The focus should be on detecting lateral movement after these devices are compromised. Cybersecurity teams should be able to immediately detect anomalies in user behavior, such as credentials being used in unexpected ways. Identity and access management is also crucial for blocking hackers from accessing certain areas.

They should also be informed about the emergence of new zero-days and check all systems for potential security vulnerabilities.

Where should cybersecurity teams prioritize?

Strategies for combating insider threats

Another notable trend observed by Google is North Korean IT employees trying to get jobs at foreign companies. They use fake identities to trick target companies into hiring them. Once hired, these employees use their access to the organization to generate revenue for the North Korean regime and steal sensitive data for espionage purposes. There have also been cases where employees have stolen sensitive data to blackmail their former employers.

See also: Tips for creating a cybersecurity plan for your business

Combating insider threats, such as North Korean workers, requires a whole-of-company approach that includes departments like HR.

Organizations should improve their hiring practices, such as conducting rigorous background checks and conducting in-person interviews where possible. Additionally, effective identity and access management programs to limit third-party access.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Using AI to make your cybersecurity team more effective

During the Google Cloud Next event, some new AI solutionsthat significantly reduce the workload of cybersecurity professionals. One of these solutions is an alert triage agentthat can conduct investigations on every security alert for customers.

“Analysts in a classic SOC are overwhelmed by the amount of work – investigating low-key true positives. They do a lot of work to get to a dead end, with no malicious activity,” an executive explained.

The use of automation and artificial intelligence can help cybersecurity teams devote their time to the most sophisticated threats.

Using AI safely

Organizations are rapidly deploying artificial intelligence tools to boost productivity and competitiveness. However, there is often a lack of control over the data fed into AI agents, rendering traditional governance strategies ineffective.

There is also the issue of trust in data obtained from artificial intelligence tools (e.g. misconfigurations).

It is vital for organizations to create a single access layer through which all data in the organization passes.

Saurabh Tiwary, Vice President and General Manager at Google Cloud, highlighted some of the ways AI can help solve data governance challenges in technology. This includes rapidly analyzing documents to give them the appropriate sensitivity label.

AI Agent Marketplace allows customers to browse, purchase, and manage AI agents that have been classified as "safe."

See also: Cybersecurity for small businesses and startups

cybersecurity teams
Where should cybersecurity teams prioritize?

Addressing attacks related to credentials in the Cloud

Compromised credentials remain one of the primary methods used to compromise data in the cloud.

One of the main causes of credential theft is the rise of infotealers, malware that collects credentials which are then sold on criminal marketplaces.

Basic authentication practices remain vital – such as not reusing passwords and using multi-factor authentication (MFA).

By prioritizing the above, cybersecurity teams can strengthen the security of their organizations. It is essential that experts are constantly informed about new threats and act accordingly.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS