Metomic CEO, Rich Vibert, gives his key predictions for data security in 2025
Over the years, weâve seen dramatic shifts in how organisations approach cybersecurityâfrom reactive measures to more proactive strategies, thanks to advancements in technology and a growing understanding of the risks we face.
The truth is, the challenges ahead arenât going away. In fact, as we move into next year, the stakes are higher.Â
But itâs not all bad news. With the right strategies in place, businesses can stay one step ahead, protect sensitive data, and avoid costly breaches.Â
So, what can we expect in 2025? Based on years of experience, and my ongoing research in the field, here are my key predictions for whatâs coming next in the data security space.
If thereâs one thing weâve learned from working with our customers, itâs that proper data classification is fundamental to effective security. When sensitive information is improperly stored or exposed, businesses are at serious risk.Â
Weâve even seen it firsthandâafter analysing more than six million Google Drive files, we found that 40% of them contained Personally Identifiable Information (PII). If that information isnât handled properly, it puts businesses at risk of a data breach.
By 2025, weâre going to see more organisations prioritising automated data classification systems to help tackle this problem. AI-driven tools will become a lot more common, and theyâll be able to automatically identify, tag, and secure sensitive data across cloud and SaaS environments.Â
These tools will help companies stay on top of the massive amounts of data being generated each day, ensuring that sensitive data is protected and reducing the risk of unnecessary exposure.
Hereâs something thatâs often overlooked: stale data. Itâs becoming a significant security issue, especially in collaborative work environments like Google Drive. In fact, weâve found that 86% of files in Google Drive havenât been updated in over 90 days. Even more concerning, 70% of them havenât been touched for more than a year. Thatâs a lot of unnecessary data taking up spaceâand more importantly, creating potential vulnerabilities that could be exploited.
As we move into 2025, I predict that security leaders will be laser-focused on reducing the amount of stale data across their SaaS platforms.Â
With regulatory requirements becoming stricter, managing stale data will become a critical part of compliance and risk reduction. Weâll see businesses taking a much more proactive approach, regularly auditing their systems to identify and remove outdated data.Â
This will become an essential part of their cybersecurity routineâessentially, digital housekeeping to ensure theyâre not leaving any unnecessary doors open for attackers.
Human error continues to be a major factor in data breaches. According to a 2024 Verizon report, 68% of breaches involved a ânon-malicious human element.â This means that while employees might not be intentionally causing harm, their actionsâwhether careless or unintentionalâare still putting data at risk.Â
Thatâs why, in 2025, weâll see businesses shifting their approach to cybersecurity by making it a shared responsibility across the entire organisation.
It wonât just be about the IT department doing all the heavy lifting anymore. Instead, businesses will start treating cybersecurity as something everyone takes responsibility for. Security leaders will push for more investment in employee education and tools that help staff spot and prevent threats in real-time.Â
Weâll see more businesses rolling out technologies that allow employees to act as a âhuman firewall,â empowering them to identify risks and take action before they escalate. This will help build a culture of data security from the ground up, where everyoneâfrom the C-suite to entry-level staffâis actively contributing to a safer work environment.
Insider threats are a major concern for organisationsâand with good reason. According to IBMâs 2024 Cost of a Data Breach Report, data breaches caused by insiders can cost businesses an average of nearly $5 million per incident. With the rapid adoption of SaaS and cloud platforms, monitoring data movement in real time is becoming even more crucial to protecting sensitive information.
In 2025, I expect businesses to double down on continuous monitoring solutions that can track data across cloud platforms and immediately detect unusual behaviour. These systems will automatically classify and protect sensitive data, ensuring itâs always secure.Â
By having these monitoring systems in place, businesses can spot potential threats early, whether from inside or outside the organisation. Itâs about staying one step ahead, preventing breaches before they have a chance to do any serious damage.
The healthcare sector is facing an escalating number of cyberattacks, many of which are disrupting patient care. According to a recent Ponemon Institute report, 69% of cyberattacks on healthcare organisations already impact patient care.Â
The cost of these attacks goes beyond dollarsâit can affect lives. In 2025, I predict that healthcare organisations will start focusing more on empowering their workforce to actively contribute to cybersecurity efforts.
This will mean more investment in educating staff at all levels to spot threats and respond to incidents quickly. Security isnât just ITâs job anymoreâevery employee plays a role in protecting sensitive data. This shift will help healthcare providers strengthen their defences and improve their ability to respond to cyber threats in real time.
The financial services sector has long been a target for cybercriminals. Attacks on financial institutions have cost up to $12 billion over the past two decades, according to the IMF, and the frequency of these attacks is only increasing. In 2025, weâll see banks and financial institutions investing more in their âhuman firewallâ approach to cybersecurity.
Similar to healthcare, this approach will involve more investment in employee education and the deployment of real-time threat detection tools. Employees will be equipped with the knowledge and technology needed to identify and prevent risks, turning the entire workforce into a proactive line of defence. With attacks becoming more frequent and sophisticated, this collective vigilance will be key to safeguarding sensitive financial data and reducing the risk of costly breaches.
As we move into 2025, data security will continue to be a critical concern for businesses. The strategies that worked in the past wonât be enough to keep up with the growing complexity of cyber threats. But the good news is that companies are becoming smarter, more proactive, and more strategic in their approach to protecting data.
From automating data classification and tackling stale data, to making cybersecurity a shared responsibility and addressing insider threats, the trends weâre seeing point to a future where businesses are better equipped to defend against evolving cyber risks. The companies that embrace these changes will not only safeguard their data but will also build trust with their customers and partners.Â
Cybersecurity may never be simple, but with the right strategies and tools in place, like Metomic, itâs possible to stay ahead of the curveâand keep data safe. Contact us today to explore how Metomicâs solutions can help you safeguard your data, reduce risks, and build a stronger security strategy.
â