> **来源:[研报客](https://pc.yanbaoke.cn)** ```markdown # Global Cybersecurity Outlook 2025 Summary ## Core Content The **Global Cybersecurity Outlook 2025** report highlights the increasing complexity of the cyber landscape, driven by geopolitical tensions, technological advancements, and the growing sophistication of cyber threats. It emphasizes the need for a security-first mindset among leaders to address these challenges and build resilient ecosystems. ## Main Trends and Key Findings ### 1. **Cyber Inequity and Complexity** - The complexity of cyberspace is exacerbating the gap between organizations that are well-prepared and those that are not. - **72%** of GCO survey respondents reported a rise in cyber risks. - **35%** of small organizations believe their cyber resilience is inadequate, up from 5% in 2022. - In contrast, **large organizations** reporting insufficient cyber resilience have nearly halved. - **Regional disparities** are evident: only **15%** in Europe and North America lack confidence in their country's ability to respond to major cyber incidents targeting critical infrastructure, while **36%** in Africa and **42%** in Latin America do. ### 2. **Cyber Threat Landscape** - **Ransomware** remains the top organizational cyber risk, with **45%** of respondents ranking it as a top concern. - **Cyber-enabled fraud** is the second-highest organizational risk, and **identity theft** is the primary personal cyber risk. - **GenAI** is significantly enhancing the capabilities of cybercriminals, enabling more sophisticated and scalable attacks. - **47%** of organizations cite adversarial advances powered by GenAI as their primary concern. - **42%** of organizations experienced a successful social engineering attack in the past year, a number that is expected to rise with AI adoption. ### 3. **Supply Chain Vulnerabilities** - **54%** of large organizations identify **third-party risk management** as a major challenge. - Supply chain complexity and lack of oversight contribute to a **more opaque and unpredictable risk landscape**. - **72%** of organizations report that **supply chain attacks** are a growing concern, with vulnerabilities introduced by third parties. ### 4. **Regulatory Fragmentation** - **78%** of private sector leaders believe that cyber and privacy regulations reduce risk in their ecosystems. - However, **two-thirds** of respondents cite the **complexity and proliferation of regulations** as a challenge. - **Regulatory fragmentation** across jurisdictions complicates compliance efforts for organizations. ### 5. **Cyber Skills Gap** - The **cyber skills gap has increased by 8%** since 2024. - **Two out of three** organizations report moderate-to-critical skills gaps. - **Only 14%** of organizations are confident in having the necessary people and skills to manage cyber risks. ### 6. **Collaboration and Response Strategies** - **Collaboration between public and private sectors** is crucial for addressing the complexity and risks in cyberspace. - **Criminal-as-a-Service (CaaS)** platforms are enabling non-experts to engage in cybercrime, lowering barriers to entry. - **INTERPOL** and other global law enforcement agencies are emphasizing the need for **new partnerships** and **collaboration** to disrupt cybercriminal activities. ### 7. **Emerging Threats to Critical Infrastructure** - Cyber threats are no longer limited to data security but now extend to **human safety** and **critical infrastructure**. - **Ukraine** is highlighted as an example of how cyber and physical attacks on sectors like energy, telecommunications, and water can have severe consequences. - **Critical infrastructure** such as **water facilities** is at risk from cyberattacks that can disrupt operations and endanger public safety. ## Key Insights - **Cyber resilience** is becoming a key differentiator between organizations. - **AI** is both a tool for defense and a weapon for cybercriminals, increasing the complexity of threat detection and response. - **Regulatory compliance** is a growing challenge due to the fragmentation of international standards. - **Supply chain security** is a critical area for improvement, as it is a major source of vulnerabilities. - **Public sector organizations** are disproportionately affected by cyber risks and lack the necessary talent to address them. - **Social engineering attacks**, especially those powered by GenAI, are becoming more frequent and harder to detect. - **Collaboration** across sectors and jurisdictions is essential for building a resilient cyber ecosystem. ## Conclusion The report underscores the need for a **comprehensive and unified approach** to cybersecurity, emphasizing the importance of **strategic collaboration**, **investment in AI-driven security solutions**, and **addressing the skills gap**. It calls for **proactive measures** to disrupt cybercriminal networks and protect both digital and physical infrastructure from emerging threats. ## Appendix: Methodology The report is based on a survey of **Global Cybersecurity Outlook (GCO)** respondents, including data from the **Annual Meeting on Cybersecurity 2024**, and includes insights from industry leaders and experts. The methodology involves analyzing trends in cyber threats, risks, and organizational preparedness across different regions and sectors. ## Contributors and Acknowledgements The report is a collaborative effort involving experts from the **World Economic Forum**, **Accenture**, **Palo Alto Networks**, **Fortinet**, **INTERPOL**, and others. It acknowledges the contributions of **industry leaders**, **government agencies**, and **cybersecurity organizations** in providing data and insights. ## Endnotes The report includes references to various studies, surveys, and expert opinions to support its findings and recommendations. ```