Report by World Economic Forum
Global Cybersecurity Outlook 2025
Key Findings
36% of respondents in Africa and 42% in Latin America lack confidence in their country's ability to respond to major cyber incidents targeting critical infrastructure.
54% of large organisations identified supply chain challenges as the biggest barrier to achieving cyber resilience.
49% of public-sector organisations indicate they lack the necessary talent to meet their cybersecurity goals, which is a 33% increase from 2024.
Only 14% of organisations are confident that they have the people and skills they need today.
The cyber skills gap has increased by 8% since 2024.
66% of organisations expect AI to have the most significant impact on cybersecurity in the year to come, but only 37% report having processes in place to assess the security of AI tools before deployment.
38% of public-sector organisations report insufficient resilience, compared to 10% of medium-to-large private-sector organisations.
Nearly 60% of organisations state that geopolitical tensions have affected their cybersecurity strategy.
72% of respondents report an increase in organisational cyber risks.
36% of respondents in Africa and 42% in Latin America lack confidence in their country's ability to respond to major cyber incidents targeting critical infrastructure.
42% of organisations reported phishing and social engineering attacks in 2024.
One in three CEOs cite cyber espionage and loss of sensitive information/intellectual property (IP) theft as their top concern.
35% of small organisations believe their cyber resilience is inadequate, which is a sevenfold increase since 2022.
47% of organisations cite adversarial advances powered by generative AI (GenAI) as their primary concern.
The proportion of large organisations reporting insufficient cyber resilience has nearly halved.
45% of cyber leaders are concerned about disruption of operations and business processes.
More than 76% of chief information security officers (CISOs) at the World Economic Forum’s Annual Meeting on Cybersecurity in 2024 reported that fragmentation of regulations across jurisdictions greatly affects their organisations’ ability to maintain compliance.
Two out of three organisations report moderate-to-critical skills gaps.
15% of respondents in Europe and North America lack confidence in their country’s ability to respond to major cyber incidents targeting critical infrastructure.