2024 has been an extremely delicate year in terms of cybersecurity. The numbers have indeed confirmed an exponential growth of cyber threats, both globally and in Italy.
The data collected from various reports outline a landscape that is undergoing radical changes, influenced mainly by the widespread use of artificial intelligence (AI).
The numbers of 2024
The statistics leave no room for doubt: corporate networks are highly vulnerable. A recent study by NinjaOne found that 93% of Italian corporate networks could be compromised. In this scenario, relying solely on traditional countermeasures may no longer be sufficient.
SMEs seem to be the most at risk: nearly 40% of small and medium-sized enterprises that have suffered a cyber attack have experienced at least eight hours of downtime, with all the economic ramifications that ensue.
The Clusit Report 2024 also highlighted a 65% increase in attacks in Italy compared to the previous year, with an average of 232 incidents per month and high or critical severity in over 80% of cases.
On the global stage, ransomware continues to be in the spotlight, as it accounts for about 70% of serious cyber attacks, with an economic backlash of over $10.5 trillion.
The forecasts for 2025
Looking ahead to the future, forecasts indicate that emerging technologies, particularly AI, will have an even stronger impact. While we don’t have a crystal ball, we can outline five main threats for 2025, namely:
- Increase in the sale of databases affected by data leaks.
- IoT device vulnerabilities.
- Advanced techniques aimed at identity theft (using deepfake and other tools).
- Spread of automated disinformation campaigns.
- AI-enhanced social engineering, to create even more targeted and harder-to-detect phishing attacks.
Another very strong signal arrived at the beginning of 2025 with a groundbreaking piece of news: several companies had to urgently revise their defensive strategies following highly sophisticated ransomware attacks. These attacks leveraged advanced algorithms capable of cloning the communication style and voice of top executives within organizations, making them almost impossible to detect due to their striking resemblance to the original.
What to do:
In light of this data, a versatile and holistic approach must be taken that embraces the following elements:
- Solid update procedures and patch installation: keep systems and software up to date to address vulnerabilities.
- Multi-factor Authentication (MFA) to protect accounts even if credentials are compromised.
- Backup and disaster recovery: frequent backups of the most important data can reduce the impact of potential ransomware attacks.
- Ongoing training to stay up-to-date on the latest trends in social engineering techniques and to recognize phishing attacks.
- Threat Intelligence Solutions, advanced security tools that leverage AI to monitor computer systems in real-time to provide a rapid response to attacks. Some solutions also keep an eye on dark web forums to search for your data, in order to promptly inform you in case of theft or breaches.
- VPN: By connecting to a Virtual Private Network, you can protect your personal data and safeguard your privacy. One of the most sought-after pieces of information for hackers is your IP address, which will be concealed by the VPN. With a VPN, your IP address will be hidden, making it much more difficult for malicious individuals to track your location or access your sensitive information. Additionally, some of the best free VPNs can offer a good level of protection.
Final Considerations
The year 2024 should have served as a wake-up call for millions of users around the world. Cybercrime remains relentless, always ready to exploit even the slightest distraction for profit. Predictions for 2025 indicate that attacks will become even more sophisticated, which is why now more than ever, staying up to date on the latest digital security strategies is absolutely crucial.
