SANS Institute Unveils 5 Emerging Cyber Attack Techniques at RSA Conference 2025
The 2025 RSA Conference keynote session, led by SANS Technology Institute President Ed Skoudis, highlighted five new and sophisticated attack techniques that enterprises must prepare for in 2025. Each technique reveals a convergence of complex threat vectors, including misconfigured cloud environments, rising operational risk in industrial control systems, and emerging regulatory dynamics around artificial intelligence. The session's focus on anticipation, risk mitigation, and resilience underscores the growing need for cross-functional leadership in cybersecurity.
Key Takeaways:
- **Authorization Sprawl**: As cloud adoption accelerates, so does the complexity of identity and access management. Enterprises must address the risk of authorization sprawl by deploying browser-level endpoint controls, enabling visibility across cloud silos, and enforcing disciplined logging practices.
- **ICS Ransomware**: Ransomware actors are increasingly targeting industrial control systems, exploiting fragmentation between IT and OT teams to disrupt essential services. Enterprises must establish cohesive strategies that align cybersecurity, operational resilience, and cross-functional governance to mitigate this threat.
- **Destructive ICS Attacks**: Nation-state adversaries are targeting ICS systems with the intent of destruction, causing real-world harm. Organizations must prepare for kinetic threats with broad operational impact, including improving visibility into control systems and reevaluating safety protocol integrity.
- **Erased Forensic Artifacts**: Advanced threat actors are erasing or avoiding digital forensic artifacts, making post-breach analysis challenging. Enterprises must elevate their incident response maturity by capturing high-fidelity data, adopting advanced DFIR tools, and training teams to operate in data-constrained environments.
- **AI Regulatory Threats**: Proposed AI-related data privacy laws may limit the ability of security teams to use AI for threat detection, creating a regulatory tension that puts defenders at a disadvantage. Enterprises must anticipate and navigate these developments to maintain security posture without regulatory disruption.
Statistics:
- 45 minutes: the duration of the SANS Institute's RSA Conference 2025 keynote session
- 5: the number of emerging cyber attack techniques highlighted in the session
- 2017: the year SANS Institute predicted the rise of ransomware combined with cryptocurrencies
- 2019: the year Skoudis analyzed the rise of attacks from the cloud against the cloud
- 2023: the year Skoudis warned that threat actors would manipulate AI tools to amplify the velocity of ransomware campaigns
Sources:
- ( GlobeNewswire, 2025)
- (SANS Institute, no date)
- (SANS Institute, no date)
- (SANS Institute, no date)