The fast-moving nature of cybersecurity threats requires constant attention to news and breach reports. Industry threat reports are plentiful, and they span a large variety of technology exposures and attacks. Yet few have a consolidated view and analysis of the overall cybersecurity threat landscape. As a result, cybersecurity leaders, boards and other C-level executives face challenges in prioritizing investments and resources.
Emerging and volatile threats are particularly challenging due to a lack of solid information. Rapid AI adoption enables new types of cyber attacks and creates new exposures, such as automation hijacks and prompt injection. Sixty-two percent of organizations reported at least one attack involving deepfakes in the last 12 months.1
Boards are worried. Eighty-one percent of non-executive directors view cybersecurity as a business risk, and 93% see cyber risk as a threat to shareholder value. Yet, less than 40% of them are confident or very confident in the ability of CIOs/CTOs (38%) and CISOs (37%) to protect enterprises from cyber threats.2
To best allocate cybersecurity resources this planning season, organizations must conduct a nuanced review of the threat landscape. Take a broad perspective that includes your cyber incidents to capture the true range of threats and drive support for long-term security initiatives.
Even though cybersecurity leaders are primarily responsible for mitigation of cybersecurity threats, other C-level executives need to be aware of the dangers so they can:
Better understand the reality behind cybersecurity events and news they see from external sources.
Have constructive discussions with the CISO about specific threats to their business.
Learn more about cyber-related business risks they own.
Make informed decisions regarding enterprise investment priorities.
Use CISO-Led Discussions of the ThreatScape to Improve Strategic Cybersecurity Initiatives
The Gartner ThreatScape matrix shown in Figure 1 helps CISOs quickly identify changing threats, communicate with the rest of the C-suite and align cybersecurity initiatives with business priorities. It combines feedback from, and analysis of, Gartner’s numerous interactions with security leaders across government and industry organizations, and dozens of threat intelligence reports covering threat trends from 2024 into the first half of 2025.
Figure 1: Gartner 2025 ThreatScape
Gartner (2025)

We categorize cybersecurity threats into six distinct areas along two axes:
Signal is the quality and volume of information available about a threat. The amount of signal varies greatly, and organizations often need to address threats before they have comprehensive information about them.
Advantage is who has the upper hand (the attacker, the defending organization or neither).
Attacker advantage typically includes newer or reactivated threats where attackers hold an edge.
No advantage is the most dynamic area; many attacks still succeed, but more mature and sufficiently funded organizations have built strong defenses and effective response capabilities.
Defender advantage includes better-understood threats, which have become less impactful over time as the cybersecurity industry has developed effective solutions and mature practices to handle them.
To support their strategic discussions with IT and business leaders, cybersecurity leaders should customize the ThreatScape presented in Figure 1 based on the maturity of their controls and the quality of signals they get. Enterprises must then tailor their responses to the different types of threats they face.
Build and Enhance Ability to Counter Critical and Emerging Threats
Even mature organizations need to address threats where attackers have a significant edge. CISOs should prioritize processes and tools to tackle deepfakes, safeguard custom-built AI applications and agents (see the Guard Against Automation Hijack as AI Agents Scale Up section below), and prepare for an eventual postquantum world. They’ll need cross-team collaboration to initiate these programs and must avoid wasteful investments amid complex external conditions or extreme marketing hype.
Guard Against Automation Hijack as AI Agents Scale Up
AI agents could bring AI and automation to the next level. But the hype surrounding them is changing the scale of adoption, creating new attack surfaces and increasing the threat of automation abuse. Organizations must prioritize the assessment of their exposure and preparedness.
AI agents are autonomous or semiautonomous software entities that use AI techniques to perceive, make decisions, take actions and achieve goals in their digital or physical environments.
It is too early to use threat intelligence reports and examples of real attacks to justify investments in securing these new AI agent automations. Cybersecurity leaders must collaborate with other C-suite executives to ensure safe adoption and design of AI-driven automations. They must not wait for AI agent-related cybersecurity incidents to occur or for industry reports to be available.
As a priority, cybersecurity leaders must discover and inventory newly available automations in existing enterprise software and custom-built AI agent initiatives so they can adapt cybersecurity practices to these use cases. There are many possible ways of categorizing agents. And increased “agent washing,” where vendors make inflated claims about offerings that are not really AI agents, makes assessment more difficult.
A simple way forward is to group agents based on their level of autonomy and the data they can access (see Figure 2). The higher the score on each measure, the greater the potential cybersecurity risk.
Figure 2: High-Level Agent Risk Categorization
Gartner

Organizations should draw these lessons from robotic process automation (RPA):
Attackers target traditional weaknesses such as software vulnerability, denial of service, poor authentication mechanisms, misconfiguration of assets and applications leading to information disclosure.
As many automations are employee-facing, hijacks are likely to come from injection of malicious content (e.g., via a malicious email), user misuse or abuse, or compromised credentials.
AI agents bring unprecedented complexity with new attack types such as direct and indirect prompt injections. As a consequence, organizations will need better formalized discovery and approval workflows, new incident response playbooks and increased ability to log and monitor automated processes.
Fortify Defenses Against Complex and Volatile Threats
Attackers and defenders are engaged in an active battle, with neither side having a definitive advantage. The threat landscape macrotrends change slowly, with the same types of attack at the top of many lists. The entire organization must work together to fight against supply chain attacks, ransomware and evolving account takeover threats targeting humans and machine identities.
For complex threats, CISOs need to start by reassessing their cybersecurity program’s maturity. New funding and ongoing executive support are vital for the necessary defense improvements. To get this backing, cybersecurity leaders must communicate about microtrends affecting these complex threats, and the required changes in defense strategy.
For volatile threats, the ability to gather “signals” about the reality of these rapidly changing risks is fundamental to support improved mitigation controls. Cybersecurity teams need to collect information by leveraging their threat intelligence and cybersecurity monitoring tools, and assess the extent of the threats for their own organization.
Maintain Vigilance Toward Established and Latent Threats
These challenges lie in the “defender advantage” column of the ThreatScape, but don’t get caught neglecting them. Established threats are more prominent. Cybersecurity teams are well prepared to counter them, the defense technologies are mature and the detection rate typically exceeds 90%. Social engineering and API abuse are prime examples because cybersecurity controls and incident response processes are highly developed.
However, evolving attack techniques require organizations to adapt their defenses against these threats: Phishing attempts become much more convincing when they leverage generative AI content creation capabilities. An organization’s APIs become critical attack surfaces as they drive many AI architectures and new business applications.
Latent threats come in multiple flavors, but are below the radar for most organizations.
Organizations should also prepare for the most unpredictable threats — emerging or reemerging — where no signal at all exists for now. To address these challenges, cybersecurity leaders must invest in a continuous threat exposure management (CTEM) program to enable resilience against unpredictable threats (see Use Continuous Threat Exposure Management to Reduce Cyberattacks).