From disruptive ransomware attacks impacting major retailers and manufacturers to large- scale outages across cloud service providers, 2025 year highlighted how operational, supply-chain and platform dependencies continue to amplify cyber risk.
Incidents such as those affecting Marks & Spencer, Jaguar Land Rover, npm’s open-source ecosystem and critical telecommunications providers demonstrated how single points of failure can cascade through entire industries.
At the same time, 2025 showed how attackers are rapidly developing their capabilities. The first documented case of an AI-orchestrated espionage campaign illustrated how artificial intelligence (AI) is being leveraged by sophisticated threat actors.
This reinforces the need for structured, trustworthy approaches to AI governance.
As always, our Top 10 is not a ranking but rather highlights some of the most important incidents of 2025 that have caused widespread disruption and/or had a significant financial impact.
This year’s Bonus Track explores emerging AI risk- management frameworks, with a deep dive into the NIST AI Risk Management Framework, highlighting how organisations can integrate governance, oversight and resilience into their AI strategies.
Together, the incidents of 2025 reflect an increasingly interconnected threat landscape – one that demands proactive, coordinated and adaptive cybersecurity practices.
As the world digitises at pace, the threat of cyber-attacks increases exponentially.