AI, Zero Trust and Resilience: Three Security Priorities for 2025
This post is for CISOs, CTOs and the executives who sponsor their programmes. In 2025 three themes compete for the same budget: AI in security operations, Zero Trust and cyber resilience. They work best as one programme with a shared owner.
AI in security operations
Defenders are putting AI into the SOC for alert triage and early investigation. In ISC2’s 2025 AI Pulse Survey, 30% of respondents said their teams had already integrated AI security tools into operations, and a further 42% were evaluating or testing them. ISC2’s definition of “AI security tools” is broad (AI-enabled products, generative AI and agentic AI for automated action), so the figure does not measure autonomous agents specifically.
My advice is to pilot on a narrow task such as triage and prioritisation, and to review the tool’s decisions before you widen its autonomy.
Zero Trust
Zero Trust replaces the assumption that anything inside the network is trusted with continual verification of identities, devices and requests across every boundary. Adoption is wide but shallow. A Gartner survey from the fourth quarter of 2023 found that 63% of organisations had fully or partially implemented a strategy, and the approach typically covered half or less of the environment.
The same survey reported that 35% of organisations had encountered a failure that disrupted their implementation, which is a narrower finding than 35% of initiatives failing. Scope and execution are the harder problems, so I would run it this way:
- Start with the highest-value assets.
- Apply least privilege, MFA and continuous context checks.
- Add micro-segmentation where the risk justifies it.
- Run it as a phased programme owned jointly by security, IT and the business.
Cyber resilience
Gartner’s 2025 CISO leadership survey (1,150+ CISOs, March 2025) added cyber resilience as an option for the first time, and it immediately became the top functional priority.
Resilience means detecting and containing an incident quickly, then restoring service. In practice:
- Build incident response and continuity into the architecture.
- Simulate breaches and run tabletop exercises.
- Track recovery metrics, such as time to detect and time to restore.
Putting them together
AI shortens detection, Zero Trust limits how far an intruder can move, and resilience limits the damage when both are bypassed. The CISO, CTO and board need to agree on risk appetite and resourcing, otherwise each theme is funded and measured separately and the gaps between them go unowned.