The State of Internet Security in 2025

The fundamentals of securing the Internet have not changed: defenders must succeed every time while attackers only need to break through once. What has shifted is the scale and sophistication of the attempts. Over the past year, Cloudflare recorded and mitigated the largest DDoS attacks ever seen—three separate times. The same period included the largest global election cycle in history, with more than half the world's population eligible to vote, and the digital reflections of geopolitical conflict were visible throughout.

The cost of cyberattacks is projected to reach $10.5 trillion in 2025. As AI adoption accelerates, threat actors are becoming more agile, and the consequences of breaches are increasingly tangible: state-sponsored campaigns and assaults on critical infrastructure are no longer hypotheticals. Security teams are facing a higher volume of attacks alongside more complex threats that carry real-world impact.

What Security Leaders Are Up Against

Conversations with security leaders across forums like the World Economic Forum and industry conferences reveal consistent pain points that shape the current threat landscape:

  • Complexity: Fragmented technology stacks, multi-cloud environments, and talent shortages have made complexity the primary enemy of security. Teams struggle with limited situational awareness, increased operational overhead, and difficulty modernizing.
  • Artificial Intelligence: Organizations are deploying AI faster than they can train their workforce on the risks it introduces. Security teams are tasked with securing AI models and protecting sensitive data, often without additional budget or resources.
  • Security blind spots: Remote work and cloud migration have expanded the attack surface. Maintaining visibility across distributed environments is a persistent challenge, and attackers are quick to exploit those gaps.
  • Trusted vendors: Supply chain incidents continue to rise. Vulnerabilities in third-party components can cascade across the digital ecosystem, requiring security teams to account for risks extending far beyond their own perimeter.
  • Detection velocity: The time to detect an intruder remains too long. Despite investments in monitoring tools, sophisticated adversaries can operate undetected within networks for extended periods.

The consensus is that layering more point solutions is not a sustainable strategy. What security leaders need are integrated platforms that reduce complexity while offering comprehensive protection and visibility.

Security Week 2025: What to Expect

This week's announcements focus on how Cloudflare's own security organization—operating as Customer Zero—has influenced product development to address the challenges above.

Preparing for Post-Quantum Cryptography

Quantum computing will fundamentally change how communications are secured. Collaborative work among NIST, Microsoft, Cloudflare, and other computing companies aims to establish robust, standards-based solutions. Cloudflare is announcing advancements to its cloud-native quantum-safe zero trust offering—the first of its kind—designed to future-proof corporate network traffic without complicating adoption.

unnamed

Contextual Threat Intelligence at Scale

Most threat intelligence arrives without context, which makes it difficult to respond effectively. To address this, Cloudflare is launching a threat events platform that delivers real-time cyber threat intelligence based on attacks observed across its global network. This gives customers access to a comprehensive view of threats occurring across the Internet, along with self-service tools to gain contextual insights into who is attacking, how, and why.

This forensic layer goes beyond raw data. It enables security practitioners to identify patterns and tactics, revealing potential weaknesses in defenses before they can be exploited. Stopping threats at the gate is not enough; staying ahead of the next vector requires dissection of the threats that have already been neutralized.

AI-Driven Security at the Edge

AI remains the dominant topic across industries, with the core concern being how to secure AI investments. Cloudflare's engineering teams have focused on protecting AI models, data, and applications. This week, the product team is sharing how new Firewall for AI capabilities and enhanced features for the AI Gateway will give users greater control over their data.

The shift from building models to deploying them introduces new risk: third parties may attempt to exploit your data to train their own generative AI systems. These updates aim to mitigate that risk. Additionally, Cloudflare is rolling out a unified platform capability that provides visibility and protection across all web and enterprise applications. This feature identifies the location of applications across an organization, assesses their potential threats, and offers risk reduction recommendations from a single pane of glass.

unnamed (1)

Moving from Reactive to Predictive Security

Security Week 2025 is part of Cloudflare's broader mission to build a better Internet. The solutions being unveiled reflect a view that security must evolve—from reactive to predictive, from complex to intuitive, and from siloed to integrated.

The week is designed for engagement through live demos, technical deep dives, and direct conversation. The goal is to leave practitioners with not just new tools, but a clearer sense of how to collectively build a safer Internet. The future of security is not about building higher walls; it is about creating smarter ecosystems.

unnamed (2)