Drawing on recent cyber incident response engagements and in-house threat intelligence activity, we explored the key threats shaping the cyber risk landscape in 2026 and the implications for organisations responsible for governance, compliance and resilience.
Our key insights include:
- Ransomware is still the number one cyber crime issue. Data theft has overtaken encryption as the most common extortion tactic. Organisations should be considering their response, communications and regulatory strategies to deal with data leaks as well as backups and recovery.
- Geopolitical cyber risk is no longer confined to critical infrastructure. We are in a more exposed world with state-aligned and destructive attacks increasingly affecting private sector organisations. We recommend understanding the impacts geopolitical shifts will have on technology, security and business reputations.
- AI is helping threat actors operate faster and at greater scale. This occurs particularly through enhanced reconnaissance, phishing and operational automation, but there is a lot of hype.
- Identity has become a primary attack surface, with attackers increasingly targeting helpdesks, privileged accounts and cloud management platforms rather than endpoints themselves. We recommend understanding how social engineering attacks target your people, or how your Cloud and Technology environments are secured, beyond adding more security tools.