The Cyber Risk Reset: Why 2026 Changes Everything
Cybercrime costs have surpassed $10 trillion. Five major regulations converge in 24 months. AI has weaponised phishing at scale. State-sponsored actors have compromised telecom networks across 80 nations. And 40% of cyber insurance claims are denied. For international businesses, the cyber risk equation has fundamentally changed. The global cyber risk landscape has undergone a structural transformation. Cybercrime costs were projected at $10.5 trillion in 2025 — a figure that would make it the world's...
EXECUTIVE SUMMARY
Cybercrime costs have surpassed $10 trillion. Five major regulations converge in 24 months. AI has weaponised phishing at scale. State-sponsored actors have compromised telecom networks across 80 nations. And 40% of cyber insurance claims are denied. For international businesses, the cyber risk equation has fundamentally changed. The global cyber risk landscape has undergone a structural transformation. Cybercrime costs were projected at $10.5 trillion in 2025 — a figure that would make it the world's...
Cybercrime costs have surpassed $10 trillion.
The global cyber risk landscape has undergone a structural transformation.
Global cybercrime costs reached an estimated $10.5 trillion in 2025, according to Cybersecurity Ventures — equivalent to $333,000 per second in economic harm.
Between December 2023 and December 2026, five major cyber regulatory frameworks have taken effect or will take effect across the world's three largest economic blocs.
Cybercrime costs have surpassed $10 trillion.
$10.5 Trillion and Counting
Global cybercrime costs reached an estimated $10.5 trillion in 2025, according to Cybersecurity Ventures — equivalent to $333,000 per second in economic harm. This figure has grown at approximately 12% compound annual growth rate since 2021, when costs stood at $6 trillion. Projections suggest costs will reach $12.2 trillion annually by 2031, driven by the expansion of attack surfaces, the proliferation of connected devices, and the industrialisation of cybercrime operations.
The financial impact on individual organisations is substantial and rising. IBM's 2025 Cost of a Data Breach Report found that the global average cost of a data breach fell to $4.44 million — a 9% decline from 2024's $4.88 million, representing the first reduction in five years. However, this headline improvement masks significant regional variation: US companies faced average breach costs of $10.22 million, a 9% increase to all-time highs. The reduction in global averages was driven primarily by faster detection and containment enabled by AI-powered security tools. Notably, IBM found that the unauthorised use of AI tools by employees — so-called "shadow AI" — added $670,000 to the average breach cost, creating a new category of insider-generated exposure.
Ransomware remains the most visible manifestation of cybercrime, though its economics are shifting. Chainalysis reported that on-chain ransomware payments totalled approximately $820 million in 2025, an 8% decline from $892 million in 2024. More significantly, only 28% of ransom demands were paid — an all-time low. However, this declining payment rate has not reduced attacker profitability: the median ransom payment surged 368% to $59,556, and ransomware attacks increased 50% year-over-year, making 2025 the most active ransomware year on record. The implication is clear: threat actors are responding to lower conversion rates with higher volume, higher demands, and more sophisticated targeting — a dynamic that increases total risk even as individual resistance improves.
Five Frameworks in 24 Months
Between December 2023 and December 2026, five major cyber regulatory frameworks have taken effect or will take effect across the world's three largest economic blocs. This convergence is unprecedented in scope and creates a compliance step-change for any business operating internationally.
The SEC's Cyber Disclosure Rules
Effective December 2023, the US Securities and Exchange Commission requires public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality. The rule applies to all registrants and has already altered corporate disclosure behaviour: companies are increasingly filing non-material cyber incidents under Item 8.01 rather than risk the regulatory consequences of misclassifying a material event under Item 1.05. For international companies listed on US exchanges — including a significant number of Chinese enterprises — this creates a disclosure obligation that may conflict with domestic regulatory frameworks.
AI as Weapon and Shield
Artificial intelligence has fundamentally altered the cyber threat landscape in both directions. On the offensive side, KnowBe4's 2025 Phishing Trends Report found that 83% of phishing emails are now AI-generated, representing a 1,265% surge in AI-linked phishing attacks. The FBI's 2025 IC3 report documented a 37% rise in AI-assisted business email compromise. Deepfake files surged from 500,000 in 2023 to 8 million in 2025, with deepfake-based CEO fraud now targeting an estimated 400 companies per day. The first quarter of 2025 alone recorded 179 deepfake incidents, surpassing the total count for all of 2024 by 19%.
Google's Cloud Threat Intelligence Group identified five novel AI-enabled malware families in 2025, including PROMPTFLUX (dynamic script generation and code obfuscation) and PROMPTLOCK (runtime LLM integration). These represent a qualitative shift: malware that uses large language models during execution to dynamically generate malicious scripts and evade detection. CrowdStrike reported that 80% of ransomware attacks now incorporate artificial intelligence, while underground platforms like Nytheon AI offer zero-code capabilities for malware and phishing generation, effectively collapsing the skill and cost barriers for conducting sophisticated cyber attacks.
On the defensive side, the AI cybersecurity market reached approximately $28.5 billion in 2025, growing at a 23% compound annual growth rate with projections to reach $86-94 billion by 2030. AI-powered security tools were the primary driver of the decline in average breach costs reported by IBM, enabling faster detection and containment. The paradox is stark: companies that deploy AI for defence see measurable cost reductions, while companies that fail to deploy AI for defence face an adversary that has already adopted it for offence. The asymmetry favours the attacker — not because AI is inherently offensive, but because defensive deployment requires institutional change, budget allocation, and organisational capability that most enterprises have not yet built.
The New Normal
Two Chinese-attributed campaigns revealed in 2024-2025 — Salt Typhoon and Volt Typhoon — represent a qualitative escalation in state-sponsored cyber operations that has direct implications for international business risk.
Salt Typhoon: Telecom Infrastructure Compromise
Salt Typhoon compromised telecommunications systems across more than 80 nations, with at least nine major US telecom companies affected — including access to lawful intercept ("wiretap") systems under the Communications Assistance for Law Enforcement Act (CALEA). The campaign operated undetected for an estimated one to two years before discovery in September 2024. High-profile targets included communications of senior political figures. The US Treasury responded with sanctions against Sichuan Juxinhe Network Technology Co., and the FBI announced a $10 million bounty for information on Salt Typhoon operatives in April 2025. While Verizon and AT&T claimed containment in December 2024, evidence of complete eradication remains unproven.
Volt Typhoon: Critical Infrastructure Pre-positioning
The Supply Chain Attack Surface
Supply chain cyber attacks have emerged as the fastest-growing attack vector, driven by the interconnected nature of modern business operations and the difficulty of securing extended vendor ecosystems. The Verizon 2025 Data Breach Investigations Report found that 30% of all data breaches now involve third parties — a 100% year-over-year increase. SecurityScorecard's 2025 Global Third Party Breach Report placed the figure higher, at 35.5%. Software supply chain attacks more than doubled during 2025, averaging 28 attacks per month compared to 13 per month in 2024, with October 2025 setting records at 32% above previous peaks.
The cost and detection dynamics of supply chain breaches are particularly concerning. IBM found that supply chain compromise costs averaged $4.91 million — second only to malicious insider threats at $4.92 million. More critically, breaches involving supply chain vectors took an average of 267 days to identify and contain — the longest lifecycle of any breach category, creating extended windows of exposure during which data exfiltration, lateral movement, and additional compromise can occur undetected. The attack surface is expanding into earlier stages of the software lifecycle: 35% of 2025 supply chain attacks originated through compromised software dependencies, 22% targeted CI/CD pipelines, and 20% involved poisoned container images.
The legacy of major supply chain attacks — SolarWinds in 2020, which affected over 18,000 organisations, and MOVEit in 2023, which impacted 2,500 organisations and 80 million individuals — has not produced proportionate improvements in third-party risk management. Gartner projects that supply chain attacks will account for 45% of all cyberattacks by 2025, a trajectory driven by the asymmetric economics of the vector: compromising one widely-used software vendor delivers access to thousands of downstream targets simultaneously.
The Insurance Protection Gap
The cyber insurance market reached approximately $16.3 billion in gross written premiums in 2025 — against a cybercrime cost base of $10.5 trillion. This 640:1 exposure ratio represents the largest protection gap in the global insurance market. Munich Re projects the market will more than double by 2030, growing at over 10% annually, but even projected growth will not materially close the gap between insured and uninsured cyber risk.
The gap is exacerbated by coverage exclusions that remove the most consequential risks from insurable scope. Lloyd's of London's 2023 mandate requires that policies exclude losses from state-backed cyber incidents — effectively rendering the most sophisticated and damaging attacks uninsurable. Forty percent of cyber insurance claims are denied, with state-sponsored attack attribution and minimum security controls violations the fastest-growing denial triggers. The attribution challenge — proving that an attack was state-sponsored — gives insurers significant latitude in payment denial, creating a structural incentive to attribute attacks to state actors even when evidence is ambiguous.
Premium trends are moving in the opposite direction from risk trends. Lockton broker data shows an average 11% decline in cyber premiums in 2025, driven by competitive pressure and increased insurer capacity. European markets saw declines of 10-12%, while US markets declined modestly at 0.2-1.6%. This softening of premiums in the face of escalating threat severity and frequency creates a mispricing dynamic that experienced risk professionals will recognise: the current pricing environment is unsustainable and will correct, likely triggered by a major state-attributed incident or a cluster of supply chain breaches that exceed modelled loss expectations.
Harvest Now, Decrypt Later
In August 2024, NIST finalised the first three post-quantum cryptography (PQC) standards — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — marking the formal beginning of the global migration from quantum-vulnerable encryption. The timeline for quantum computers achieving the capability to break current RSA and elliptic curve cryptography remains uncertain, with estimates typically ranging from 10 to 15 years. However, the "harvest now, decrypt later" (HNDL) threat — in which adversaries collect encrypted data today for future decryption when quantum capability matures — means that the risk is already present. NSA, CISA, and NIST have jointly warned that adversaries are already harvesting encrypted data with long-term strategic value.
For international businesses, the quantum migration challenge is threefold. First, the inventory problem: most organisations do not know where all their cryptographic implementations reside, making migration planning impossible without a comprehensive discovery exercise. Second, the transition timeline: major cloud providers have announced hybrid TLS support by 2024-2025 with full PQC migration targets by 2028-2030, but enterprise applications typically lag infrastructure providers by three to five years. Third, the compliance dimension: as PQC standards are adopted into regulatory frameworks, companies that have not begun migration planning will face both security exposure and compliance risk. The consensus among cryptographic experts is that planning, discovery, and inventory completion must be achieved within two to four years — a timeline that is already running.
Strategic Implications for International Businesses
The cyber risk landscape of 2026 presents four irreducible challenges for international businesses. First, the regulatory convergence demands a unified compliance architecture that can simultaneously satisfy SEC, EU, and Chinese reporting obligations — an architecture that most organisations have not yet designed, let alone implemented. Companies that treat cyber compliance as a jurisdiction-by-jurisdiction exercise will face structural inefficiency and elevated enforcement risk.
Second, the AI transformation of the threat landscape requires a corresponding AI transformation of defensive capabilities. The 83% AI-generated phishing rate and the emergence of runtime LLM-integrated malware mean that organisations relying on pre-AI security architectures face an adversary that has already evolved beyond their detection capabilities. Investment in AI-powered security is no longer discretionary; it is existential.
Third, the supply chain attack surface demands a fundamental rethinking of third-party risk management. When 36% of all breaches originate from third parties and detection takes 267 days, the traditional approach of annual vendor assessments and questionnaire-based compliance is demonstrably inadequate. Continuous monitoring, zero-trust architecture, and contractual liability frameworks must replace periodic review cycles.
Fourth, the insurance protection gap means that companies cannot transfer their way out of cyber risk. With 40% claim denial rates, state-sponsored exclusions, and a 640:1 exposure ratio, cyber insurance is a supplement to — not a substitute for — comprehensive risk management. Boards must understand that cyber risk retention is the default position, whether or not it is the intended one.
This page preserves the original historical SRG article text and exhibits while reformatting the structure for the current Global Risk Watch deep-dive template.
Charts and source-register language are retained from the source article where available.
Historical deep-dive format normalized for Global Risk Watch; original charts and exhibits preserved.