Summary is AI-generated, newsdesk-reviewed
  • AI automation enables 90% intrusions, new vulnerabilities exceed 35,000, reshaping cyber threats.
  • Ransomware groups up 30%; financial ransom demands surge 179%, emphasizing cyber risk urgency.
  • Quorum Cyber report outlines sector-specific threats, enhancing resilience with Microsoft-first security.

Quorum Cyber has unveiled its 2026 Global Cyber Risk Outlook report, revealing alarming shifts in the global cybersecurity landscape. The report indicates that advancements in AI automation and the introduction of Ransomware-as-a-Service (RaaS) platforms have transformed the threat environment, allowing nation-state actors to automate nearly 90% of intrusions. For the first time, global vulnerability disclosures have surpassed 35,000.

Significant changes in attacker strategies are noted, with a marked departure from traditional slow-encryption methods. In the financial sector, ransom demands have surged by an astonishing 179%. The report highlights organizations' escalating challenge as detection windows narrow and entry barriers for hackers diminish, empowering less experienced cybercriminals to execute attacks previously reserved for highly skilled operators.

Cyber Risk Considerations in 2026

The findings in the 2026 Global Cyber Risk Outlook are based on observations from incidents and investigations conducted with more than 350 organizations worldwide in 2025, ranging from small entities with 10 staff to large organizations with up to 10,000 employees. The report emphasizes several key points reshaping 2026 cyber risk considerations:

  • A 30% increase in the formation of new ransomware groups by October 2025.
  • A 21% rise in global vulnerability disclosures, exceeding 35,000.
  • Nation-state groups beginning to automate up to 90% of intrusions using AI agents.
  • A shift among cybercriminals from encryption to faster, less costly data exfiltration attacks.
  • The emergence of new white-label RaaS platforms facilitating the rapid setup of branded criminal operations.
  • Ransom demands have increased significantly across sectors, with growth of 179% in financial services and 97% in manufacturing.
  • Russia, China, and Iran-linked nation-state actors remain significant threats to the public sector, while North Korea-linked actors likely amassed over $2 billion in 2025 through cybercrime.

The Professionalization of the Cybercriminal Economy

Federico Charosky, Quorum Cyber’s Chief Executive Officer, remarked, “Over the past year, we have witnessed a marked acceleration in the capability and ambition of threat actors. The proliferation of AI-enabled tooling, combined with an increasingly professionalised cybercriminal economy, has lowered barriers to entry and expanded the reach of even modestly skilled actors.”

He emphasized that the report offers critical insights from Quorum Cyber's intelligence, incident response, and counter extortion work, providing guidance for organizations to anticipate and mitigate emerging risks.

Enhancing Cyber Resilience

Quorum Cyber continues its collaboration with Microsoft as part of the MISA

The 2026 Global Cyber Risk Outlook also contains companion reports for nine key industry sectors: energy, financial services and insurance, healthcare and pharmaceuticals, higher education, housing and construction, legal and professional services, manufacturing, public sector, and retail. These companion reports deliver sector-specific threat dynamics and actionable strategies to enhance cyber resilience.

To further aid organizations in understanding and acting upon these findings, Quorum Cyber is offering a live webinar on February 25, featuring Lesley Kipling, Chief Security Advisor at Microsoft, and Quorum Cyber's Threat Intelligence leadership. The session will explore how evolving tactics by threat actors align with current cloud, identity, and AI environments, outlining strategies for improving security resilience into 2026.

The Global Cyber Risk Outlook 2026 underscores Quorum Cyber's commitment to its Microsoft-first security strategy, leveraging comprehensive insights into cloud, identity, and AI-driven ecosystems. Quorum Cyber continues its collaboration with Microsoft as part of the Microsoft Intelligent Security Association (MISA), maintaining all four Microsoft Security specializations: Cloud Security, Identity and Access Management, Information Protection and Governance, and Threat Protection.

In case you missed it

How Is The Role Of Biometrics Changing In Physical Access Control?
How Is The Role Of Biometrics Changing In Physical Access Control?

Biometrics today provide better security and frictionless user experiences. Biometric identifiers like fingerprints, facial recognition, and iris scans are unique and difficult to...

Dormakaba Acquires Alliants: Hospitality Access Solutions
Dormakaba Acquires Alliants: Hospitality Access Solutions

dormakaba has signed a binding agreement to acquire Alliants Limited, the guest experience technology partner behind more than 100,000 hotel rooms for the world’s leading hos...

Allied Universal® Honored As Admired Workplace By Newsweek
Allied Universal® Honored As Admired Workplace By Newsweek

Allied Universal®, the world's pioneer security and facility services provider, has been named one of America's Most Admired Workplaces by Newsweek for the third consecutive ye...