Quorum Cyber has unveiled its 2026 Global Cyber Risk Outlook report, revealing alarming shifts in the global cybersecurity landscape. The report indicates that advancements in AI automation and the introduction of Ransomware-as-a-Service (RaaS) platforms have transformed the threat environment, allowing nation-state actors to automate nearly 90% of intrusions. For the first time, global vulnerability disclosures have surpassed 35,000.
Significant changes in attacker strategies are noted, with a marked departure from traditional slow-encryption methods. In the financial sector, ransom demands have surged by an astonishing 179%. The report highlights organizations' escalating challenge as detection windows narrow and entry barriers for hackers diminish, empowering less experienced cybercriminals to execute attacks previously reserved for highly skilled operators.
Cyber Risk Considerations in 2026
The findings in the 2026 Global Cyber Risk Outlook are based on observations from incidents and investigations conducted with more than 350 organizations worldwide in 2025, ranging from small entities with 10 staff to large organizations with up to 10,000 employees. The report emphasizes several key points reshaping 2026 cyber risk considerations:
- A 30% increase in the formation of new ransomware groups by October 2025.
- A 21% rise in global vulnerability disclosures, exceeding 35,000.
- Nation-state groups beginning to automate up to 90% of intrusions using AI agents.
- A shift among cybercriminals from encryption to faster, less costly data exfiltration attacks.
- The emergence of new white-label RaaS platforms facilitating the rapid setup of branded criminal operations.
- Ransom demands have increased significantly across sectors, with growth of 179% in financial services and 97% in manufacturing.
- Russia, China, and Iran-linked nation-state actors remain significant threats to the public sector, while North Korea-linked actors likely amassed over $2 billion in 2025 through cybercrime.
The Professionalization of the Cybercriminal Economy
Federico Charosky, Quorum Cyber’s Chief Executive Officer, remarked, “Over the past year, we have witnessed a marked acceleration in the capability and ambition of threat actors. The proliferation of AI-enabled tooling, combined with an increasingly professionalised cybercriminal economy, has lowered barriers to entry and expanded the reach of even modestly skilled actors.”
He emphasized that the report offers critical insights from Quorum Cyber's intelligence, incident response, and counter extortion work, providing guidance for organizations to anticipate and mitigate emerging risks.
Enhancing Cyber Resilience
Quorum Cyber continues its collaboration with Microsoft as part of the MISA
The 2026 Global Cyber Risk Outlook also contains companion reports for nine key industry sectors: energy, financial services and insurance, healthcare and pharmaceuticals, higher education, housing and construction, legal and professional services, manufacturing, public sector, and retail. These companion reports deliver sector-specific threat dynamics and actionable strategies to enhance cyber resilience.
To further aid organizations in understanding and acting upon these findings, Quorum Cyber is offering a live webinar on February 25, featuring Lesley Kipling, Chief Security Advisor at Microsoft, and Quorum Cyber's Threat Intelligence leadership. The session will explore how evolving tactics by threat actors align with current cloud, identity, and AI environments, outlining strategies for improving security resilience into 2026.
The Global Cyber Risk Outlook 2026 underscores Quorum Cyber's commitment to its Microsoft-first security strategy, leveraging comprehensive insights into cloud, identity, and AI-driven ecosystems. Quorum Cyber continues its collaboration with Microsoft as part of the Microsoft Intelligent Security Association (MISA), maintaining all four Microsoft Security specializations: Cloud Security, Identity and Access Management, Information Protection and Governance, and Threat Protection.
