Summary is AI-generated, newsdesk-reviewed
  • AI and RaaS platforms enable nation-states to automate 90% of cyber intrusions.
  • Ransomware demands in financial services up 179%, detection windows shrinking drastically.
  • Cybercriminals shift to faster data exfiltration, using new white-label RaaS platforms.

Quorum Cyber has released its 2026 Global Cyber Risk Outlook report, bringing attention to the significant transformations in the cyber threat landscape due to AI automation and Ransomware-as-a-Service (RaaS) platforms.

These developments have enabled up to 90% automation of nation-state intrusions and have pushed global vulnerability disclosures beyond the 35,000 mark for the first time. A notable shift in tactics is also evident as ransomware attacks in the financial sector have skyrocketed by 179%, indicating attackers are moving away from slower encryption methods.

Rising cyber threats

The report is based on incidents and investigations from over 350 global organisations, ranging in size from 10 to 10,000 employees in 2025.

Key findings of the report highlight the urgent need for updated cyber risk approaches in 2026

Key findings of the report highlight the urgent need for updated cyber risk approaches in 2026. The formation of new ransomware groups has increased by 30% as of October 2025, while global vulnerability disclosures have surged by 21%, exceeding 35,000. Additionally, there is early evidence of AI agents being used by nation-state groups to automate up to 90% of intrusions. The trend is growing toward data exfiltration attacks, with new white-label RaaS platforms facilitating rapid launches of branded criminal operations.

Changing dynamics in cybercrime

Financial institutions have faced a 179% rise in ransom demands, while the manufacturing sector has seen demands increase by 97%. Nation-state actors linked to Russia, China, and Iran continue to threaten the public sector, and North Korea-affiliated groups reportedly amassed over $2 billion from cyber activities in 2025.

According to Federico Charosky, CEO of Quorum Cyber, "Over the past year, we have witnessed a marked acceleration in the capability and ambition of threat actors. The proliferation of AI-enabled tooling, combined with an increasingly professionalised cybercriminal economy, has lowered barriers to entry and expanded the reach of even modestly skilled actors."

Sector-specific insights

These reports provide sector-specific threat analyses and practical guidance for bolstering cyber resilience

In addition to the primary report, companion documents cover nine specific industry sectors: energy, financial services and insurance, healthcare, higher education, housing, legal services, manufacturing, public sector, and retail. 

These reports provide sector-specific threat analyses and practical guidance for bolstering cyber resilience. Quorum Cyber will present a webinar on February 25 with Lesley Kipling, Chief Security Advisor at Microsoft, discussing how evolving tactics influence cloud and AI-driven environments and what security leaders can do to prepare for 2026.

Microsoft-first security strategy

The report underscores Quorum Cyber's commitment to its Microsoft-centric security approach, leveraging significant insights into cloud, identity, and AI-driven scenarios.

As a prominent Microsoft security services provider and a member of the Microsoft Intelligent Security Association (MISA), Quorum Cyber holds specialisations in Cloud Security, Identity and Access Management, Information Protection, and Threat Protection.

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...