Quorum Cyber has released its 2026 Global Cyber Risk Outlook report, bringing attention to the significant transformations in the cyber threat landscape due to AI automation and Ransomware-as-a-Service (RaaS) platforms.
These developments have enabled up to 90% automation of nation-state intrusions and have pushed global vulnerability disclosures beyond the 35,000 mark for the first time. A notable shift in tactics is also evident as ransomware attacks in the financial sector have skyrocketed by 179%, indicating attackers are moving away from slower encryption methods.
Rising cyber threats
The report is based on incidents and investigations from over 350 global organisations, ranging in size from 10 to 10,000 employees in 2025.
Key findings of the report highlight the urgent need for updated cyber risk approaches in 2026
Key findings of the report highlight the urgent need for updated cyber risk approaches in 2026. The formation of new ransomware groups has increased by 30% as of October 2025, while global vulnerability disclosures have surged by 21%, exceeding 35,000. Additionally, there is early evidence of AI agents being used by nation-state groups to automate up to 90% of intrusions. The trend is growing toward data exfiltration attacks, with new white-label RaaS platforms facilitating rapid launches of branded criminal operations.
Changing dynamics in cybercrime
Financial institutions have faced a 179% rise in ransom demands, while the manufacturing sector has seen demands increase by 97%. Nation-state actors linked to Russia, China, and Iran continue to threaten the public sector, and North Korea-affiliated groups reportedly amassed over $2 billion from cyber activities in 2025.
According to Federico Charosky, CEO of Quorum Cyber, "Over the past year, we have witnessed a marked acceleration in the capability and ambition of threat actors. The proliferation of AI-enabled tooling, combined with an increasingly professionalised cybercriminal economy, has lowered barriers to entry and expanded the reach of even modestly skilled actors."
Sector-specific insights
These reports provide sector-specific threat analyses and practical guidance for bolstering cyber resilience
In addition to the primary report, companion documents cover nine specific industry sectors: energy, financial services and insurance, healthcare, higher education, housing, legal services, manufacturing, public sector, and retail.
These reports provide sector-specific threat analyses and practical guidance for bolstering cyber resilience. Quorum Cyber will present a webinar on February 25 with Lesley Kipling, Chief Security Advisor at Microsoft, discussing how evolving tactics influence cloud and AI-driven environments and what security leaders can do to prepare for 2026.
Microsoft-first security strategy
The report underscores Quorum Cyber's commitment to its Microsoft-centric security approach, leveraging significant insights into cloud, identity, and AI-driven scenarios.
As a prominent Microsoft security services provider and a member of the Microsoft Intelligent Security Association (MISA), Quorum Cyber holds specialisations in Cloud Security, Identity and Access Management, Information Protection, and Threat Protection.
Quorum Cyber reveals the extensive, but alarming findings of its 2026 Global Cyber Risk Outlook report. AI automation and Ransomware-as-a-Service (RaaS) platforms have fundamentally altered the threat landscape, enabling nation-state actors to automate up to 90% of intrusions, and pushing vulnerability disclosures past 35,000 for the first time.
Attackers abandon slow-encryption tactics, as evidenced by ransom demands in financial services exploding by 179%. Organisations face a stark reality: detection windows are shrinking, barriers to hacker entry are collapsing, and even modestly skilled criminals now wield capabilities once reserved for elite operators.
Cyber risk considerations
Insights from the 2026 Global Cyber Risk Outlook are derived from incidents and investigations observed across over 350 global organisations ranging in staff size from 10 to 10,000 throughout calendar year 2025. Highlighted report findings that need to reshape 2026 cyber risk considerations include:
- The number of newly formed ransomware groups increased by 30% in the year to October 2025
- Global vulnerability disclosures rose 21%, surpassing 35,000
- Early evidence of a nation-state group using AI agents to automate up to 90% of an intrusion
- Cybercriminals are increasingly shifting away from encryption toward faster, lower-cost data exfiltration attacks
- New white-label RaaS platforms enabling rapid launch of branded criminal operations
- Average ransom demands surged across multiple sectors, including 179% in financial services and 97% in manufacturing
- Nation-state threat actors associated with Russia, China, and Iran remain the top threats to the public sector, while North Korea-linked actors likely earned over $2 billion from cybercrime in 2025
Professionalised cybercriminal economy
“Over the past year, we have witnessed a marked acceleration in the capability and ambition of threat actors. The proliferation of AI-enabled tooling, combined with an increasingly professionalised cybercriminal economy, has lowered barriers to entry and expanded the reach of even modestly skilled actors,” says Federico Charosky, Quorum Cyber’s Chief Executive Officer.
“This report distills the most significant developments observed across our intelligence, incident response, and counter extortion work, offering practical guidance to help organisations anticipate and mitigate emerging risks.”
Strengthening cyber resilience
In addition, the 2026 Global Cyber Risk Outlook includes companion reports focused on nine industry sectors, including energy, financial services and insurance, healthcare and pharmaceuticals, higher education, housing and construction, legal and professional services, manufacturing, public sector, and retail. Each companion report outlines sector-specific threat dynamics and practical considerations for strengthening cyber resilience.
To help organisations interpret these findings and prioritise action, Quorum Cyber will host a live webinar on February 25 featuring Lesley Kipling, Chief Security Advisor at Microsoft, alongside Quorum Cyber’s Threat Intelligence leadership. The session will examine how evolving threat actor tactics intersect with modern cloud, identity, and AI-driven environments — and what security leaders should focus on to strengthen resilience heading into 2026.
The 2026 Global Cyber Risk Outlook reflects Quorum Cyber’s Microsoft-first approach to security, informed by deep visibility into cloud, identity, and AI-driven environments. Founded as a Microsoft-first security services provider, Quorum Cyber is a long-standing member of the Microsoft Intelligent Security Association (MISA) and holds all four Microsoft Security specialisations: Cloud Security, Identity and Access Management, Information Protection and Governance, and Threat Protection.