87% of global security leaders say the same thing: AI is now the fastest-growing cyber risk. Not a future threat – an active one, right now. The World Economic Forum surveyed 800 executives and security professionals from around the world and published its findings in February 2026. The data is alarming – and deserves careful attention.
AI is working for the attackers too
The share of organizations assessing the security of AI tools before deployment has doubled over the past year – from 37% to 64%. That sounds encouraging. The problem is that AI is already running in production across most organizations, and security teams are struggling to keep up.
Attackers are not waiting. They use AI to automate target reconnaissance, generate personalized phishing campaigns at industrial scale, and accelerate exploit development. Shadow AI – applications and services used by employees without IT department approval – creates attack surfaces that many organizations do not even know exist.
Adopting AI without a clear inventory of its use across the organization means leaving doors open that have never been mapped.
Geopolitics is no longer context – it is an attack vector
91% of organizations with over 100,000 employees have revised their security strategy because of geopolitical volatility. Not out of theoretical caution – out of operational necessity.
Regional differences in preparedness are equally significant. 84% of respondents in the Middle East and North Africa believe their countries are ready to handle a major cyberattack on critical infrastructure. In Latin America and the Caribbean, only 13% share the same level of confidence. This gap – referred to in the report as the “cyber equity gap” – is not solely a problem for less prepared regions. It is a systemic global vulnerability: supply chains do not respect geographic boundaries.
Cyber-enabled fraud: no longer someone else’s problem
73% of respondents say someone in their personal network was affected by cyber-enabled fraud in 2025. Not an abstract statistic – colleagues, business partners, family members. Phishing via email, vishing via phone calls, smishing via SMS. Old methods, increasingly precise execution, now assisted by AI.
A clear gap exists between how CEOs and CISOs perceive risk. CEOs are most concerned about fraud and phishing – attacks with immediate financial and reputational impact. CISOs rank ransomware as the top threat. Both perspectives are valid. Organizations that treat these risks separately are getting the approach wrong.
What works – according to the data
The WEF report and security agency recommendations from the US and Europe converge on the same set of measures. Zero trust architecture and network segmentation limit damage after a breach – the attacker gets in, but cannot move laterally. EDR (Endpoint Detection and Response) maintains real-time visibility. Auditing third-party vendors reduces supply chain risk – one of the most exploited vectors over the past two years. And regular cybersecurity training for employees remains, according to the data, one of the most cost-effective investments an organization can make.
One element connects all these measures: they require decisions at the leadership level, not just at the technical level. Cybersecurity in 2026 is no longer a conversation between IT and vendors. It is a boardroom conversation.
Source: weforum.org
For detailed information about our cybersecurity solutions, please visit the dedicated page: Cyber Security.












