Source: Cyber catalyst report: Guiding priorities in cyber investments
1. Shifting ransomware tactics shine a spotlight on privacy risks
Amid a complex regulatory landscape, threat actors are leveraging privacy lapses to scale widespread attacks. New tactics include incremental data leaks to pressure organizations to pay ransom, leading to both financial and reputational concerns. Ransom payments represent only a fraction of the total financial impact. Operational downtime, recovery expenses, legal fees, regulatory fines, and reputational harm often far exceed ransom amounts. Supply chain attacks are becoming a preferred vector, exploiting vulnerabilities in interconnected vendors and service providers to amplify disruption across entire ecosystems.
2. The regulatory landscape is evolving with increased litigation creativity
The privacy regulatory landscape in Europe is shaped by the GDPR and a patchwork of other laws, including local ones. Further, organizations doing business in other countries, such as the US, need to navigate country- and state-specific regulations, creating increased operational complexity. The evolving enforcement landscape and creative litigation strategies by plaintiffs’ attorneys are notable concerns for European companies.
3. AI amplifies risks
While generative artificial intelligence has not yet created a new category of risks, it can amplify existing and familiar ones. Most impactfully, AI tools may enable even less technically skilled threat actors to execute complex intrusions into companies’ systems. For instance, threat actors might leverage AI to automate their scouting activities and develop more persuasive social engineering campaigns, potentially heightening the likelihood of incidents that compromise privacy-sensitive data. While the current perspective of Marsh’s cyber specialists is that AI-related privacy risks are already contemplated under broad cyber coverage, insurer responses may differ and insurers remain vigilant in tracking ongoing AI-related litigation concerning alleged privacy infringements.
Four actions to mitigate privacy and ransomware risks
The Cyber catalyst report: Guiding priorities in cyber investments indicates that 68% of European organizations are very confident in their company’s ability to manage cyber risk, slightly less than the global average (see Figure 3).