Why cyber resilience matters in a rapidly changing cyber landscape

The current cyber risk landscape

The current cyber risk landscape is dominated by persistent ransomware, accelerating vulnerability exploitation, and growing dependence on complex digital supply chains. Across sectors, attackers are weaponising identity weaknesses, third party dependencies and, increasingly, AI.

Ransomware continues to gain momentum

Ransomware remains the headline threat and is still rising. Global ransomware incidents have increased every year since 2022, with cumulative attacks reaching nearly 8,000 by the end of 2025 and continuing to climb into 20261.The latest data from NCC Group suggests 2025 saw a 50% increase in cyber-attacks compared to 20242. These attackers continue to favour “hack and leak” double extortion, with campaigns such as Cl0p mass exploitation and Scattered Spider operations driving spikes in monthly activity. 

We do not expect the current military activity in the Middle East to introduce new attack methods. However, we do anticipate an increase in disruption motivated attacks, particularly against organisations that have taken a public stance on the conflict or play a critical role in state operations.

The race between disclosure and exploitation

Ransomware’s threat is heightened by the fact that exploitation of IT vulnerabilities is becoming quicker. The time from vulnerability disclosure to exploitation has compressed dramatically, in many cases from days to within 24 hours3, driven by automation and AI. 

Over 48,000 common vulnerabilities and exposures were identified in 2025, representing a 20% increase on 20244. AI is amplifying both sides of the equation: attackers benefit from generative tooling for phishing, deepfake enabled fraud, and exploit development; defenders are beginning to leverage AI to triage alerts and accelerate investigations, but the offensive use cases are currently moving faster. This means preparedness is key for companies focusing on cyber risk.

Identity and supply chain risks continue to grow

A large proportion of successful intrusions begin with compromised credentials, absent MFA and social engineering, often using native speaker help desk impersonation as an entry point. 

Third party and supply chain weaknesses underpin many of the largest incidents in 2025, with losses propagating well beyond the initial victim. In 2025, a data breach at Marquis Software Solutions, a financial software provider, impacted over 74 banks and credit unions, exposing sensitive data belonging to more than 400,000 customers5.

Building resilience for a more connected threat landscape

The picture that emerges is clear. Cyber risk is accelerating, becoming faster, more disruptive and increasingly interconnected across supply chains and identity layers. Organisations that invest early in resilience, rapid patching and strong third party oversight will be far better positioned to withstand the next wave of attacks.