Charlotte Nicholls, underwriter – Cyber and Shak Mohammed, Claims Adjuster – Cyber at Markel International examine the cyber market for 2026.
By Charlotte Nicholls and Shak Mohammed
Originally published in Emerging Risks, January 2026:
The Big Risks for ’26 – Resilience key in navigating cyber landscape
5-minute read
The cyber risk landscape is evolving at a fast pace, driven by geopolitical tensions, technological developments and advanced threat actors — bringing new challenges for businesses operating in a volatile world. We’re seeing more organisations fortifying their defences to safeguard systems and confidential data from cybercriminals, who are showing no signs of abating.
As we enter 2026, there are three emerging themes that should be top of mind for risk managers — the persistent threat of ransomware, the doubled-edged impact of artificial intelligence (AI) and the growing complexity of supply chain vulnerabilities.
Advanced ransomware tactics explained
Ransomware remains the most significant driver of cyber insurance claims and business disruption. In 2025, the average cost of a ransomware incident exceeded $5 million, with attackers deploying more advanced tactics. Ransomware gangs, for example, are forming “super groups” so they can pool expertise to maximise impact. These groups are leveraging zero-day exploits and sophisticated social engineering, including the use of native language speakers, to enhance the credibility of their attacks on businesses globally.
Double extortion ransomware has also become more prominent whereby attackers are not only encrypting data but also threatening to leak sensitive information on the dark web — putting significant pressure on their victims. High-profile campaigns, such as the ones we’ve seen against major high street retailers, have demonstrated how quickly disruption can cascade through multiple sectors.
The ripple effects are not restricted to direct victims. Supply chain partners and customers often suffer significant collateral damage in the form of downtime due to linked systems, resulting in increased costs for implementing workarounds and decreases in revenue because of the outage(s).
Rethinking risk assessments in supply chains
Modern enterprises are more interconnected than ever, relying on a web of vendors, partners and technology providers. This interdependence creates fertile ground for attackers seeking to maximise disruption. Threat actors exploit these connections so they can move laterally across networks, monetising attacks across multiple organisations simultaneously.
This reality demands a fundamental rethink of business continuity planning and vendor risk management. Some key questions for risk managers are:
- Do we have alternative suppliers if one fails?
- What level of access do vendors have to our systems, and are these properly secured?
- Is our crisis response plan written down should we have a complete system shutdown?
Addressing these issues is critical to reducing systemic exposure.
Another key threat is AI. On the one hand, businesses are deploying AI to enhance threat detection and automate defences. But on the other, threat actors are weaponising it to scale attacks and bypass traditional controls.
As the threat landscape evolves, so too must our defences, ensuring that nothing is trusted by default and that vigilance and resilience remain at the heart of every organisation’s cyber strategy.
We’re witnessing the emergence of AI agents capable of performing any task a user desires. A user can now “vibe code” a software application simply by instructing an AI agent on their requirements, enabling individuals without any coding expertise to create software with minimal effort. This means novice criminals can venture into the realm of developing harmful software, while more seasoned threat actors can enhance their ransomware or even instruct an agent to search for vulnerabilities, significantly simplifying their tasks.
The rise of AI-generated deepfakes — convincing fake videos and audio — has also made it alarmingly easy to impersonate senior executives and manipulate employees. The CrowdStrike Global Threat Report 2025 highlighted a 442% surge in phishing attacks, spearheaded by AI-powered deepfakes and a substantial increase in the effectiveness of AI-generated phishing emails.
Businesses must therefore invest in continuous employee training and deploy advanced monitoring tools, which can detect AI-driven anomalies. Concurrently, organisations should ensure their own use of AI complies with data protection laws and emerging AI-specific regulations for the country/countries they operate in.
Remaining resilient in the face of adversity
These risks aren’t isolated incidents but systemic challenges that span technology, geopolitics and human behaviour. Ransomware is becoming more targeted, AI is amplifying attacks and supply chain vulnerabilities are multiplying. A zero-trust security strategy, continuous employee education and robust vendor management are therefore essential.
As the threat landscape evolves, so too must our defences, ensuring that nothing is trusted by default and that vigilance and resilience remain at the heart of every organisation’s cyber strategy.
Related content
-
The importance of proactive cyber risk management in an evolving threat landscape
Rachel Nestor explores the recent surge in cyber attacks on major UK retailers, highlighting the need for robust supply chain management and tailored insurance solutions.
-
Markel launches InsurtechRisk+ product for insurtech businesses
InsurtechRisk+ package contains four insuring clauses – insurance services and technology liability, directors and officers (D&O) liability, crime, and cyber liability and loss cover.
-
Navigating the fintech risk landscape
Fintech investment faces challenges, but optimism remains for future growth and innovation.