Over 75% of organisations reported increase in cyber fraud says World Economic Forum
- Muskan Gohil

- Jul 9
- 2 min read

As per the World Economic Forum’s latest report, Global Cybersecurity Outlook 2026, over 75% of organisations reported an increase in cyber fraud.
Reason:
Attackers aren’t getting smarter — their tools are.
Automation + accessibility = a threat landscape that scales faster than most defences.
And for critical national infrastructure (CNI), the stakes couldn’t be higher.
What’s changing? A LOT:
1. AI‑powered attacks are here — and they’re scaling
Adversaries are already using AI to:
Automate reconnaissance
Adapt malware in real time
Scale social engineering
Increase attack volume at near‑zero cost
CNI organisations must now fight AI with AI — but with strong governance, or they’ll introduce new risks faster than they can mitigate them.
2. Quantum risk is no longer theoretical
Quantum computing will break today’s encryption — not in decades, but in years. Criminals are already harvesting encrypted data now to decrypt later.
NIST has released post‑quantum standards. CNI organisations should be adopting them NOW, not waiting for quantum maturity.
3. Cloud-smart is replacing cloud-first
Cloud brings resilience, but also data sovereignty challenges. Regulated sectors must answer two critical questions: Where does the data live? Who can access it?
One suggested approach:
Sensitive workloads → back on-prem
Specialist local cloud services → for regulated processing.
This hybrid model should be the new normal.
4. IT/OT convergence is the next big vulnerability
OT (Operational Technology) systems (utilities, transport, manufacturing) were never designed for modern cyber exposure. Now they’re networked, targeted, and underfunded.
Key issue: IT security priorities ≠ OT operational priorities.
Applying IT controls blindly to OT can create new operational risks.CNI leaders must govern both worlds without sacrificing uptime or safety.
Regulators are tightening the screws
EU: DORA + NIS2
UK: Cyber Security & Resilience Bill with a 24‑hour incident notification requirement
Compliance is no longer a checkbox — it’s becoming a real‑time obligation.
What organisations MUST do next:
Organisations must design playbooks with below priorities at its core for CNI, cloud and AI governance teams:
Core priorities:
Continuous resilience testing
AI‑powered detection + response
Post‑quantum encryption planning
Hybrid cloud with strict data sovereignty controls
Dedicated OT security investment
Governance frameworks for responsible AI
“Secure by design” procurement standards
Cross‑sector information sharing + trusted partners
The organisations that adapt early will be resilient. The ones that wait will be reacting to headlines instead of shaping them.
Cyber risk isn’t just increasing — it’s accelerating. AI, quantum, cloud, and OT convergence are reshaping the threat landscape faster than traditional security models can keep up.
CNI leaders must evolve now. The next wave of attacks won’t look like the last.
References:
Link to World Economic Forum’s latest outlook:
Link to Cyber Security and Resilence Bill:
Link to DORA:
Link to NIS2:
Link to Independent News:



Comments