top of page

Over 75% of organisations reported increase in cyber fraud says World Economic Forum

Image Illustration of major culprits for 75% increase in org cyber frauds - by Muskan Gohil
Image Illustration of major culprits for 75% increase in org cyber frauds - by Muskan Gohil

As per the World Economic Forum’s latest report, Global Cybersecurity Outlook 2026, over 75% of organisations reported an increase in cyber fraud.

 

Reason:

 

Attackers aren’t getting smarter — their tools are.

 

Automation + accessibility = a threat landscape that scales faster than most defences.

And for critical national infrastructure (CNI), the stakes couldn’t be higher.

 

What’s changing? A LOT:

 

1. AI‑powered attacks are here — and they’re scaling

 

Adversaries are already using AI to:

  • Automate reconnaissance

  • Adapt malware in real time

  • Scale social engineering

  • Increase attack volume at near‑zero cost


CNI organisations must now fight AI with AI — but with strong governance, or they’ll introduce new risks faster than they can mitigate them.

 

2. Quantum risk is no longer theoretical

 

Quantum computing will break today’s encryption — not in decades, but in years. Criminals are already harvesting encrypted data now to decrypt later.

NIST has released post‑quantum standards. CNI organisations should be adopting them NOW, not waiting for quantum maturity.

 

3. Cloud-smart is replacing cloud-first

 

Cloud brings resilience, but also data sovereignty challenges. Regulated sectors must answer two critical questions: Where does the data live? Who can access it?

One suggested approach:

  • Sensitive workloads → back on-prem

  • Specialist local cloud services → for regulated processing.

 This hybrid model should be the new normal.

 

4. IT/OT convergence is the next big vulnerability

 

OT (Operational Technology) systems (utilities, transport, manufacturing) were never designed for modern cyber exposure. Now they’re networked, targeted, and underfunded.

 

Key issue: IT security priorities ≠ OT operational priorities.

 

Applying IT controls blindly to OT can create new operational risks.CNI leaders must govern both worlds without sacrificing uptime or safety.

 

Regulators are tightening the screws


EU: DORA + NIS2

UK: Cyber Security & Resilience Bill with a 24‑hour incident notification requirement

Compliance is no longer a checkbox — it’s becoming a real‑time obligation.

 

What organisations MUST do next:


Organisations must design playbooks  with below priorities at its core for CNI, cloud and AI governance teams:

 

Core priorities:

 

  • Continuous resilience testing

  • AI‑powered detection + response

  • Post‑quantum encryption planning

  • Hybrid cloud with strict data sovereignty controls

  • Dedicated OT security investment

  • Governance frameworks for responsible AI

  • “Secure by design” procurement standards

  • Cross‑sector information sharing + trusted partners

 

The organisations that adapt early will be resilient. The ones that wait will be reacting to headlines instead of shaping them.

 

Cyber risk isn’t just increasing — it’s accelerating. AI, quantum, cloud, and OT convergence are reshaping the threat landscape faster than traditional security models can keep up.

CNI leaders must evolve now. The next wave of attacks won’t look like the last.

 


 

References:


Link to World Economic Forum’s latest outlook:

 

Link to Cyber Security and Resilence Bill:

 

Link to DORA:

 

Link to NIS2:

 

Link to Independent News:

 

 

 


 
 
 

Comments


bottom of page