# Global Cybersecurity Outlook 2026 **Publisher:** World Economic Forum **Published:** n/a **Category:** Global institutions & policy **Type:** Report **Access:** Free **Official source:** https://www.weforum.org/publications/global-cybersecurity-outlook-2026/digest **Canonical:** https://tourismintel.ai/reports/global-cybersecurity-outlook-2026 ## At a glance - 94% of executives identify AI as the most significant cybersecurity change driver in 2026. - 87% of respondents report AI-related vulnerabilities as the fastest-growing cyber risk over 2025. - 64% of organizations account for geopolitically motivated cyberattacks in risk mitigation strategies. - 73% of survey respondents experienced cyber-enabled fraud personally or within their network during 2025. - 65% of large companies cite third-party and supply chain vulnerabilities as their greatest resilience challenge, up from 54% in 2025. ## What the report covers The World Economic Forum's 2026 cybersecurity outlook examines how AI adoption, geopolitical fragmentation and emerging threats are reshaping organizational cyber readiness globally. Published as the 2026 edition, the report surveys executives across sectors and regions to assess cyber risk priorities, national preparedness, and the divergence between innovation adoption and security governance. It explores how cyber-enabled fraud, ransomware, and supply chain vulnerabilities affect boards and security teams differently. ## Key findings AI is the dominant cybersecurity driver but vulnerabilities accelerate faster than defences. According to the survey, 94% of respondents identify AI as the most significant driver of change in 2026. Organizations are responding: the proportion assessing AI tool security nearly doubled from 37% in 2025 to 64% in 2026. Yet AI vulnerabilities are accelerating at an unprecedented pace, with 87% of respondents identifying AI-related risks as the fastest-growing cyber threat. Geopolitical volatility is reshaping cyber strategy and eroding confidence in national preparedness. The survey finds 64% of organizations now account for geopolitically motivated cyberattacks when designing risk mitigation strategies. Notably, 91% of the largest organizations have changed their cybersecurity approaches due to geopolitical volatility. However, confidence in national response capability is declining: 31% of respondents report low confidence in their nation's ability to respond to major cyber incidents, up from 26% the previous year. Regional disparities are stark: 84% of Middle East and North Africa respondents express high confidence in national critical infrastructure protection, versus only 13% in Latin America and the Caribbean. Cyber-enabled fraud has become pervasive and shifted executive priorities away from ransomware. The survey reveals 73% of respondents experienced cyber-enabled fraud personally or within their network during 2025. This threat now ranks as the top cyber risk concern for chief executives, displacing ransomware. Chief information security officers, by contrast, remain primarily focused on ransomware and supply chain vulnerabilities—reflecting a widening gap between boardroom and operational cyber priorities. Supply chain vulnerabilities have become the dominant barrier to resilience among large enterprises. The report documents a sharp rise in concern: 65% of large companies by revenue now identify third-party and supply chain vulnerabilities as their greatest challenge to cyber resilience, up from 54% in 2025. The report notes that this reflects ongoing opacity and concentration risks in supply chains. Public-sector organizations also report markedly lower cyber resilience, with 23% reporting insufficient capabilities. ## Key numbers | Metric | Value | Note | |---|---|---| | Executives identifying AI as most significant cybersecurity driver in 2026 | 94% | Survey finding | | Organizations with processes to assess AI security | 64% in 2026, up from 37% in 2025 | Observed increase year-on-year | | Respondents identifying AI vulnerabilities as fastest-growing cyber risk in 2025 | 87% | Survey finding | | Organizations accounting for geopolitically motivated cyberattacks in risk mitigation | 64% | Survey finding | | Largest organizations that changed cybersecurity strategy due to geopolitical volatility | 91% | Survey finding; by organization size | | Respondents with low confidence in national cyber incident response | 31%, up from 26% in 2025 | Survey finding; year-on-year change | | Respondents experiencing cyber-enabled fraud in 2025 | 73% | Survey finding; personal or network-related | | Large companies citing supply chain vulnerabilities as greatest resilience challenge | 65%, up from 54% in 2025 | Survey finding; year-on-year change | ## Why it matters **DMOs & destinations** — Destinations relying on tourism infrastructure—airports, hotels, digital booking systems—face escalating cyber threats. Geopolitical volatility and AI-enabled attacks pose direct risks to visitor management platforms and payment systems. Low national cyber preparedness (31% globally) means destinations cannot assume government protection. DMOs must embed cybersecurity into destination marketing and critical infrastructure planning. **Hotels & hospitality** — Hotels handle guest data, payment systems and operational networks vulnerable to cyber-enabled fraud (73% experienced it in 2025). Supply chain risks are acute: 65% of large companies flag third-party vulnerabilities as their top barrier to resilience. Hospitality firms depend on vendors for booking engines and PMS. Aligning boardroom fraud concerns with security team priorities around ransomware and supplier risk is now essential. **Travel tech & distribution** — Travel platforms must assess AI tool security: 64% of organizations now do so, doubling from 37% in 2025. Distribution partners face supply chain scrutiny; 65% of large companies treat this as their greatest challenge. AI vulnerabilities accelerate fastest (87% report this). Travel tech must address AI governance gaps, supply chain transparency and fraud detection. ## Methodology and limits The report draws on survey responses from executives across sectors and geographies; the full sample size and respondent profile are not disclosed in the public summary. Data compares 2025 and 2026 results where noted and includes regional breakdowns and sector analysis. This brief is based on the publicly available digest only; the full methodology appendix is referenced but not reproduced. --- © World Economic Forum for the original report. This brief is an original editorial summary by TourismIntel (https://tourismintel.ai). Read the original: https://www.weforum.org/publications/global-cybersecurity-outlook-2026/digest