This site uses PostHog and Google Analytics (with IP anonymization) to understand how visitors use the service. No advertising cookies. Privacy Policy

Global Cybersecurity Outlook 2026

Global institutions & policyFreeGlobal2026 edition; data from 2025

At a glance

  • 94% of executives identify AI as the most significant cybersecurity change driver in 2026.
  • 87% of respondents report AI-related vulnerabilities as the fastest-growing cyber risk over 2025.
  • 64% of organizations account for geopolitically motivated cyberattacks in risk mitigation strategies.
  • 73% of survey respondents experienced cyber-enabled fraud personally or within their network during 2025.
  • 65% of large companies cite third-party and supply chain vulnerabilities as their greatest resilience challenge, up from 54% in 2025.

What the report covers

The World Economic Forum's 2026 cybersecurity outlook examines how AI adoption, geopolitical fragmentation and emerging threats are reshaping organizational cyber readiness globally. Published as the 2026 edition, the report surveys executives across sectors and regions to assess cyber risk priorities, national preparedness, and the divergence between innovation adoption and security governance. It explores how cyber-enabled fraud, ransomware, and supply chain vulnerabilities affect boards and security teams differently.

Key findings

AI is the dominant cybersecurity driver but vulnerabilities accelerate faster than defences. According to the survey, 94% of respondents identify AI as the most significant driver of change in 2026. Organizations are responding: the proportion assessing AI tool security nearly doubled from 37% in 2025 to 64% in 2026. Yet AI vulnerabilities are accelerating at an unprecedented pace, with 87% of respondents identifying AI-related risks as the fastest-growing cyber threat.

Geopolitical volatility is reshaping cyber strategy and eroding confidence in national preparedness. The survey finds 64% of organizations now account for geopolitically motivated cyberattacks when designing risk mitigation strategies. Notably, 91% of the largest organizations have changed their cybersecurity approaches due to geopolitical volatility. However, confidence in national response capability is declining: 31% of respondents report low confidence in their nation's ability to respond to major cyber incidents, up from 26% the previous year. Regional disparities are stark: 84% of Middle East and North Africa respondents express high confidence in national critical infrastructure protection, versus only 13% in Latin America and the Caribbean.

Cyber-enabled fraud has become pervasive and shifted executive priorities away from ransomware. The survey reveals 73% of respondents experienced cyber-enabled fraud personally or within their network during 2025. This threat now ranks as the top cyber risk concern for chief executives, displacing ransomware. Chief information security officers, by contrast, remain primarily focused on ransomware and supply chain vulnerabilities—reflecting a widening gap between boardroom and operational cyber priorities.

Supply chain vulnerabilities have become the dominant barrier to resilience among large enterprises. The report documents a sharp rise in concern: 65% of large companies by revenue now identify third-party and supply chain vulnerabilities as their greatest challenge to cyber resilience, up from 54% in 2025. The report notes that this reflects ongoing opacity and concentration risks in supply chains. Public-sector organizations also report markedly lower cyber resilience, with 23% reporting insufficient capabilities.

Key numbers

MetricValue
Executives identifying AI as most significant cybersecurity driver in 202694%
Organizations with processes to assess AI security64% in 2026, up from 37% in 2025
Respondents identifying AI vulnerabilities as fastest-growing cyber risk in 202587%
Organizations accounting for geopolitically motivated cyberattacks in risk mitigation64%
Largest organizations that changed cybersecurity strategy due to geopolitical volatility91%
Respondents with low confidence in national cyber incident response31%, up from 26% in 2025
Respondents experiencing cyber-enabled fraud in 202573%
Large companies citing supply chain vulnerabilities as greatest resilience challenge65%, up from 54% in 2025

Figures as published in the source; forecasts and survey results are labelled as such in the note.

Why it matters

DMOs & destinations

Destinations relying on tourism infrastructure—airports, hotels, digital booking systems—face escalating cyber threats. Geopolitical volatility and AI-enabled attacks pose direct risks to visitor management platforms and payment systems. Low national cyber preparedness (31% globally) means destinations cannot assume government protection. DMOs must embed cybersecurity into destination marketing and critical infrastructure planning.

Hotels & hospitality

Hotels handle guest data, payment systems and operational networks vulnerable to cyber-enabled fraud (73% experienced it in 2025). Supply chain risks are acute: 65% of large companies flag third-party vulnerabilities as their top barrier to resilience. Hospitality firms depend on vendors for booking engines and PMS. Aligning boardroom fraud concerns with security team priorities around ransomware and supplier risk is now essential.

Travel tech & distribution

Travel platforms must assess AI tool security: 64% of organizations now do so, doubling from 37% in 2025. Distribution partners face supply chain scrutiny; 65% of large companies treat this as their greatest challenge. AI vulnerabilities accelerate fastest (87% report this). Travel tech must address AI governance gaps, supply chain transparency and fraud detection.

Methodology and limits

The report draws on survey responses from executives across sectors and geographies; the full sample size and respondent profile are not disclosed in the public summary. Data compares 2025 and 2026 results where noted and includes regional breakdowns and sector analysis. This brief is based on the publicly available digest only; the full methodology appendix is referenced but not reproduced.

Official source

The report is © World Economic Forum. This brief is an original editorial summary by TourismIntel — it quotes only figures published in the source and never reproduces the document.

Check the official statistics on Pulse

Related reports

All reportsBrief updated September 3, 2026