Geopolitical instability, AI-enabled attacks, insider exposure, identity compromise, and data extortion all made the digital landscape more inhospitable and unpredictable in the first half of the year. Organisations are now operating in a threat environment where compromise is becoming easier, access is becoming more valuable, and disruption increasingly extends beyond technology alone.
The ever-evolving threat landscape has shifted businesses’ focus onto cyber resilience: the ability to withstand a cyber-attack, bounce back, and resume business as usual as quickly and as safely as possible. All while retaining trust from customers, investors, business partners, and the wider ecosystem.
That’s why the most effective organisations are shifting their focus from defending against individual threats to holistic resilience. Rather than attempting to predict every emerging attack technique and setting up defences against every potential threat actor, they are investing in controls that reduce the impact of compromise, limit attacker freedom of movement and improve the speed of detection, response, and recovery.
Identity is the primary security boundary
Identity sits at the centre of most major incidents whether the initial access comes through phishing, social engineering, helpdesk manipulation, token theft, insider recruitment or supply chain compromise.
Cybercriminals are attempting to obtain trusted access, so organisations need to treat identity infrastructure as critical security infrastructure. Strong authentication remains essential, but resilience increasingly depends on broad identity governance.
Among the measures they need to take are reducing standing privilege, enforcing conditional access policies, protecting administrative accounts, strengthening joiner-mover-leave processes, and continuously validating trust relationships across cloud, Software-as-a-Service (SaaS), and hybrid environments.
At the bare minimum, organisations need to verify who a user is, but they must also continuously assess whether access remains appropriate through a session and whether behaviour aligns with expected activity.
Attackers aren’t always breaking into systems, they’re logging in by using legitimate credentials. So, to build cyber resilience, trust controls must become dynamic rather than permanent.
Reducing the blast radius data exposure
As the frequency of extortion-led attacks and large-scale data theft has increased, so organisations need to think differently about storing and securing sensitive information.
While it’s important to know where data is stored, it’s also vital to understand how quickly it can be accessed, copied, and removed once an attacker gains trusted access. Reducing the blast radius of compromise requires greater viability over data flows, permissions, and dependencies.
Wherever possible, sensitive information should be segmented, privileged access should be tightly controlled, and excessive permissions should be continuously reviewed. Data classifications programmes become significantly more valuable when they inform access decisions, monitoring priorities, and incident response planning. The objective is to ensure that a single compromised identity, token or endpoint cannot immediately provide unrestricted access to the organisation’s most valuable information assets.
Insider threats remain a constant threat
Organisations shouldn’t let their guard down from potential risks from within either – but without treating employees and contractors as threats. As real cyber security incidents frequently remind us, insider exposure rarely exists in isolation. Identity compromise, social engineering, shadow AI usages, contractor access, third-party support functions, and criminal recruitment all create opportunities for trusted access to be abused.
Our Threat Intelligence team advises that insider risk programmes need to move beyond traditional HR-focused models. Organisations should seek greater visibility into abnormal access patterns, unusual data movement, privilege escalation activity, and behaviour that deviates from established baselines. Trusted users, compromised users, and malicious insiders can often appear similar from a technical perspective. Effective monitoring therefore focuses on behaviour and context rather than intent alone.
As covered comprehensively by Quorum Cyber’s Threat Intelligence team in the 2026 Global Cyber Risk Mid-Year Review, the threat landscape will continue to evolve throughout the rest of 2026 and into next. Attackers will adopt new tools, geopolitical tensions will create new uncertainties, and AI will continue to accelerate both offensive and defensive capabilities.
The organisations that succeed in building cyber resilience to counter the threats posed in the era of AI, disinformation and geopolitical risk will be those that understand their critical assets, control their identities, reduce unnecessary trust, protect their data, and prepare for disruption before it occurs.
Download the 2026 Global Cyber Risk Mid-Year Review
Read the report to see how your organisation can best protect itself against data exfiltration and build world-class cyber resilience.
Contact us if you need to talk about any topics covered in the report or wish to speak to an expert.
Our experts will discuss the key messages from the report in a webinar on Tuesday 18th August at 11am ET / 4pm BST. You can register for AI, Identity and Trust: Secure the Foundations of Cyber Resilience in 2026 today.
2026 Global Cyber Risk Mid-Year Review
The 2026 Global Cyber Risk Mid-Year Review describes the state of the global threat landscape and reveals that cybercriminals are increasingly adopting an extortion-led business model to monetise stolen data, identities, and cloud access rather than relying on ransomware and data encryption.

















