Articles 3 min read

What Every Business Leader Should Know About Cyber Risk Today

Cyber threats have changed significantly in just a few years. Attackers are increasingly using legitimate credentials rather than trying to break through traditional security controls. Cloud platforms, third-party relationships and expanding digital ecosystems have created more ways to access an organization’s systems and data. Artificial intelligence is making social engineering faster and more convincing. At the same time, employees are managing more accounts, applications and online interactions than ever before, creating additional opportunities for cybercriminals to exploit. Together, these shifts are making identity security, third-party cyber risk and employee awareness increasingly important components of cyber risk management.

The fundamentals of cybersecurity remain important, but organizations also need to consider whether their security programs reflect how attacks happen today. Effective cyber risk management requires understanding who has access, where exposure exists and whether employees and security teams are prepared to recognize and respond to new cyber threats.

cybersecurity professional working on a laptop

How the Cyber Threat Landscape is Changing

Ransomware, endpoint protection and network security remain critical. But today’s attack surface extends much further, encompassing identities, cloud platforms, third-party relationships and increasingly convincing AI-enabled social engineering.

Attackers are taking advantage of automation, publicly available information and increasingly convincing impersonation techniques to target organizations of all sizes. Supply chain attacks continue to create ripple effects across industries, while cybercriminals increasingly rely on compromised credentials or manipulate employees into granting access rather than attempting to bypass technical controls.

As technology continues to advance, organizations must recognize that the threat landscape is no longer defined solely by malware or network intrusions. It is increasingly shaped by trust, identity and human behavior.

Artificial intelligence is transforming how organizations operate, but it is also changing how cybercriminals conduct attacks. According to IBM’s 2026 Cost of a Data Breach Report, one in four malicious breaches were AI-enabled, a 56% increase from the prior year.

Phishing emails, fraudulent messages and social engineering campaigns can now be developed faster and with greater sophistication than ever before. Attackers can use AI tools to create convincing communications that imitate executives, vendors, colleagues or trusted organizations, making it more difficult for employees to identify malicious activity.

Poor grammar, unusual phrasing and other warning signs employees may have been trained to recognize are becoming less reliable as AI helps attackers create more polished and personalized communications.

As these attacks become more convincing, people remain one of the most targeted entry points into an organization. Employee awareness and judgment are therefore just as important as the technology designed to detect and stop malicious activity.

At the same time, security teams can use AI and automation to analyze activity, identify suspicious patterns and help detect threats that may be difficult for employees or traditional security tools to recognize.

Organizations, therefore, should consider AI from both directions: how attackers are using it and how their own security capabilities can evolve in response.

For years, cybersecurity strategies focused heavily on protecting networks and devices. Today, identity has become one of the most valuable assets organizations need to protect.

On a personal level, individuals are responsible for safeguarding the digital identities that give them access to financial accounts, healthcare information, online services and sensitive personal data. A single compromised password or account can have significant consequences.

For organizations, identity extends far beyond employee login credentials.

Every employee, contractor, vendor and privileged user represents a digital identity that must be properly managed and secured. Organizations need visibility into who has access to critical systems, what information they can reach and whether that access remains appropriate over time.

At the same time, organizations themselves have identities that cybercriminals actively target.

Attackers increasingly impersonate executives, employees, vendors and even entire organizations to deceive customers, redirect payments, gain unauthorized access or damage brand trust. A compromise involving an employee account can create operational challenges, but an attack that successfully exploits a company’s identity can have far-reaching financial, legal and reputational consequences.

The modern-day intersection between personal, employee and corporate identities create opportunities for attackers. A weakness or breach in one area often allows insight and eventually access into other areas. In a recent event, our team saw firsthand how a breach of an executive’s personal identity led to the infiltration of a corporate environment. The combination of the use of common password structures by the individual, and the personal information gathered allowed attackers to impersonate the executive. Fortunately, a fellow employee felt something was off in the communications they were receiving and circled back to confirm the executive’s request. The interaction with the attackers was terminated and corrective action was taken, avoiding what could have been a multimillion-dollar transfer of funds.

As businesses continue to expand their use of cloud technologies, AI platforms and third-party services, identity management has become a foundational component of cybersecurity. Protecting identities today means protecting both the people behind the business and the business itself.

Most organizations depend on cloud platforms, software providers, consultants, vendors and other third parties to operate. These relationships drive efficiency and innovation, but they also introduce additional risk – extending an organization’s cyber exposure beyond the systems it directly controls.

Major supply chain incidents have increased nearly fourfold over the past five years, according to IBM’s 2026 X-Force Threat Intelligence Index. A security issue affecting a third party can quickly impact downstream customers, creating disruptions that organizations may have little control over.

As a result, cybersecurity leaders are placing greater emphasis on vendor due diligence, ongoing risk assessments and visibility into third-party security practices.

Organizations should understand which third parties have access to sensitive systems and information, evaluate the security controls surrounding that access and reassess those relationships as they change.

Organizations continue to invest in cybersecurity tools, platforms and monitoring capabilities, and those investments are essential. However, technology alone cannot eliminate cyber risk and many of the fundamentals of a strong cybersecurity program remain the same.

Multi-factor authentication, appropriate access controls, timely patching, security monitoring and tested incident response plans continue to provide important layers of protection. Security awareness also remains critical, particularly as phishing and impersonation become harder to recognize.

Security awareness training should evolve alongside the threats employees are likely to come across. Recognizing a suspicious email based on obvious spelling errors is no longer enough. Employees need to know how to respond to unexpected requests, verify identities through trusted channels and recognize when something that appears legitimate may warrant a second look.

The strongest cybersecurity programs combine appropriate technology with clear processes, informed employees and defined accountability. When any one of those elements is overlooked, gaps begin to emerge.

What Should Leaders Be Asking?

As the threat landscape evolves, business leaders should consider whether their programs are keeping pace with today’s realities.

Key questions include:

The answers to these questions can identify where an organization’s cybersecurity program has kept pace and where additional attention may be needed.

Keeping Pace with Cyber Risk

Cybersecurity is not a one-time initiative. It is an ongoing commitment to protecting people, identities, information and business operations.

Regularly reassessing access, third-party exposure, employee readiness and security capabilities can help organizations identify gaps before they become incidents. As the threat landscape continues to change, organizations that understand where they are exposed and adapt their defenses accordingly will be better positioned to protect their people, data and business operations.

Withum’s Cybersecurity Consulting Services Team helps organizations assess their security posture, strengthen identity and access management, evaluate third-party risk, enhance security awareness and improve cyber resiliency.

Subscribe to Our Cybersecurity Insights!

Staying ahead of cyber threats starts with staying informed. Beginning October 1, Withum’s Cybersecurity Consulting Services Team will launch a recurring briefing covering emerging cyber threats, real-world incidents, and key risk considerations. Subscribe to our Cybersecurity Insights to receive the latest updates directly in your inbox.

Withum plus signs.

Have Questions or Need Guidance?

For more information on this topic, please contact a member of our team.

Contact Us

Related Insights

Read more
two cybersecurity professionals reviewing a security dashboard.
Why Managed IT Is a Business Strategy, Not Just a Help Desk

For small and midsize businesses (SMBs), technology has become fundamental to nearly every part of the business, from serving customers and processing payments to managing data and keeping operations running. Yet many businesses still approach IT reactively, addressing issues when something breaks rather than managing technology as critical business infrastructure. Artificial intelligence is making that…

Read more
Gears icon on a digital display with reflection. Concept of business process workflow.
How Oversight Gaps Can Develop in Multiemployer Plans

Even in well-run multiemployer plans (“Plans”), oversight gaps can quietly grow over time. In many cases, these gaps are not the result of negligent or disengaged Boards. Rather, they emerge when too much reliance is placed on existing systems, familiarity and routine reduce visibility into how processes actually operate, or technical complexity discourages questions and…

Read more
business continuity
Guide: Business Continuity and Disaster Recovery – Strategic Insights for Operational Resilience