Kroll
Reports
All Statistics
72% of organizations believe they can respond to an incident within 1–24 hours.
51% of organizations cite differing risk tolerance as the leading cause of gaps in threat prioritization.
48% of businesses say the CEO now makes the final decision on cyber budgets.
Only 12% of companies feel "completely prepared" to address the global patchwork of data privacy laws.
The most common cybersecurity threats reported include malware (44%) and AI-powered exploits (28%).
Cybersecurity threats rank among the most significant business challenges to organisations (47%).
35% of financial services professionals identified political instability as a challenge to supply chain assessment.
44% of financial and professional services organisations use AI for identifying risk signals.
Nearly half of financial services professionals (49%) say keeping up with regulatory changes is the biggest challenge in sanctions compliance, up from one-third (34%) in 2023.
55% of organizations are cutting or not increasing investment in red and purple teaming.
94% of organizations view cybersecurity as a primary business risk.
59% of organizations are increasing spending on cloud and third-party security.
Organizations face an average annual recovery cost and downtime of $2.2 million from cyber incidents.
Only 10% of organizations have achieved very high cyber maturity.
43% of organizations report limited cyber literacy among executives.
39% of organizations experience phishing attacks.
80% of organizations increased cybersecurity budgets in 2026.
99% of organizations have an incident response plan.
Organizations with higher cyber maturity experience 50% less financial impact per dollar of revenue when cyber incidents occur.
52% of organizations are cutting or not increasing investment in identity access management controls and zero-trust architecture.
3% of organizations update incident response plans only after a cyber incident.
72% of organizations report frequent misalignment between cybersecurity efforts and broader business priorities.
36% of organizations acknowledge gaps in how threats are prioritized.
28% of organizations experience business email compromise.
Slightly more than a third (34%) of companies have implemented continuous monitoring for AI, highlighting a gap in managing AI-related risks and compliance failures.
Approximately 90% of organisations report some degree of automation across business activities, with IT and cybersecurity functions becoming highly automated and digitised.
At least four in 10 business leaders are increasing budgets, expanding teams, upskilling, and/or hiring external help for cybersecurity challenges and data privacy concerns
Only 41% of companies have AI policies and guidance in place, which relates to managing risks associated with AI.
Nearly three-quarters (74%) of organisations report increased cybersecurity and data privacy concerns.
Nearly three-fifths (58%) of professionals in the insurance sector express concern over potential new economic and financial sanctions
While 37% of financial and professional services organizations peform sanctions screening entirely in-house, using a third party (34%) and hybrid approach (28%) are becoming increasingly common.
Only 38% of financial services professionals are "very confident" in their financial compliance program's ability to detect emerging geopolitical threats.
26% of financial services professionals identified geopolitical risk as a challenge to supply chain assessment.
AI is primarily being used to identify suspicious behavior (63%) across financial and professional services organizations.
54% of financial and professional services organisations use AI for network analysis.
Over 71% of executives across financial and professional services anticipate a rise in financial crime risks in 2025. This is also stated as almost three quarters of senior global financial services professionals.
Nearly half of financial and professional services organizations (49%) expect to invest in AI solutions as part of their efforts to tackle financial crime.
68% of executives across financial and professional services who expect an increase in financial crime risk cite cybersecurity threats and data breaches as the top risk factor.
Over a quarter (27%) of financial and professional services organizations have AI and machine learning as an established part of their financial crime compliance programs, exceeding 2023 levels (24%).
Among financial services professionals who were less than "very confident" in their program's ability to assess their supply chains for threats, more than half (56%) of global respondents identified cybercrime as the biggest challenge to their programs in 2025.
Only 20% of financial services professionals believe AI has had a "very positive" effect on their financial crime compliance framework – down from 37% in 2023.
Looking ahead through 2025, just one-third (33%) of financial services professionals say that they are "very prepared" to address geopolitical risks over the next 12 months.
Globally, just under two in five (39%) senior financial professionals say that they are "very confident" in their organisation's sanctions screening capabilities, with the U.K. (34%) trailing the global average.
AI is primarily being used to identify suspicious behavior (63%) across financial and professional services organizations.