Kroll

44 stats3 reports

All Statistics

72% of organizations believe they can respond to an incident within 1–24 hours.

Incident ResponseOperational Readiness

51% of organizations cite differing risk tolerance as the leading cause of gaps in threat prioritization.

Risk ToleranceThreat Prioritization

48% of businesses say the CEO now makes the final decision on cyber budgets.

Budget

Only 12% of companies feel "completely prepared" to address the global patchwork of data privacy laws.

RegulatoryComplianceData privacy Legal

The most common cybersecurity threats reported include malware (44%) and AI-powered exploits (28%).

Cybersecurity threatsMalwareAI-powered exploits

Cybersecurity threats rank among the most significant business challenges to organisations (47%).

Cybersecurity threats

35% of financial services professionals identified political instability as a challenge to supply chain assessment.

Political instabilitySupply chainFinancial services

44% of financial and professional services organisations use AI for identifying risk signals.

AIFinancial services

Nearly half of financial services professionals (49%) say keeping up with regulatory changes is the biggest challenge in sanctions compliance, up from one-third (34%) in 2023.

Sanctions complianceRegulatoryFinancial services

55% of organizations are cutting or not increasing investment in red and purple teaming.

Security TestingProactive DefenseBudgetInvestmentRed Teaming

94% of organizations view cybersecurity as a primary business risk.

CybersecurityBusiness Risk

59% of organizations are increasing spending on cloud and third-party security.

Cloud SecurityThird-Party SecurityBudgetSpendingInvestment

Organizations face an average annual recovery cost and downtime of $2.2 million from cyber incidents.

Incident Recovery CostDowntime Cost

Only 10% of organizations have achieved very high cyber maturity.

Cyber MaturityRisk Management

43% of organizations report limited cyber literacy among executives.

Executive Cyber Literacy

39% of organizations experience phishing attacks.

Phishing

80% of organizations increased cybersecurity budgets in 2026.

Budget

99% of organizations have an incident response plan.

Incident Response Plan

Organizations with higher cyber maturity experience 50% less financial impact per dollar of revenue when cyber incidents occur.

Cyber MaturityFinancial Impact

52% of organizations are cutting or not increasing investment in identity access management controls and zero-trust architecture.

BudgetInvestmentIdentity Access Management ControlsZero-Trust Architecture

3% of organizations update incident response plans only after a cyber incident.

Incident Response PlanOperational Readiness

72% of organizations report frequent misalignment between cybersecurity efforts and broader business priorities.

CybersecurityBusiness Priorities

36% of organizations acknowledge gaps in how threats are prioritized.

Threat PrioritizationRisk ManagementThreat Prioritization Gaps

28% of organizations experience business email compromise.

Business Email Compromise

Slightly more than a third (34%) of companies have implemented continuous monitoring for AI, highlighting a gap in managing AI-related risks and compliance failures.

AIMonitoringCompliance

Approximately 90% of organisations report some degree of automation across business activities, with IT and cybersecurity functions becoming highly automated and digitised.

Automation

At least four in 10 business leaders are increasing budgets, expanding teams, upskilling, and/or hiring external help for cybersecurity challenges and data privacy concerns

BudgetData privacy

Only 41% of companies have AI policies and guidance in place, which relates to managing risks associated with AI.

AIAI policies

Nearly three-quarters (74%) of organisations report increased cybersecurity and data privacy concerns.

CybersecurityData privacy

Nearly three-fifths (58%) of professionals in the insurance sector express concern over potential new economic and financial sanctions

Insurance

While 37% of financial and professional services organizations peform sanctions screening entirely in-house, using a third party (34%) and hybrid approach (28%) are becoming increasingly common.

Sanctions screeningFinancial services

Only 38% of financial services professionals are "very confident" in their financial compliance program's ability to detect emerging geopolitical threats.

GeopoliticsComplianceFinancial services

26% of financial services professionals identified geopolitical risk as a challenge to supply chain assessment.

GeopoliticsSupply chainFinancial services

AI is primarily being used to identify suspicious behavior (63%) across financial and professional services organizations.

AIFinancial services

54% of financial and professional services organisations use AI for network analysis.

AINetworkFinancial services

Over 71% of executives across financial and professional services anticipate a rise in financial crime risks in 2025. This is also stated as almost three quarters of senior global financial services professionals.

Financial crimeFinancial services

Nearly half of financial and professional services organizations (49%) expect to invest in AI solutions as part of their efforts to tackle financial crime.

AIFinancial crimeFinancial services

68% of executives across financial and professional services who expect an increase in financial crime risk cite cybersecurity threats and data breaches as the top risk factor.

Data breachCyber threatFinancial services

Over a quarter (27%) of financial and professional services organizations have AI and machine learning as an established part of their financial crime compliance programs, exceeding 2023 levels (24%).

AIMachine learningComplianceFinancial services

Among financial services professionals who were less than "very confident" in their program's ability to assess their supply chains for threats, more than half (56%) of global respondents identified cybercrime as the biggest challenge to their programs in 2025.

CybercrimeSupply chainFinancial services

Only 20% of financial services professionals believe AI has had a "very positive" effect on their financial crime compliance framework – down from 37% in 2023.

AIFinancial crimeComplianceFinancial services

Looking ahead through 2025, just one-third (33%) of financial services professionals say that they are "very prepared" to address geopolitical risks over the next 12 months.

GeopoliticsFinancial services

Globally, just under two in five (39%) senior financial professionals say that they are "very confident" in their organisation's sanctions screening capabilities, with the U.K. (34%) trailing the global average.

Sanctions screeningFinancial services

AI is primarily being used to identify suspicious behavior (63%) across financial and professional services organizations.

AIFinancial services