Nearly three in ten organizations worldwide experienced at least one successful cyberattack over the past year, according to the Hiscox Cyber Readiness Report 2026 published September 15. The report, based on responses from 6,800 security decision-makers across the UK, Europe and the US, found that these incidents inflicted substantial financial, operational and human costs on victims. Companies that fell prey to attacks reported facing an average of four separate incidents during the 12-month period.

UK-based companies were hit hardest, with 38% reporting successful attacks, while US organizations experienced the lowest rate at 20%. Each cyber incident cost organizations roughly $52,000 on average, though the figure varied dramatically by country—Italian firms faced the steepest average cost at $134,138 per incident. Operational disruption proved severe, with the global average downtime following an attack reaching 32.8 hours. Among attack victims, 32% reported delays to growth initiatives or new business efforts, 31% cited higher staffing or external expert costs, 30% saw negative impacts on financial performance or credit ratings, 29% lost business opportunities or partnerships, 28% faced financial penalties, and 26% suffered negative publicity. Beyond financial and operational damage, over two-thirds of victims—69%—reported employee burnout, elevated stress levels, or toxic workplace culture following a cyberattack.

Keven Knight, CEO of Talion Cyber Security, said the findings "should serve as a wake-up call for business leaders." Knight explained that downtime extends far beyond locked computers, encompassing "disruption to service, disruption to employees and their ability to perform their jobs, plus disruption to customers because they are unable to access the services or goods an organization provides to them." According to Knight, every second of downtime drains company finances, making cyber risk "something board members and business leaders should never overlook."

In response to escalating threats, businesses are investing approximately $51,000 annually on average to strengthen cyber defenses, the Hiscox study found. These investments focus primarily on refreshing employee cybersecurity training (62%), bringing on additional cybersecurity staff (55%), and acquiring new software and tools (51%). Notably, 32% of respondents revealed their organizations now tie executive pay or performance measures directly to cybersecurity results. Companies are also taking concrete steps to secure AI tools deployed in their operations, including upskilling staff in AI and cybersecurity (33%), expanding AI awareness programs (33%), reviewing cyber insurance to ensure AI risks are covered (32%), and planning regular AI audits (31%). Hiscox noted that "businesses are less concerned about speculative future AI scenarios than practical risks that already exist today," including corrupted training data, vulnerable third-party tools and reduced human oversight. The combination of rising attack frequency and mounting operational costs underscores why organizations are now linking leadership accountability directly to security outcomes. For executives accustomed to treating cybersecurity as an IT issue, the shift toward compensation incentives tied to defense effectiveness signals a fundamental recalibration of risk ownership at the highest organizational levels.