Photo credit: Vertigo3d/E+/Getty Images
For its 2026 Global Digital Trust Insights report,1 PwC surveyed 3,887 business and technology executives across 72 countries to understand their cyber concerns and priorities for the year ahead. Here are some key findings.
The impact of geopolitics
- 60% of leaders said they were increasing cyber risk investment in response to geopolitical volatility.
- Only 6% said their organization was “very capable” of withstanding cyber attacks across all vulnerabilities surveyed (ranging from weak authentication to supply chain vulnerabilities).
Top 5 threats leaders said their organization was least prepared to address
- Cloud-related threats: 33%
- Attacks on connected products: 28%
- Third-party breaches: 27%
- Quantum computing threats: 26%
- Social engineering: 25%
Measuring the costs of cyber risks
- 27% of respondents said their most damaging breach over the past three years cost their organization US$1M or more.
- 50% said their organization was measuring the financial impact of cyber risks to either a significant or large extent.
Budgeting
- 78% of respondents said they expected to increase their cyber budget.
- Only 24% said they were spending significantly more on proactive measures than on reactive ones.
- 67% said their organization has an even proactive/reactive cost ratio.
Top 5 cyber investment priorities
- AI: 36%
- Cloud security: 34%
- Network security and zero trust: 28%
- Data protection/data trust: 26%
- Threat management: 24%
Top 5 agentic AI priorities
- Cloud security: 39%
- Data protection: 39%
- Cyber defence and operations: 38%
- Security testing: 31%
- Cyber governance, risk, and compliance: 30%
Managing AI data risk
For AI solutions to be effective, the data sets used must be high quality, secure, and verified. But…
- Only 6% of respondents said their organization had implemented all of the data risk measures identified in the survey (ranging from data classification policies to encryption).
Talent and skills gaps
- Top 2 challenges to implementing AI for cyber defence: a lack of knowledge and a lack of relevant skills.
- 53% said they were prioritizing AI and machine learning tools to help close capability gaps.
- 48% of respondents whose organization had experienced a major attack said they were prioritizing managed services to address cyber talent gaps.
Quantum computing
- 49% of respondents said their organization hadn’t considered or started implementing any quantum-resistant security measures.
- <10% included quantum readiness in their top three budget priorities.
- Only 3% said they had implemented all quantum-resistant measures surveyed (ranging from data mapping to quantum-resistant encryption).
Top 3 barriers to adopting quantum-resistant cryptography
- Gaps in technical expertise to adopt industry standards: 37%
- Gaps in dedicated quantum computing knowledge and resources: 36%
- Gaps in existing systems and/or data integration challenges: 34%
To access the full report, which includes foundational and future-ready tips for C-suite leaders, visit pwc.com.
Michelle McRae is the managing editor of CPABC in Focus magazine.
This article was originally published in the September/October 2026 issue of CPABC in Focus.