Businesses fear cyberattacks more than anything else, driven by AI and supply chain worries
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Industries
- Finance
- Reported by
- 1 outlet
An article from
Dive Brief
Many companies still aren’t preparing thoroughly enough to face a hack, the insurance firm Travelers said in a new report.
Published Sept. 23, 2026
Dive Brief:
- Cybersecurity is the issue that concerns business leaders the most in 2026, the insurance firm Travelers said in a report published on Tuesday.
- AI is a major part of why cyber risks loom so large, the report found.
- Travelers recommended several steps that businesses can take to minimize their risk exposure.
Dive Insight:
Companies are more aware than ever before of the multitude of cybersecurity threats they face. “Confidence that companies can navigate cyber events is increasing,” Travelers said in its report. “But AI is rewriting the threat landscape faster than many companies can respond.”
Security breaches topped the list of cyber-specific concerns that business leaders voiced, with 56% of them citing it as a source of worry. Following close behind were breaches involving AI (55%) and revenue losses stemming from vendor-related incidents (53%). Both of those threats have multiplied in recent years as AI has become more ubiquitous and supply chains have become more complex.
Within the AI threat environment, businesses are most concerned about attackers using AI to exploit vulnerabilities (56%), threat actors using AI for social engineering (54%) and AI models inappropriately accessing sensitive corporate data (52%). Fewer than half of leaders said they worried about “inaccurate output from AI tools leading to poor business decisions.”
While research into AI governance has produced varied results, Travelers’ report paints a stark picture of how mature that work is. “Nearly 9 in 10 business leaders surveyed report that at least some portion of their workforce uses AI tools on a day-to-day basis,” the firm said, “yet fewer than 6 in 10 have formal practices in place to govern it.” Nearly half (47%) of businesses said they were somewhat or very worried about a lack of visibility into their organization’s AI use.
Travelers found that different industries were worried about slightly different cybersecurity threats. Many healthcare providers worried about a computer glitch that knocked systems offline, while manufacturers largely worried about hackers gaining access to financial accounts. Retailers expressed fears about hacks stemming from intrusions into their vendors.
Preparation is the key to avoiding major consequences from a cyberattack, Travelers said, and the firm added that some of its results “tell an encouraging story.” Eight in 10 businesses said they use firewalls, and three-quarters said they diligently update and patch their software, according to the report.
But many companies aren’t adopting “more advanced defenses,” according to Travelers. Barely half of respondents said they simulate cyberattacks to identify vulnerabilities, and half of companies don’t have a contract with an incident-response firm. Four in 10 businesses don’t have a written plan for dealing with a cyberattack, the report found.
Originally published by Cybersecurity Dive. © Cybersecurity Dive. Written by Eric Geller.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-23 15:09 UTC
Related stories
- Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
BleepingComputer · 2026-10-08
- Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The Hacker News · 2026-10-08
- Major rules for federal contractors handling sensitive data are nearing the finish line
CyberScoop · 2026-10-07
- Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
The Hacker News · 2026-10-07
- Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
The Hacker News · 2026-10-07