Cyber is the Number One Global “People Risk,” Says Marsh

Cyber is the Number One Global “People Risk,” Says Marsh

Cyber is the Number One Global “People Risk,” Says Marsh

https://www.infosecurity-magazine.com/news/cyber-number-one-global-people/

Publish Date: 2026-04-30 05:10:00

Source Domain: www.infosecurity-magazine.com

Cyber-related challenges dominate the top 10 people risks highlighted in a new global survey from Marsh.

The insurance broker’s 2026 People Risks report is compiled from interviews with over 4500 HR and risk professionals in 26 global markets.

Technological change and disruption was cited most frequently in the top 10 risks.

“Cyber-threat literacy” placed first while tech skills shortages, such as those in cyber and AI, came in at number three.

“Mindset barriers to AI adoption” came sixth. This includes limited knowledge of AI risks and mitigations, and workforce non-compliance with AI regulations and policy.

Mishandling of data and IP was placed seventh.

Read more on employee-related risk: Cost of Insider Incidents Surges 20% to Nearly $20m

Marsh claimed that these factors could together expose organizations to an increased risk of cyber-attacks and breaches, reduce their competitiveness and ability to keep pace with the evolving threat landscape, and damage reputation and trust.

The challenges of low security awareness among employees are well understood but continue to impact global organizations. The US Cybersecurity and Infrastructure Security Agency (CISA) was forced to release new guidance in January to help security teams mitigate insider risk.

Ed Ventham, director of broking at UK cyber-insurance specialist Assured, argued that the focus on cyber-threat literacy, while valid, misses a bigger point.

“The real issue isn’t just whether people understand cyber risk, it’s how things play out when something goes wrong,” he told Infosecurity. “Increasingly, the material impact isn’t necessarily a traditional cyber-attack; it can be a failure in technology performance, systems not behaving as expected or platforms going down. All of these events drive business interruption, operational disruption and, ultimately, real economic loss.”

Business leaders should be more focused on mitigating the business impact of cyber-related…

Source