The Threat You Are Already Inside

Cybersecurity Is No Longer a Line Item. It Is a Balance Sheet Event.

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
May 2026 · 4 min read
Cover image for Part 1 of The Threat You Are Already Inside series by Garzon Cyber Solutions, showing the title Cybersecurity Is No Longer a Line Item It Is a Balance Sheet Event with four key statistics

Sophos surveyed more than 5,000 IT and cybersecurity leaders across 14 countries for its 2025 State of Ransomware report. The average cost of recovering from a single ransomware incident, excluding the ransom itself, now sits at £1.22 million (€1.41 million). For organisations with fewer than 250 employees, the figure is £510,000 (€588,000). These are not projections. They are observed costs from organisations that lived through it.

Boards still budget for cybersecurity the way they budget for facilities management. A fixed annual allocation. A line item buried somewhere between IT infrastructure and corporate insurance. Something the CISO explains once a year in a slide deck that no one questions.

That model is finished.

The arithmetic boards are not working.

Fortinet’s 2025 Cybersecurity Skills Gap Report found that 52% of organisations experienced cyber incidents costing more than £800,000 (€920,000) in the past twelve months. That figure was 38% in 2021. The trajectory is not ambiguous.

Meanwhile, Swiss Re and Munich Re project that global cyber insurance premiums will reach £13.1 billion (€15.1 billion) in 2026. Munich Re expects the market to more than double by the end of the decade. Insurers are pricing risk that many boards have yet to acknowledge. When the underwriter understands your exposure better than your board does, governance has already failed.

Mastercard’s 2025 research across small and mid-sized businesses found that one in five SMBs that suffered a cyberattack went bankrupt or ceased operations entirely.

One in five.

Multi-extortion changed the calculus.

The board members who still believe that a solid backup strategy protects against ransomware are operating on assumptions from 2019.

Palo Alto Networks’ Unit 42 Global Incident Response Report for 2026 documents a structural shift in how ransomware operates. Encryption appeared in only 78% of extortion cases, down from above 90% in prior years. Attackers are now layering data theft, direct client harassment, and regulatory exposure threats on top of, or instead of, encryption. Restoring from backup does nothing when stolen data is being sent to your customers, your regulator, and your competitors simultaneously.

Unit 42 also found that median ransom demands rose to £1.2 million (€1.38 million), up from £1 million the previous year. But the ransom itself is the smaller number. Sophos reports that 42% of SMBs cite a lack of people and capacity as the primary reason they fell victim to an attack in the first place. The breach is not the only cost. The inability to recover efficiently is where the real financial damage compounds.

Infographic summarising six key statistics from Part 1 of The Threat You Are Already Inside series by Garzon Cyber Solutions: recovery costs, SMB failure rates, incident costs, NIS2 compliance gaps, insurance premiums, and third-party incidents
Six statistics. One conclusion. Cybersecurity is a balance sheet event.

NIS2 made this personal

CyberSmart’s 2026 research across 670 business leaders in nine European countries found that 84% of in-scope organisations are not compliant with NIS2. The directive, which entered enforcement in October 2024, introduces personal accountability for senior leadership. Board members and managing directors in essential and important entities can face individual sanctions for governance failures.

This is not abstract. Marsh McLennan’s 2025 Cyber Risk Intelligence Centre report found that 70% of organisations experienced at least one material third-party cyber incident in the past year. Supply chain exposure, vendor risk, and insufficient oversight of outsourced functions are exactly the governance gaps NIS2 was designed to close. The organisations that treated compliance as a project with a deadline rather than a permanent operating discipline are now the most exposed.

What boards actually need to govern

The World Economic Forum’s Global Cybersecurity Outlook 2026 reports that 65% of large companies now rank third-party and supply chain vulnerabilities as their greatest challenge, up from 54% the previous year. That same report found 87% of leaders identify AI-related vulnerabilities as the fastest-growing cyber risk category.

Boards do not need to become technical. They never did. What they need is the ability to answer four questions with evidence, not assumptions.

What is our actual financial exposure from a cyber incident? Not theoretical. Quantified. Tested against scenarios that reflect how attacks operate today, not how they operated five years ago.

Who is accountable? NIS2 requires named individuals with defined responsibilities. If the answer is to point at the CISO and hope for the best, the governance model is incomplete.

What does our insurance actually cover? Cyber insurance policies are tightening exclusions. War clauses, infrastructure failure carve-outs, and minimum security control requirements are becoming standard. The board that has not reviewed its policy wording in the past twelve months may discover its coverage is narrower than it assumed.

Can we prove it? Regulators and insurers are moving beyond policy documentation toward technical evidence. ENISA’s 2025 threat landscape catalogued 4,875 incidents across the EU in a single twelve-month period. The organisations that can demonstrate operational resilience through evidence, not paperwork, will be the ones that retain coverage, pass audits, and recover faster.

The commercial reality

Cybersecurity is no longer an IT function with a reporting line to the CTO. It is a board-level commercial risk with direct implications for revenue continuity, regulatory standing, insurance viability, and market reputation.

The organisations that understand this are not spending more. They are spending differently. Investing in governance architecture that connects security operations to board oversight. Building compliance frameworks that produce evidence, not just documentation. Securing the specialist talent to operate these capabilities at the pace the threat environment now demands.

Marsh McLennan found that organisations with robust incident response plans are 13% less likely to experience a material cyber event. That is not a technology advantage. It is a governance one.

The question for every board is not whether a cyber incident will affect the balance sheet. It is whether the board will have seen it coming, and whether the governance structure in place will determine whether the organisation recovers or becomes another statistic.

This is Part 1 of "The Threat You Are Already Inside," a five-part series examining how cybersecurity risk intersects with every level of the organisation. Part 2 examines why the CISO’s detection architecture is facing the wrong direction.

Garzon Cyber Solutions provides cybersecurity advisory, compliance architecture, and specialist recruitment for organisations building integrated security capability.

Where does this sit on your own risk register?

A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.

Start the Conversation →
#CyberSecurity#ThreatIntelligence#Leadership#Governance#RiskManagement#GarzonCyberSolutions