What Cyber Risks Are Businesses Underestimating?
October 6, 2026

October is Cybersecurity Awareness Month, making it the perfect time for businesses to take a fresh look at their cyber risk exposures. While ransomware and major data breaches often dominate headlines, some of today's most significant risks may be receiving less attention than they deserve.
To better understand the current threat landscape, we asked four experts the same question:
What is the one cyber risk you think businesses are underestimating most right now?
Their answers highlight everything from AI-enabled impersonation and business email compromise to cybersecurity fundamentals and litigation exposure.
AI-Powered Impersonation and Social Engineering
Michael Spinks, CFC, Head of SME Cyber, US
Michael Spinks believes businesses should pay close attention to how artificial intelligence is changing social engineering attacks.
"Although not necessarily underestimated by all businesses, one of the biggest areas of concern right now is AI-enabled social engineering and identity impersonation.
Many organizations still believe that their employees can simply eradicate issues by spotting fraudulent emails with giveaways such as poor spelling or grammar. AI, however, has pretty much eradicated those indicators by enabling threat actors to create professional, personalized, and convincing communications at scale.
We are increasingly seeing not only deep-fake audio, but also video impersonation with fake supplier communications targeting senior decision makers in a business. AI is therefore not necessarily being used to exploit technical vulnerabilities, but human trust."
AI continues to reshape how cybercriminals approach social engineering. For many organizations, strengthening verification processes may become just as important as strengthening technology controls.
Don't Overlook the Fundamentals
William Altman, CyberCube, Director of Cyber Threat Intelligence Services
While new threats often generate the most attention, William Altman warns against losing sight of long-standing cybersecurity weaknesses.
"The data is consistent: most successful intrusions still trace back to the fundamentals, which includes unpatched vulnerabilities, weak or reused credentials , missing multi-factor authentication, and access permissions that have sprawled over time without ever being cleaned up.
AI-enabled agentic ransomware deserves attention, but it shouldn't crowd out focus on fixing foundational control failures, which remain the primary entry points that attackers exploit.
My reminder to businesses: do not let the novelty of what's emerging distract from what's already known to work against you."
Emerging threats deserve attention, but strong cybersecurity fundamentals remain one of the most effective ways to reduce cyber risk.
The Continuing Threat of Business Email Compromise
Matt Massino, Coalition, Inc., Business Development Team Lead - North East
According to Matt Massino, one of the most underestimated cyber risks continues to be business email compromise (BEC).
"Businesses are still underestimating the risk sitting in their inboxes.
Business email compromise attacks don't require sophisticated malware or a highly technical exploit. Instead, they rely on trust and a well-timed request.
BEC and funds transfer fraud often appear as legitimate business activity. This means that businesses need to invest in both strong email security technologies and security best practices to prevent related losses."
Because these attacks frequently mimic normal business communications, they can be difficult to detect. That is what makes strong internal processes and employee awareness so important.
The Litigation Risk Most Businesses Aren't Planning For
Carolyn Purwin Ryan, Mullen Coughlin LLC, Partner
Cyber incidents don't just create operational and security challenges. According to Carolyn Purwin Ryan, they can create legal exposure from the very beginning, making litigation preparedness an important part of ongoing cyber risk management.
"Litigation risk.
Businesses still tend to think of litigation as something that happens after a cyber incident. I think that's a mistake. The litigation case is being built while the incident is happening.
Every decision can become an exhibit: what you knew, when you knew it, what your policies required, whether you followed them, what data you retained, and what you told regulators, customers, and insurers."
Her perspective serves as a reminder that cyber risk extends beyond technology. Response decisions, communications, and documentation can all play a role in what follows an incident.
Key Considerations for Businesses
Although each expert identified a different concern, a common theme emerged: cyber risk extends far beyond technology alone.
People, processes, communications, governance, and legal considerations all play a role in an organization's overall cyber resilience. As businesses continue to navigate an evolving threat landscape, understanding where risks exist and taking practical steps to address them can help strengthen preparedness and support long-term resilience.
Cyber threats will continue to evolve, but businesses don't have to navigate them alone. Working with a trusted advisor can help you better understand your risks, evaluate your cybersecurity and cyber insurance strategies, and make informed decisions to move forward with confidence.


