惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
博客园 - 【当耐特】
博客园_首页
The Cloudflare Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Apple Machine Learning Research
Apple Machine Learning Research
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
雷峰网
雷峰网
量子位
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
IT之家
IT之家
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
V
Visual Studio Blog
F
Fortinet All Blogs
Martin Fowler
Martin Fowler

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Cyber is the Number One Global “People Risk,” Says Marsh
Phil Muncaster · 2026-04-30 · via www.infosecurity-magazine.com

Cyber-related challenges dominate the top 10 people risks highlighted in a new global survey from Marsh.

The insurance broker’s 2026 People Risks report is compiled from interviews with over 4500 HR and risk professionals in 26 global markets.

Technological change and disruption was cited most frequently in the top 10 risks.

“Cyber-threat literacy” placed first while tech skills shortages, such as those in cyber and AI, came in at number three.

“Mindset barriers to AI adoption” came sixth. This includes limited knowledge of AI risks and mitigations, and workforce non-compliance with AI regulations and policy.

Mishandling of data and IP was placed seventh.

Read more on employee-related risk: Cost of Insider Incidents Surges 20% to Nearly $20m

Marsh claimed that these factors could together expose organizations to an increased risk of cyber-attacks and breaches, reduce their competitiveness and ability to keep pace with the evolving threat landscape, and damage reputation and trust.

The challenges of low security awareness among employees are well understood but continue to impact global organizations. The US Cybersecurity and Infrastructure Security Agency (CISA) was forced to release new guidance in January to help security teams mitigate insider risk.

Ed Ventham, director of broking at UK cyber-insurance specialist Assured, argued that the focus on cyber-threat literacy, while valid, misses a bigger point.

“The real issue isn’t just whether people understand cyber risk, it’s how things play out when something goes wrong,” he told Infosecurity. “Increasingly, the material impact isn’t necessarily a traditional cyber-attack; it can be a failure in technology performance, systems not behaving as expected or platforms going down. All of these events drive business interruption, operational disruption and, ultimately, real economic loss.”

Business leaders should be more focused on mitigating the business impact of cyber-related incidents, he noted.

“The risk isn’t just incidents occurring,” Ventham continued. “It’s a lack of preparation for when they do, and a lack of understanding or forethought about how quickly they translate into lost revenue, contractual exposure, and balance sheet impact. That’s where boards need to be focusing.”

Why Managing People‑Shaped Risk is Becoming a Competitive Advantage

Managing people-shaped risk effectively is essential to driving competitive advantage, the Marsh report argued.

Some 40% of respondents who did so said they increased workforce productivity and efficiency, while 36% said they achieved faster progress on strategic initiatives such as AI adoption.

Hervé Balzano, president of health and benefits at Mercer, said, "In 2026, resilience depends on how well organizations invest in their people: building the right skills, supporting health and financial security, and redesigning work so humans and technology can perform at their best together.”

To better manage the risks associated with human error, Marsh recommended:

  • Reframing cyber risk to include broader risks such as those to OT, HR and benefits systems, and third-party services
  • Identifying potential exposures via cyber-risk planning
  • Recruiting talent with strong cybersecurity skills
  • Creating a cyber-centric culture where security concerns are heard and all staff understand their responsibilities
  • Reducing the causes of fatigue and stress, which can lead employees to drop their guard
  • Ensuring human oversight of critical systems backed by strong governance and insurance cover