
The cyber-extortion landscape is expanding in scale and becoming harder to assess through traditional organisational boundaries. For example, Orange Cyberdefense’s latest Security Navigator findings show that cyber-extortion victims have tripled since 2020 to roughly 19,000 organisations, while the finance and insurance sectors recorded a 71% increase in incidents.
The more consequential shift is how organisations need to think about the dependencies connecting them. Cloud providers, software platforms, managed services and third-party suppliers can create links between businesses that are not always visible through conventional risk assessments.
Charl van der Walt, Head of Security Research at Orange Cyberdefense, describes this as a dense web of interdependence, where a weakness in one part of the ecosystem can create exposure elsewhere.
Security Navigator 2026 found a 71% jump in cyber-extortion incidents in finance and insurance specifically. What’s driving that sector-specific spike, and is it opportunistic or targeted?
Firstly, we argue that the shape of incidents across industries emerges because the attacks are largely opportunistic. Finance as an industry has always ranked high because it’s large and highly digitised. Swings in numbers are not uncommon, and we rarely see the overall ranking of a sector change dramatically year on year.
This year we further argue in the Navigator that the increase in finance and insurance occurred mostly in the USA and the Republic of Korea. Specifically for finance and insurance, the Republic of Korea accumulated 29 victims after seeing no victims previously.
One prominent actor in this sector, Qilin, claimed nearly all victims (27) in this industry in the Republic of Korea. This might point to a common platform or a common service provider that was compromised.
You’ve said the “supply chain” is no longer linear. It’s a web where a single weak vendor can cascade into mass compromise. For a CFO or risk officer, what does that mean for how they should actually be underwriting third-party and counterparty risk today compared to, say, five years ago?
We think that renowned cybersecurity pioneer Dr Dan Geer Jr. sum this best in his writing of the powerful ‘A Rubicon’ paper published in 2018 that is very true and relevant, where he cited that: “dependence is the wellspring of risk; the fact that you yourself may not depend on something directly does not mean that you do not depend on it indirectly. We call this transitive reach of dependence ‘interdependence,’ which in cybersecurity is known as the nature of ‘correlated risk.”
Several incidents illustrate the scale of this interdependence:
- Cl0p’s exploitation of the Cleo managed file-transfer vulnerability accounted for approximately 18% of all cyber-extortion victims recorded in the first quarter of 2025.
- Research indicates that multi-party “ripple events” can produce median losses more than 10 times higher than typical single-party breaches.
Five years ago we were thinking in terms of questionnaires, certifications, annual assessments, individual vendor scores: “How mature is this supplier’s cybersecurity?”
Today we need to think in terms of criticality + connectivity + financial impact + concentration + fourth-party dependencies + substitutability: “If this supplier (or something underneath it) fails, what happens to us, how much could we lose, how quickly can we recover, and how many of our other exposures fail at the same time?”
We argue that this change actually requires a fundamental re-orientation: Instead of asking only how we can offset our business risk (e.g. through insurance), we also need to consider how we can improve the system’s overall resilience since we are interdependent with the supply web.
Strategic technology procurement also comes into play here. Country of origin, jurisdiction, export controls, sanctions, law-enforcement access and the possibility of service denial can therefore become relevant counterparty-risk considerations alongside technical security.
You’ve framed 2026 as requiring a “wartime mindset” in cybersecurity, with a shift from blame to collective resilience. What does that shift look like in practice inside a boardroom?
In a war, even the corporate board understands that the business is inextricably linked to the conflict, and the outcome of the conflict. The board needs to recognise that conflict in cyberspace is impacting society and the economy overall, and the business depends on those domains for its success and survival. It should be asking questions about how and where such dependencies lie, and how they can be managed.
Another wartime shift goes from asking “Who failed?” to asking “How do we become more resilient?” A resilience-oriented organisation focuses on conditions, decisions and recovery rather than individual blame. It seeks to understand why an incident succeeded, whether warning signs were visible, how information flowed and how quickly the organisation adapted.
Boards should ensure that decision rights are established before a crisis, understand how incidents escalate, test recovery processes, examine critical dependencies and verify that security, operations, legal, communications and executive teams can act from a shared picture during an event.
SMEs account for roughly two-thirds of cyber-extortion victims, but they sit inside the supply chains of much larger institutions. Should a bank or insurer be assessing its own risk based on the security posture of its smallest vendors now?
Simply put, yes. But beyond that, our earlier point about contributing to the resilience of the wider system suggests that banks and insurers should be asking how they can contribute to improving the security and resilience of SMEs in their web. A small vendor may become strategically important if it has privileged access, supports critical operations, processes sensitive information, provides services to multiple institutions or relies on widely shared technology platforms.
Attackers often target points of concentration rather than individual organisations. A seemingly minor supplier can become the pathway through which risk spreads across an entire network of customers. The critical question is not whether a supplier is small. It is whether the organisation understands what that supplier connects to, what would happen if it failed, how quickly exposure would be detected and whether essential services could continue while recovery takes place.
Your report frames cybercrime as increasingly entangled with state actors and hacktivism. For institutions in Southeast Asia specifically, how should that geopolitical convergence change the way a risk committee thinks about attribution and response?
Two trends are clear:
- The Navigator recorded 143 unique cyber-extortion victims across eight Southeast Asian countries between October 2024 and September 2025, up from 103 in the previous reporting period (39%). Four Southeast Asian countries entered the victim dataset for the first time during that reporting period. Cybercrime (especially cyber extortion) is growing everywhere and Southeast Asia is no exception.
- Establishment (politically motivated state-aligned) hacktivism is increasingly an attribute of modern geopolitical conflict worldwide. It is accelerating and also escalating toward more visible physical impacts.
These threat categories are converging with regards to targets, techniques and impacts. They increasingly overlap with state activity and are both highly opportunistic in nature.
The result is that every organisation is potentially a target, and the distinctions between different types of actors are becoming less meaningful to threat and risk management – which means that simple, actor-oriented, sector-based intelligence and threat assessments are simply too naive now to serve as useful predictors.
For risk committees, this supports a graduated attribution model rather than a single verdict. Confidence in the technical facts of an incident may be high while confidence in the actor’s identity, motivation, or state relationship remains moderate or low.
If a CIO or board member reads only one number from Security Navigator 2026 before their next risk committee meeting, what should it be, and what decision should it change?
The number is 45% – the increase in observed cyber-extortion victims compared with the previous edition.
Risk committees should elevate cyber-extortion resilience as a board-level priority, with explicit oversight of recovery readiness, operational continuity, and the investment required to sustain operations during an extortion event.
Cyber Extortion is a proxy for other security threats. Tackling this one central issue will also cover a multitude of other threats and risks.




