Cyber Threats the Top Business Concern as AI Heightens Risk: Travelers Risk Index
The rapid growth and lack of governance or regulation in the use of artificial intelligence has once again made cyber threats the top concern among businesses.
According to the latest Risk Index from insurer Travelers, 58% of respondents said they worry a great deal or some about cyber risks. The concern outpaced those involving economic or geopolitical risks.
Cyber threats ranked as the top overall business concern for the fifth time in eight years.
AI is a double-edged sword, it appears. While the technology is used by businesses to improve decision-making and efficiency, it is also being used by hackers. The cyber-threat landscape is being transformed faster than many businesses can respond. While an overwhelming 89% said AI is used in day-to-day operations, only 59% said business practices have been developed for employees’ use of AI.
“The message is clear: Organizations of all sizes should treat cyber threats, especially AI-related cyber risk, as a core business issue and take steps to strengthen defenses,” Menefee added.
Fifty-five percent of the 1,202 U.S. business insurance decision makers said a security breach or cyber event involving AI was a concern. AI in the wrong hands to exploit system vulnerabilities or create phishing or social engineering schemes are top-of-mind for respondents – as is the retention of company data to train AI models.
However, heightened cyber risk seems to have increased the take-up of cyber insurance and increased cybersecurity investments. Insurance is purchased by 70% of businesses, according to respondents. This is the highest percentage since the index turned cyber-focused in 2018, Travelers said. Of the business leaders surveyed, 92% expressed confidence in insurance carriers as a source of cybersecurity expertise and guidance.
Companies have also spent more on firewalls, data backups, employees background checks, onboarding/offboarding employees users, and multifactor authentication. But, when it comes to running simulations of cyberattacks or incident-response plans, there is room for improvement, according to survey results.