Cyber security
19.05 2026

Neglecting cybersecurity can cause forced downtime and give competitors an advantage

Organizations can no longer view cyber risk as a separate issue; it is an integral part of the business model and growth strategy, writes KPMG cybersecurity expert Mihkel Kukk.

According to Kukk, this means that every technological decision, partnership, or digital service simultaneously creates opportunities for criminals trying to gain access to data. Organizations that succeed are those that can directly link security to business value creation, rather than treating it as a cost, as emphasized in KPMG’s latest report Cybersecurity Considerations 2026. The realization of cyber risks can deal a serious blow to the entire company, meaning this is not merely a localized “back-office IT” problem.

Cyber risks evolve over time and are becoming increasingly complex. One of the biggest shifts is related to the widespread adoption of artificial intelligence (AI) and automation. Security operations are becoming increasingly autonomous—systems detect, analyze, and respond to threats in real time. At the same time, a new layer of risk is emerging: not only user identities but also machine identities (APIs, services, AI agents) are becoming vulnerable. If left unmanaged, attackers may gain access that is difficult to detect. Therefore, traditional identity management alone is no longer sufficient; organizations must create a comprehensive view of all digital identities, whether human or system-based.

Another key trend is the impact of geopolitics on cybersecurity. Supply chains, technology partners, and regulations are no longer neutral, as they may represent direct risks. Organizations must consider where their critical technology originates, what dependencies exist, and how international tensions affect service availability and security. This means cybersecurity and procurement strategy must be tightly linked, and excessive reliance on a single partner or region should be avoided for critical services.


Employee cyber skills help mitigate risks

At the same time, cybersecurity has become a cornerstone of organizational resilience. The question is not only about preventing attacks but also responding to and recovering from them. A cyber incident essentially constitutes a business disruption, with impacts ranging from financial loss to reputational damage. Therefore, organizations must invest not only in defensive measures but also in tested recovery capabilities. Crisis exercises, backup strategies, and clear responsibility models are no longer “nice to have” but essential.


The regulatory environment adds another dimension

The EU’s Network and Information Security Directive (NIS2), the Digital Operational Resilience Act (DORA), and other regulations increase organizational accountability and require clear evidence that risks are managed. This is not just about passing audits but about adopting a systematic approach where governance, risk management, and compliance (GRC) are integrated into daily management. Organizations that treat regulatory requirements as a strategic tool rather than merely an obligation gain a clear advantage.

A significant challenge also remains at the people level. The shortage of cybersecurity skills will not disappear anytime soon, and organizations must find smart ways to address it. This includes increased automation, developing existing employees, and engaging trusted partners. A hybrid model, where internal and external expertise complement each other, proves most effective.


Strong cybersecurity is a competitive advantage

At the center of all these trends is trust. Digital business functions only when customers, partners, and employees trust systems and data handling. Identity management, data protection, and transparency are no longer technical details but directly tied to brand and reputation. Every cyber incident is a potential trust crisis with long-term impact.

Looking ahead, organizations must also consider the impact of emerging technologies, including quantum computing. Although its practical effects have not yet fully materialized, it is clear that today’s cryptographic solutions may not be sufficient in the future. Organizations that begin planning for a post-quantum strategy early will reduce risks and gain an advantage.

In summary, the key message for cybersecurity in 2026 is simple: security must be strategic, integrated, and business-driven. It is no longer just a defensive mechanism but an opportunity to create competitive advantage and strengthen organizational resilience. Management teams that treat cyber risk as a financial and business risk can make better decisions and investments where they create the most value.

Mihkel Kukk

Cybersecurity Strategic Advisor

KPMG: A properly selected information security standard serves as a quality mark for partners

Companies that rely on external service providers for data processing increasingly face a key qu..

Cyber security

Why Purple Teaming is the Missing Link in Modern Cybersecurity

In today’s cybersecurity landscape, most organizations are caught between two realities: they kn..

Cyber security

Reflections from the Field - A Red Team’s Perspective on Cybersecurity in Estonia

Over the past several years, our red team has conducted extensive offensive security assessments..

KPMG Expert: AI Solutions for Automating Routine Processes Deliver the Quickest Returns

By implementing artificial intelligence, the quickest returns are achieved thro..

AI

KPMG IT Expert: Practitioner-Trainers Make Training Engaging and Practical

IT or cyber security training is more engaging when delivered by trainers who a..

Provide a safe and sustainable business environment for your company. We help build a resilient and reliable digital landscape, even in the face of changing threats.

KPMG Baltics OÜ

+372 626 8700
cyber@kpmg.ee
Ahtri 4, 10151 Tallinn, Estonia
${item.title}
KPMG Baltics KPMG Global Privacy KPMG IT Audit
Email again:

Analysis of employee awareness

Analysis of employee awareness focuses on mapping the skills and increasing the competencies of the weakest link in cyber security: the users, the employees.

Email again:

Threat assessment

Threat assessment is a tactical and technical service that allows a company to get a quick overview of external threats.

Email again:

Maturity assessment

Maturity assessment helps plan IT investments and design further steps to mitigate vulnerabilities and ensure better security.

Email again: