Marsh, a global insurance broker and risk adviser, has released its Global Cyber Loss Trends Report, offering a detailed view of how cyber risk is evolving across Europe. The report points to a year-on-year drop in the number of cyber incidents recorded in 2026, suggesting some progress in cyber security practices and a reduction in widespread, systemic events.
Yet the lower volume of incidents does not signal a weaker threat environment. The report makes clear that the seriousness of cyber risk remains high, driven by cyber extortion, privacy-related events, expanding third-party vulnerabilities, and the substantial financial consequences that follow major incidents. Based on cyber incident and claims data submitted by Marsh clients during 2025, the findings show that organisations still face a complex and costly risk landscape.
Privacy incidents remain dominant in Europe
One of the most notable findings is the strong concentration of privacy-related losses. Around 73 percent of cyber damage reports in Europe were linked to privacy incidents, a level that stands well above the global average. This pattern is widely associated with Europe’s distinct regulatory and compliance framework, where data protection obligations significantly shape the reporting and impact of cyber events.
Although the total number of reported incidents declined, the region continues to experience serious exposures tied to data handling, breach notification, and compliance requirements. Privacy risk continues to define the European cyber environment more than in many other markets.
Extortion and third-party exposure continue to raise losses
Cyber extortion remains a major source of disruption and cost. Incidents involving ransomware, stolen data, and related coercive tactics represented about 15 percent of all reported cases. These events continue to generate significant recovery expenses, response costs, and business interruption losses for affected companies.
At the same time, supply chain and third-party weaknesses are becoming more prominent. The report states that 14 percent of cyber damage claims were connected to third parties, including suppliers, business partners, and digital service providers. This continued increase highlights how interconnected business ecosystems can amplify cyber exposure well beyond an organisation’s own internal systems.
Manufacturing and food sectors show increased exposure
Sector-based analysis shows that nearly 20 percent of cyber damage claims came from the manufacturing industry, marking an increase compared with the previous year. The report also identifies a notable rise in claims from the food and beverage sector.
This shift reflects the growing dependence of these industries on both information technology and operational technology environments. As digital systems become more deeply embedded in production and supply operations, these sectors face broader exposure to service disruption, operational shutdowns, and downstream financial loss.
Cyber resilience is becoming a business requirement
The findings also underline the increasing pressure on companies to strengthen compliance readiness, especially as they address GDPR obligations and adapt to the NIS2 Directive, which introduces broader resilience and notification requirements across the European Union.
A strong cyber resilience strategy is no longer optional. Companies are expected to combine solid cyber security controls with incident response planning, including the ability to communicate outside compromised networks during an event. Effective third-party risk oversight and appropriate cyber insurance coverage are also critical parts of a modern resilience framework.
Leadership view on the changing threat landscape
Commenting on the findings, Yeşim Aksüt, CEO of Marsh Turkey, noted that while cyber incident numbers across Europe declined in 2025, the impact and complexity of those incidents remain a serious concern. She emphasized that privacy-related exposures continue to shape cyber risk in the region, while extortion, social engineering, and third-party incidents are creating increasingly expensive and complicated damage scenarios.
She also stressed that as cyber threats develop and regulatory expectations grow, companies must do more than focus on prevention alone. They must be ready to respond quickly and recover effectively when incidents occur. In this process, cyber insurance plays a critical role by providing access to specialist risk knowledge, incident response resources, and financial protection before, during, and after a cyber event.









