Cyber Risk Matrix — a Synthesized Board Perspective
Relative severity, incidence of occurrence, and expected loss given occurrence across the current cyber risk universe, synthesized from CISA, NIST, IBM, CrowdStrike, Verizon, Ponemon, FBI IC3, Protiviti, NETSCOUT and other primary industry sources.
As of September 2026
Board composition — 9 sector perspectives:Hyperscale cloud & platform ·
Financial services ·
Industrial / OT & manufacturing ·
Aviation & transportation ·
Healthcare ·
Energy & critical infrastructure ·
Retail & consumer ·
Government & public sector ·
Cyber insurance & risk transfer.
Each CISO perspective carries 25+ years managing enterprise risk at global scale.
Risk category
Severity continuum
LowModerateHighCritical
Incidence
Avg. loss / occurrence
Board insight & primary sourcing
1
Ransomware & Cyber Extortion
Critical severity
Very High
48% of all breaches now involve ransomware
$5.08M
avg. all-in cost / incident
Avg. ransom payment surged to $1.88M in Q2 2026 (median just $150K); 63% of victims now refuse to pay.
Sources: IBM Cost of a Data Breach 2025 · Verizon 2026 DBIR · Coveware by Veeam, Q2 2026
2
Nation-State & Advanced Persistent Threats
Critical severity
Moderate
Targeted, but cloud-conscious intrusions up 266% YoY
$4.44M+
baseline, often understated
Breakout time as fast as 27 seconds; state-nexus actors linked to a record $1.46B crypto theft in 2025. Strategic / IP loss is frequently unquantified.
Source: CrowdStrike 2026 Global Threat Report
3
Agentic AI & AI Agent Risk
High severity — fastest-rising
High, rising sharply
88% of enterprises running agents report ≥1 incident
$4.7–4.8M
avg. AI agent-related breach
70% of enterprises grant agents more access than equivalent human roles; only ~22% treat agents as identity-bearing entities with independent controls. 16,200 AI-related incidents in 2025 (+49% YoY).
Sources: CISA, Careful Adoption of Agentic AI Services (2026) · IBM 2025 · Darktrace / Gravitee / Teleport industry pulse surveys, 2026
4
Software Vulnerability & Zero-Day Exploitation
High severity
Very High
Now #1 initial access vector (31% of breaches)
$4.44M+
tracks breach baseline
CISA's KEV catalog grew 20% to 1,484 entries in 2025; zero-day exploitation before public disclosure rose 42%.
Sources: Verizon 2026 DBIR · CISA KEV Catalog · CrowdStrike 2026 Global Threat Report
5
Cloud, Third-Party & Supply Chain Exposure
High severity
High
30% of breaches involve a 3rd party — 2× YoY
$60B
aggregate global cost, 2025
Longest dwell time of any category — 267 days to identify and contain. Cloud-conscious state-nexus intrusions up 266% YoY as multi-cloud footprints expand.
Sources: Verizon 2025/2026 DBIR · IBM 2025 · Cybersecurity Ventures · CrowdStrike 2026
6
Insider Threats
Medium-High severity
High
~24 incidents / yr at a typical large org
$17.4M
avg. annual cost / org
Per-incident: $780K (compromised credentials), $715K (malicious), $677K (negligent). Avg. 81 days to contain.
Source: Ponemon Institute, 2025 Global Cost of Insider Risks Report
7
Business Email Compromise, Phishing & Social Engineering
Medium severity
Very High
Top vector by volume — 16% of breaches
$3.04B
BEC aggregate — largest single IC3 category
Phishing losses tripled YoY to $215.8M; 86% of BEC losses moved via wire/ACH transfer. AI-enabled BEC losses reached $30M.
Sources: FBI IC3 2025 Internet Crime Report · IBM 2025
8
DDoS & Availability Attacks
Medium-Low severity
Very High volume
8M+ attacks logged in H2 2025 alone
Low–Med.
mainly downtime / reputational
Record 30 Tbps attack observed; 42% of attacks now multi-vector; 20,000+ botnet-driven attacks in a single month (July 2025).
Source: NETSCOUT DDoS Threat Intelligence Report, H2 2025
○ None/Low
◔ Low-Med
◑ Medium
◕ Med-High
● Very High
Harvey ball fill = relative magnitude within this matrix, not an absolute statistical scale.
Cross-cutting accelerant — AI (agentic & generative): rather than a single bucket, AI is amplifying nearly every category above. AI-enabled adversary activity rose 89% in 2025 (CrowdStrike); FBI IC3 logged $900M+ in AI-related fraud losses across 22,000+ complaints; "shadow AI" adds ~$670K to the average breach when AI oversight is absent (IBM 2025); and 32% of CISOs cite AI data-governance risk as their top AI-related concern (Protiviti Top Risks 2026). The board treats agentic AI as both a standalone risk (row 3) and a force-multiplier on ransomware, BEC/social engineering, and vulnerability exploitation.