← Back to Feed

From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO

August 25, 2026 · Cyble · Severity: CRITICAL

For years, cybersecurity teams have communicated risk through labels such as “High,” “Medium,” and “Low.” Those ratings can help security teams prioritize vulnerabilities, but they often leave CFOs with a more important question unanswered: What does the risk actually mean for the business financially?  That question has become harder to ignore as the threat landscape accelerates. Cyble’s 2025 threat predictions, published as the year unfolded, provide a useful illustration. More than 80% of the threats Cyble forecast—including AI-driven ransomware and complex supply-chain attacks—materialized as anticipated.   It was observed that dark-web discussions about using large language models for phishing, automated social engineering, and ransomware negotiation as early as six months before AI-powered ransomware became a mainstream concern.  From Threat Signals to Financial Exposure  Cyble’s 2025 research identified several trends that demonstrate why qualitative risk scores are no longer enough.  Ransomware incidents increased by 52% in 2025, according to Cyble's analysis. Cyble's full-year 2025 report recorded 6,604 ransomware attacks, compared with 4,346 in 2024. December 2025 alone recorded nearly 731 attacks, the second-highest monthly total of the year, surpassed only by February.  The FBI and CISA also issued joint warnings regarding Medusa ransomware, including the use of AI to streamline intrusion, escalate privileges, and evade detection. The EU SOCTA 2025 report similarly identified an increase in ransomware activity. Cyble also documented 57 new ransomware groups, 27 new extortion groups, and more than 350 new ransomware strains during 2025 alone.  At the same time, ransomware affiliates proved remarkably adaptable. Cyble also documented 57 new ransomware groups, 27 new extortion groups, and more than 350 new ransomware strains during 2025 alone.  International disruption operations targeted several ransomware...

Key Takeaways

  • Cyble advises translating cyber risk from qualitative ratings like high or medium to financial terms that CFOs and business leaders understand.
  • Organizations should review the full article for complete details and implement relevant security measures.
  • Organizations should review the full article for complete details and implement relevant security measures.
☕ Buy a Coffee