Home > Risks Management and Insurance Magazine > Articles > Cybersecurity: challenges in risk assessment and management

Cybersecurity: challenges in risk assessment and management

15/09/2026

As AI, technological dependence, and the evolution of threats means that cybersecurity has become a strategic risk for companies and institutions, and a rethink of digital risk management and advancing towards continuous resilience models is called for.

Every sector is undergoing an unprecedented technological acceleration that’s transforming the way companies, public administrations, and critical infrastructure operate. This historic milestone has also expanded the risk area that defines its vulnerability. In an environment shaped by AI, global interconnection, and reliance on technology providers, cybersecurity has ceased to be a purely technical matter and is now instead regarded as a fundamental component of business resilience and national security.

“Digitalization has been very rapid and security hasn’t kept pace. The more we depend on digital systems to operate, the greater the impact of any failure or attack,” explains Mar López, CEO of Sofistic and an expert in cybersecurity. The data reflect this trend: incident volume is rising, as is their complexity and severity. The combination of new offensive capabilities, the professionalization of cybercrime, and the use of artificial intelligence by attackers is complicating exposure to threats. “The growth is real and sustained, but what matters is not only the volume, but those cases of high severity are increasing,” López points out.

The main difficulty isn’t just the sheer number of attacks, but their ability to disrupt critical operations. “The difference between a managed incident and a business crisis can be measured in hours of inactivity, loss of customer confidence, reputational impact, among other factors,” he assures.

 

A difficult risk to model

The changing nature of cyber risk makes it one of the most complex to assess and quantify. Compared to other traditional risks, we do not have decades of stable data. The history is short, fragmented, and becomes obsolete from the moment it is generated. Furthermore, threat actors operate almost in real time, which causes detection systems based on known patterns to become quickly obsolete.

Today’s attackers no longer depends solely on a single, large weakness. “They don’t look for a large obvious gap and instead search for small vulnerabilities, which individually may seem harmless, but when combined together can trigger a serious incident,” he explains. Layering speed on top of this further complicates the situation. “The time between the emergence of a vulnerability and its exploitation has been radically reduced, eliminating the margins that traditional models allowed,” he points out.

This means that cybersecurity requires abandoning static models and moving towards dynamic risk management. It can’t be managed solely with static quantitative models and now requires a dynamic risk-based approach, with capacity for continuous monitoring, real-time threat intelligence, and permanent visibility into the exposure area,” it adds.

 

Technological dependence and systemic risk

The concentration on large technology providers means that organizations no longer depend solely on their own systems, but also on an extensive network of providers, platforms, and services, so that a localized incident can become a systemic event. “The greater the dependency, the greater the impact when it fails, whether due to an attack, human error, or a simple update that’s not implemented correctly,” warns the expert. Moreover, the same event can simultaneously affect thousands of organizations, many of them unaware of the extent to which they are part of that same chain of dependency.

“The risk reas is no longer just the organization but the entire ecosystem it operates in,” highlights the Sofistic’s CEO. This reality forces a reconsideration of traditional evaluation models, incorporating a broader view of third parties, critical providers, and technological concentration. Moreover, threats aren’t limited to data theft anymore. “They’re just one part of the story and can even be considered as something occasional or one part of a larger attack, where that data is intended to be used for extortion or access to intellectual property material,” explains López.

One of the most significant risks is operational disruption. A ransomware attack or an intrusion can paralyze essential systems without the need to extract information. In sectors such as energy, healthcare, or logistics, the economic and social impact can be immediate. Another emerging vector is identity impersonation, aggravated by the use of AI. “This isn’t an improvement in conventional fraud, it’s the lack of credibility of the human verification process as internal control,” he points out, referring to the advancement of deepfake technology and voice cloning.

 

Critical infrastructure and state cybersecurity

Critical infrastructure has become one of the priority targets for cyberattacks, and could lead to the disruption of essential services such as energy, transportation, or communications. “They aren’t just another objective within the threat ecosystem. In my opinion, they’re the most coveted target by some attackers,” says López. The threat doesn’t come solely from cybercrime with economic motivations – there are also state-backed actors and groups linked to geopolitical conflicts that seek to position themselves within strategic networks to generate pressure capacity or destabilizing capacity.

“The public image of risk is always lower than the actual reality,” he explains. Growing dependence on technology has put cybersecurity on the national security agenda. “I worked for nine years in the Department of Homeland Security, coordinating the National Cybersecurity Strategy, and even then, it was clear that cyberspace had become a space of confrontation between states,” he recalls. For the expert, the most significant change is that cybersecurity is no longer understood as an exclusive responsibility of the technical departments. “It’s a national security dimension, not just a technological matter.”

 

AI and digital resilience

AI is transforming both offensive capabilities and defensive capabilities in cybersecurity. Attackers use it to automate phishing campaigns, develop more sophisticated malware, and identify vulnerabilities more quickly, while organizations can leverage it to strengthen incident detection and response. “It’s everywhere, in offense and defense, and whoever manages it better has an advantage,” warns the expert.

Against this backdrop, López argues that organizations must evolve from a model based solely on prevention to a digital resilience strategy. To do this, it’s essential to know the exposed assets, prepare the incident response, and strengthen the human factor, since cybersecurity can no longer be the exclusive responsibility of technical departments, but rather a key element to guarantee continuity, trust, and competitiveness.

 

Article collaborator:

Mar López is CEO of Sofistic, an advanced multinational cybersecurity company belonging to Cuatroochenta. She has more than two decades of experience in the field of cybersecurity and has led projects related to the protection of national interests and the digital transformation of the public sector. Between 2012 and 2021, she headed up the Cybersecurity and Disinformation Combat Office of the Department of Homeland Security of the Presidency of the Government of Spain. Subsequently, as an associate director at Accenture, she led cybersecurity programs for public bodies and the health sector.

donwload pdf
Electric generators have more uses than just in a blackout

Electric generators have more uses than just in a blackout

On April 28, 2025, Spain was left without electricity from one moment to the next. The blackout, which paralyzed essential infrastructure and services for hours, shone a light on a key device, the electric generator – our last backup when the network fails. Strictly...

read more
Remote sensors: innovation at the service of prevention

Remote sensors: innovation at the service of prevention

Risk management enters a new technological era thanks to an innovation that facilitates evolving from prevention that's based on periodic inspections to a predictive and continuous model, thereby strengthening industrial safety and anticipating potential failures. The...

read more