EY

16 Sep 2026

EY says 36% of corporate assets remain exposed to cyber risk

  • RE+D Magazine

Businesses are entering a new era of cybersecurity and cyber resilience, as the rapid development of artificial intelligence creates new capabilities for defenders while also providing cyber attackers with new tools, according to EY’s latest study, the “2026 Global Cybersecurity Leadership Insights Study.”

The EY study highlights the challenges organisations face in an environment characterised as NAVI (Non-linear, Accelerating, Volatile and Interconnected).

The study is based on the views of more than 800 Chief Information Security Officers (CISOs) and cybersecurity executives worldwide and examines 475 different categories of digital assets. A key finding is the concept of the “vulnerability zone,” which encompasses, on average, 36% of an organisation’s assets.

What Is the “Vulnerability Zone”?

The vulnerability zone refers to assets characterised by low visibility and inadequate monitoring. In other words, these are elements of an organisation’s digital ecosystem that are not sufficiently monitored and can therefore provide easier entry points for cyberattacks.

The highest exposure rates are found among:

  • Operational technology (OT) and physical assets: 57%
  • Ecosystems and third-party partners: 49%
  • Artificial intelligence systems and tools: 47%
  • Network infrastructure: 38%

The picture also varies significantly by industry. The infrastructure sector has the highest proportion of assets in the vulnerability zone, at 71%, followed by metals at 67% and health sciences at 64%.

The heightened exposure of sectors that rely on operational technology systems is particularly significant, as OT assets can be used as entry points, allowing attackers to carry out lateral movement—moving from one system to another until they gain access to their ultimate targets.

The “Secure Creators”

The study also identifies significant differences in organisational readiness. A distinct category is represented by “Secure Creators,” organisations that implement more advanced cybersecurity practices and technologies.

In these organisations, only 30% of assets are located within the vulnerability zone, compared with 42% among the remaining participants, which the study classifies as “Prone Enterprises.”

This difference highlights the importance of systematically cataloguing, maintaining visibility over and continuously monitoring an organisation’s entire portfolio of digital assets.

Artificial Intelligence Is Changing the Landscape

A key factor in the new cybersecurity environment is frontier AI, referring to the most advanced forms of artificial intelligence. Sophisticated models can be used to identify vulnerabilities and conduct more targeted attacks. At the same time, AI systems themselves are creating new areas of exposure for businesses.

The rapid evolution of AI tools, the uncontrolled use of GenAI applications outside approved corporate channels, and the development of agentic AI, which creates more digital identities and connections, are increasing the complexity of monitoring.

Indicative of the situation is the fact that 70% of cybersecurity professionals believe that the most significant risks lie in “blind spots,” referring to assets that are not adequately monitored.

At the same time, only 43% of respondents use automated processes to identify and catalogue assets, while fewer than half are confident that their asset inventories are complete and up to date.

Businesses Do Not Feel Prepared

Despite the rapid evolution of cyber threats, organisational preparedness remains limited. Only 45% of CISOs say they feel prepared to respond to cyberattacks that leverage artificial intelligence.

Readiness is even lower when it comes to quantum attacks, with only 21% of executives saying they are prepared. These findings highlight the gap between the pace at which technologies are evolving and organisations’ ability to adapt their defences in a timely manner.

Six Priorities for Cyber Resilience

EY recommends a series of measures to strengthen organisational resilience:

Continuous and automated asset inventory management, enabling businesses to maintain real-time visibility of their assets and identify areas of exposure.

Closing security gaps across the entire attack surface.

Defining and protecting the “minimum viable enterprise,” meaning the critical functions that must remain operational even in the event of a severe cyberattack.

Accelerating investment in modern cybersecurity technologies and practices.

Continuous management of third-party and supplier risk, with particular emphasis on identity.

Strengthening the security of perimeter devices and networks as a fundamental component of an organisation’s overall resilience strategy.

Panagiotis Papagiannakopoulos, Partner at EY Greece and Head of Cybersecurity Services, notes that frontier AI is reshaping organisational priorities and creating a need for a comprehensive strategic shift.

According to Mr Papagiannakopoulos, senior business executives are being called upon to accelerate the adoption of AI in defensive cybersecurity operations, enhancing visibility, automation, and the early detection and response to threats.

The central message of the study is that cyber resilience is no longer solely about protecting systems against known threats. It requires continuous visibility across the entire digital environment, automation, and the ability to adapt rapidly to evolving risks—particularly as artificial intelligence simultaneously transforms both the offensive and defensive sides of cybersecurity.





By browsing this website, you agree to our privacy policy.
I Agree