Cybersecurity emerges as the main threat against which companies feel most vulnerable, scaling from 23% to 40% in just one year, according to the Global Risk Landscape 2026 report prepared by BDO.
The document details that cyberattacks increased by 58% worldwide between 2023 and 2025 and that 68% of executives perceive that crises affect their organizations with increasing speed.
Despite this context, only 9% of companies declare having a "very proactive" risk management, while more than half admit difficulties in identifying the most relevant risk signals and 55% acknowledge that short-term urgencies hinder long-term strategic planning.
However, 99% of organizations state they are driving improvements in their risk management systems for the next three years. In 2026, cybersecurity is at the top of the risk list (40%), followed by artificial intelligence (27%) and geopolitics (25%). In parallel, regulatory risk falls from 35% to 24% and that associated with the supply chain drops from 28% to 24%.
Cybersecurity, a fundamental challenge
The rise of cybersecurity as a priority concern is due to structural deficiencies that go beyond the mere volume of investment, including the late incorporation of specialized cybersecurity teams into digital transformation projects.
Only one in ten teams (10%) participates from the ideation phase of initiatives, while more than half (57%) join in the planning stage and one in four (26%) do so during execution. This late entry implies working when key decisions are already made, compromises security from the design stage, and multiplies vulnerabilities that could have been avoided.
The BDO report also identifies a significant gap between CEOs and technology leaders. Although both groups agree in identifying cybersecurity as the predominant risk today, only 29% of the former believe it will continue to hold that position within five years, compared to 41% of the latter. This difference highlights greater optimism in senior management, where furthermore 23% admit that their organization invests less than necessary in cybersecurity, evidencing a disconnect between the magnitude of the threat and the resources allocated to address it.
AI: From Risk Focus to Business Lever
The vision of artificial intelligence has also undergone a significant shift: two-thirds of respondents (66%) now consider its development an opportunity for business, compared to 57% in 2025, while the proportion of those who perceive it primarily as a risk has decreased from 30% to 24%, reflecting greater familiarity with its uses and growing confidence in its transformative capacity.
However, AI ranks as the second risk that most concerns CEOs in this year's report, mainly due to associated factors such as data privacy (61%), regulatory compliance challenges (51%), and cybersecurity (50%).
Another relevant front linked to AI is fraud, although the concern of senior executives in this area has fallen notably: currently, 93% of leaders do not place it among the main risks, despite the expansion of technologies such as deepfakes.
The BDO study also points out that only 13% of organizations actively update their defenses against AI-related fraud, compared to 79% who claimed to have a specific plan in 2025.
"Although companies increasingly recognize that risks are interconnected and more complex, they continue to manage them in an isolated and reactive manner. There must be a change, as companies have to start anticipating scenarios and managing risks transversally. Those companies that manage to make that leap will be turning uncertainty into a competitive advantage," assured the partner responsible for Risk Advisory Services at BDO Spain, Gonzalo García Liñán.