A revolution in modern warfare is posing questions for investment portfolios.
Cheap attacks, costly lessons: how AI is reshaping cyber risk
As AI makes cyber attacks cheaper, cyber resilience now looks vital to protecting companies and long-term investor value.
Article last updated 7 August 2026.
|
Quick take
|
It no longer takes a cyber Bond villain to cause corporate chaos. With cheap tools, a convincing email, and one exposed gap in the chain, attackers can now turn modest effort into expensive disruption.
Cyber risk is no longer just operational. It can stop sales, increase costs, squeeze margins, and damage trust in the companies we invest in. They can also draw the attention of regulators and unsettle investors if the financial hit looks material.
That is why companies need to protect not only data, intellectual property, financial assets, and reputation, but also the weaker links that can put them at risk. “You are the weakest link” was once Saturday-night theatre. For companies, it is now a useful way to approach cyber security. The better question for investors is whether management knows where the weakest links are, and whether the board is curious enough to question them before attackers do.
The bill for bargain breaches
The hackers behind the cyber attacks on Marks & Spencer and Jaguar Land Rover in 2025 claimed to have stolen one billion customer records from these and other major companies. The attack on Jaguar Land Rover halted production and caused widespread delays across the company’s supply chain. The Bank of England cited the incident as a key reason for lower-than-expected headline UK GDP growth in Q3 2025 and estimated its cost to the UK economy at close to £2bn. The US had its own costly example: a 2024 ransomware attack on UnitedHealth disrupted healthcare payments and cost around $3bn.
These incidents also show how cyber risk can cascade through the corporate supply chains and partner networks. A breach at a supplier, software provider or outsourced service partner can quickly become a listed company’s operational, reputational and financial problem.
The threat of cyber attack is not new – the UK Government’s ‘Cyber Essentials’ advice for companies is now 12 years old. Cisco’s 2025 Cybersecurity Readiness Index found that 73% of UK organisations experienced a cyber incident in the past year. The global average cost of a data breach, including response and recovery, was estimated at about $4.4m according to IBM’s Cost of a Data Breach report.
The continued rise of AI technology in recent years is rapidly reshaping the cyber security landscape. These AI-related risks can be used to:
• Create convincing phishing emails that mimic colleagues, suppliers or IT teams.
• Target third-party partners with access to company data and systems.
• Use social engineering, such as phone calls or messages, to trick employees into approving payments or sharing access details.
• Scan public records, social media, cloud infrastructure, and company systems to find weak points faster, while AI coding tools and advanced large language models (LLMs) – such as Anthropic’s Claude Mythos, built for cyber-security research – can help create low-cost, sophisticated attacks.
• Generate ‘deepfake’ voice or video impersonations to mimic senior executives or trusted contacts.
We believe small and medium enterprises are particularly vulnerable, due to often-constrained budgets and limited resources. AI is changing the economics of cyber crime, making attacks cheaper, faster, and more convincing. This gives criminals more opportunities to launch cyber attacks at scale, including targeting smaller companies that may have been deemed uneconomic to pursue in the past.
That matters for investors because the gap between cyber leaders and laggards may widen. Companies with resilient cyber defences may be better placed to protect long-term value.
The breach club regulars
How often UK organisations have experienced cyber breaches or attacks in the past 12 months.
Managing risk: Defence needs directors
The increasing frequency, sophistication, and impact of cyber incidents underscore the importance of continually improving security measures. Companies can leave themselves vulnerable by underinvesting in cyber security. The UK Government’s Cyber Security Breaches Survey 2025 suggests that board-level responsibility for cyber security has declined since 2021. The report stated that 38% of businesses had a board member with responsibility for cyber security in 2021, compared with 27% in 2025.
Nevertheless, our recent engagement with companies listed on Aim, the London Stock Exchange’s market for smaller growth companies, in which we invest, has shown that good practices are being widely adopted. Most invest in cyber insurance, employee training, and board-level oversight of cyber incidents.
However, many of these companies don’t use outside expertise to provide assurance over their practices or to conduct regular penetration testing (simulated attacks to test their defences). Although most firms monitor cyber risk and submit incident reports to boards, there is little evidence that board members receive training to provide rigorous oversight of cyber risk management practices. Only a small number of the companies we have engaged with have assigned cyber oversight to a specific board member. This is a concern for us, as we seek to protect the value of companies in our clients’ portfolios, and we intend to keep this under review, engaging with companies where appropriate.
Directors need to know whether the company’s defences work, whether external partners are being watched closely, and whether crisis plans would survive a real attack. This is not about signing off polished reports. It is about asking practical questions beforehand: have we tested the policies, do people know what to do, do critical partners know their role, and when the alarm sounds, who is in charge?
The attack on Marks & Spencer showed how cyber risk can enter through people and partners outside a company’s own walls, after attackers reportedly persuaded third-party contractors to approve password resets. Weaknesses in suppliers or other third parties can quickly become a company’s own problem. Strong governance, therefore, requires boards to look beyond internal controls and ask how critical partners assess, monitor, and respond to cyber threats.
Breach response: ready on paper
Percentage of organisations that say they take, or would take, the following actions following a cyber security breach or attack
Fighting code with code
While AI has lowered the costs and improved the efficiency of attacks, it can also strengthen defences. For example, AI can act as a force multiplier for cybersecurity teams, helping companies spot unusual behaviour, monitor third-party risks, detect code flaws, prioritise fixes, recover affected systems, and contain threats before they spread. Companies that lead the pack will need to defend themselves against AI-enabled attacks while also harnessing AI as an opportunity.
Rising cyber threats should also support demand for businesses that help others defend themselves. The opportunity is not simply in the technology itself, but in how well companies use it.
The risks of failing to adapt as cyber criminals change their tactics are growing rapidly. We believe companies that adopt the highest standards of cyber security protection can represent a more attractive and robust investment. Companies that take cyber resilience seriously, through regular testing, AI-enabled defences and informed board oversight, may be better placed to protect long-term value. Those who continue to treat cyber security as an IT housekeeping matter may find the cost of complacency rising.