CISOs lost on average $1.7 million from cyber scams in 2024, a new report from BrandShield found.
The report, which surveyed 200 cyber leaders from the UK, US, and Europe, found that 98% of organisations experienced some form of cyber-attack in 2024, with 94% of CISOs lost at least half a million dollars due to cyber scams.
With these staggering numbers, 76% of CISOs anticipate an increase in their 2025 threat monitoring budgets. Those that suffered more losses plan to spend more to prevent them.
This reflects the urgent need to address escalating cyber threats. The trend indicates a heightened focus on preventive measures, with 39% expecting a budget increase of up to 10% and 29% anticipating a more significant boost of 11 to 25%.
With this intention to spend more on cybersecurity, CISOs are also reconsidering their vendors. Over three in four (77%) of CISOs are considering switching their cybersecurity providers, primarily in pursuit of holistic, comprehensive risk coverage.
CISOs are prioritising integrated, end-to-end solutions that provide robust and scalable security across multiple threat vectors, with 22% identifying holistic coverage as a primary motivator for switching cybersecurity provider.
Cost-effectiveness actually ranked quite low among reasons for switching, and only 13%, indicating that CISOs are more focused on effectiveness than on simply reducing costs.
The survey also found that specifically, brand reputation is a prominent concern when it comes to cyber incidents like brand impersonation (31%), executive impersonation (28%), and phishing and scams (27%).
Recommended reading
- Cybersecurity in 2024 | The High Cost of Innovation
- AI in Cybersecurity | Navigating the Promises and Risks
- 87% of Firms Hit By AI Cyber-attacks
The threats not only target organisations directly, but also exploit their reputation, highlighting the growing overlap between cybersecurity and brand protection.
When it comes to external threats, CISOs pointed to rogue mobile apps (27%), social media impersonations (27%), and compromised credentials (27%) as their top concerns. These threats underline the evolving nature of cyber threats, where scams and exploitation are increasingly causing serious risk to organisations.
When looking at the biggest cybersecurity challenge in 2025, CISOs are navigating an era of rapid transformation. Cyber leaders cited economic pressures, including in supply chains (19%), AI (18%), 5G and increased connectivity (17%), and regulatory changes (17%) as the top concerns for the current year. State-level threat actors (15%) and quantum computing (14%) were also noteworthy challenges.
The pattern shows that global instability and tensions, as well as emerging technologies and their necessary governance, will continue to challenge organisations in the cyber landscape.





