Almost four-fifths (77%) of organisations expect their cyber budget to increase over the coming year, according to PwC’s 2025 Global Digital Trust Insights survey.
The survey, polling over 4,000 business and tech executives across 77 countries and territories, revealed that just 2% of companies have adopted cyber resilience throughout their organisation. That’s despite 66% of tech leaders identifying cyber-attacks as the top risk to mitigate in the coming year.
One reason for that gap is that CISOs lack sufficient authority and autonomy. PwC noted that less than half are significantly involved in strategic decisions around strategic planning, board reporting and overseeing tech deployments.
Although many CEOs and executives understand the importance of evaluating cyber risks, fewer than half are doing so effectively. Only 15% are measuring the financial impact of these risks, despite the average cost of a data breach rising to $3.3 million (£2.47 million).
For tech leaders, the top four cyber threats found most concerning this year are cloud-related threats (42%), hack-and-leak operations (38%), third-party breaches (35%) and attacks on connected products (33%).
Two-thirds (67%) of security leaders said that genAI has expanded their attack surface over the last year, ahead of other technologies such as cloud technology (66%), connected products (58%), operational technology (54%) and quantum computing (42%).
Despite the rising threats and a lack of preparedness, the survey found that organisations are beginning to take action.
More than three-quarters (77%) expect their cyber budget to increase over the coming year, with 30% of organisations expecting an increase of between 6-10%, while one-fifth (20%) expect budgets to increase by 11% or more.
Nearly half (48%) of business leaders plan to prioritise data protection and data trust as their top cyber investment over the next year. Tech leaders, on the other hand, note cloud security (34%) remains their top-priority.
While leveraging genAI remains key to cyber resilience strategies, organisations reported several challenges when incorporating the technology, notably with existing systems/processes (39%) and a lack of standardised internal policies governing its use (37%).
Recommended reading
- Compromised Backups Increase Ransomware Costs 8X
- NCSC Warns Ransomware Threat to Rise with AI
- ISACA Report: Cybersecurity Teams Understaffed & Underfunded
A successful cyber-strategy could mean a boost for business, as firms view investments in cybersecurity as a key differentiator for competitive advantage, with over half (57%) citing customer trust and 49% citing brand integrity and loyalty as primary drivers for such investment.
“Cyber resilience is everyone’s responsibility, from the boardroom to the employee,” said Sean Joyce, global cyber and privacy leader at PwC US.
“We must hold each other accountable and ensure we address emerging risks by leveraging new technology, practising foundational cybersecurity principles, and investing in resources that will secure the future of the organisation.”





