Gartner, the technological research and consulting company, surveyed around 275 senior risk executives and managers to document and compare emerging risks in the second quarter (Q2) of 2024.
According to the newly-published results, artificial intelligence (AI)-enhanced malicious attacks have once again topped the emerging risk rankings. Additionally, fresh concerns regarding soft ransomware targets are also coming to the forefront of enterprise risks.
“Similar to AI-enhanced malicious attacks, soft ransomware targets require minimal experience and cost to cause significant financial and reputational damage,” explained Gamika Takkar, director, research in the Gartner Risk & Audit Practice.
In fact, three of the top five most cited risks are in the technology category; AI-enhanced malicious attacks in first place, AI-assisted misinformation in fifth place, and the aforementioned risk of soft ransomware targets now coming in at second place.
Meanwhile, escalating political polarisation—which entered the track in Q4 of 2023—held steady as the third-most cited concern, while misaligned organisational talent moved up from the fifth to the fourth most cited risk.
Causes of Soft Ransomware Targets
Soft ransomware targets include the types of systems that may be especially vulnerable to ransomware due to underinvestment or technical debt, leading to longer disruptions in business operations when attacks occur.
The ease of carrying out such attacks, via what’s known as ransomware-as-a-service (RaaS), allows cybercriminals with even minimal experience and technical skill to deploy attacks at low cost.
As Takkar further explained: “Ransomware-as-a-service lowers the barrier to entry for inexperienced cybercriminals who know just enough about how to attack and disrupt business operations, creating worse impacts than usual when attacks occur.”
Mitigating Potential Consequences
The potential impacts of soft ransomware targets range from operational disruptions and delay of services, to increased exposure to multi-extortion, to increased financial burden in the form of direct and indirect costs.
Direct costs include ransoms, remediation, litigation, and public relations, while indirect costs, such as reputational damage and loss of intellectual property, also create burden on the organisation.
“While operational disruption and increased costs are dire consequences of soft ransomware targets, the exposure to extortion can impact not just the organization itself, but any and all associated third-parties as well, further underscoring the importance of understanding and preventing such risk,” noted Takkar.
Recommended reading
- Are Organisations Ready for 90-Day TLS Certificates?
- 45% of UK Energy Firms Disrupted by Cyber-attacks
- OpenAI, Google, Microsoft and More Launch Coalition for Secure AI
These latest survey results follow a string of other findings from Gartner where AI has featured prominently.
For instance, earlier this month, it was discovered just under two-thirds (62%) of CFOs and over half (58%) of CEOs believe that, out of all technologies, AI will have the most significant impact on their industries in the next three years.
Further, at the beginning of this month, another survey from the research firm found that 64% of customers would prefer companies not use artificial intelligence in their customer service.





