error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

Loading

The page is loading.

Please wait...


      Cyber threats are advancing in scale, complexity, and global influence. In 2025, KPMG’s global network of incident responders observed a rise in cross‑border threat activity, rapid exploitation of high‑impact vulnerabilities, and increasing operational sophistication across both financially motivated and state‑affiliated adversaries.

      2025 was defined less by a single dominant ransomware cartel and more by high‑volume, fast‑moving Ransomware‑as‑a‑Service (RaaS) ecosystems. Groups such as Qilin and Akira featured repeatedly across live cases, commonly leveraging compromised credentials, unpatched edge infrastructure, or poorly governed remote access to move quickly from access to impact.

      What stood out operationally was the churn: new names appear, rebrand, or disappear rapidly — but tradecraft remains consistent: identity abuse, speed over stealth, double‑extortion, and pressure on business operations.

      Oisín Fouere

      Global Head of Cyber Response

      KPMG International

      Key highlights

      Why this matters now

      Across regions, incidents increasingly blur the line between ransomware, data extortion, and supply-chain fallout — with adversaries prioritising business impact and speed of execution.

      At the same time, cyber insurance is shaping incident response maturity. Organisations are more frequently operating with pre‑negotiated response retainers, breach counsel, and crisis communications pathways, while insurers expect disciplined execution in the first 24–72 hours

      In practical terms, the difference between a contained event and a business‑wide crisis often comes down to preparedness, clear decision rights, tested playbooks, and defensible forensic evidence

      What we’re seeing globally

      In 2025, KPMG incident responders consistently observed high‑tempo activity driven by established RaaS ecosystems and affiliate models, with recurring initial access paths including compromised credentials, VPN/RDP exposure, third‑party compromise, and edge infrastructure vulnerabilities.

      A key message for CISOs: the patterns are globally consistent — the same actor groups, entry vectors, and exploitation playbooks appear repeatedly, regardless of geography. Cyber risk is globally distributed, and so must be response.

      What we are seeing in Europe

      Europe continues to account for a large share of incidents, shaped by its industrial landscape, digital interconnectedness, evolving regulatory environment, and geopolitical context. In 2025, KPMG responders frequently encountered high‑tempo ransomware activity involving groups linked to Qilin, Akira, and “Scattered Spider‑style” affiliates — typically moving quickly through identity compromise and exposed edge infrastructure. 


      Key takeaway

      In Europe, incident complexity and cost are magnified by intense regulatory pressure — where the driver of an engagement is often the risk of non‑compliance and the need for defensible response and reporting across jurisdictions.


      2025 Global IR Trend Report

      2025 Global IR Trend Report

      This report offers a global perspective on the cyber incidents investigated by KPMG member firms worldwide, highlighting major trends, threat actor behaviors, and industry-specific insights observed throughout 2025.

      Key learning: enhancing detection and response maturity

      Across incidents, systemic weaknesses in identity controls, credential management, patching, and user awareness remain central drivers of compromise — compounded by limited detection and response capabilities that allow attackers to reach material impact before containment begins.

      Five focus areas we see organisations prioritising:


      • Strengthening identity controls

        (identity as the new perimeter; ITDR, PAM, JIT access, governance)

      • Reinforcing MFA and password practices

        (coverage, configuration, enforcement, password management)

      • Cyber resilience and backups

        (immutable and air-gapped, distributed across on‑prem and cloud)

      • Proactive defence

        (MDR, threat hunting, purple teaming/red teaming, CTI-driven prioritisation)

      • IR readiness

        (retainership, tabletop exercises, ransomware simulations, pre-negotiated experts)



      Looking forward to 2026

      2026 is likely to be a year of flux. While ransomware and hacktivism persist, new technology — particularly AI — may amplify the effectiveness of highly convincing social engineering, and increase risk to identity and cloud-based access paths.

      Five developments shaping 2026:

      • AI‑powered attack automation
      • Hyper‑targeting of digital identities (including deepfake-enabled social engineering)
      • Weaponisation of OT and critical infrastructure
      • Systemic supply chain compromise
      • Defensive AI becomes a target (evasion, poisoning, manipulation) 

      Contact us

      Oisín Fouere

      Global Head of Cyber Response

      KPMG International

      Dave Harvey

      Director, Cyber Response Services

      KPMG in the UK

      Jayesh Kerai

      Director – Cyber Response Services

      KPMG in the UK

      Mark Tomlin

      Director - Cyber Incident Response Lead for UK Government & Defence

      KPMG in the UK


      Our advisory insights

      Something went wrong

      Oops!! Something went wrong, please try again

      MTD

      Get in touch


      Discover why organisations across the UK trust KPMG to make the difference and how we can help you to do the same.