Safety

Generative AI Raises Cyber Risks While Most Companies Remain Unprepared

The PwC 2024 Global Digital Trust Insights survey finds that the spread of generative artificial intelligence significantly increases the risk of severe cyberattacks, while many companies are not adequately prepared.

PwC’s 2024 Global Digital Trust Insights survey shows an increase in companies that experienced data-privacy incidents costing more than $1 million in the past year — rising from 27% to 36%. Despite this rise, more than one-third of organizations made no risk-management efforts, and only one in four improved their cyber resilience over the past 12 months.

The survey is based on responses from 3,876 business and technology leaders across 71 countries, collected between May and July 2023.

Financial impact and sector differences

Across the sample, damaging cyber incidents caused an average loss of $4.4 million per affected organization. In the healthcare sector the average loss was higher at $5.3 million, about 25% above the overall average. The share of respondents reporting incidents with losses of $1 million or more by sector was:

  • Healthcare: 47%
  • Technology, Media and Telecommunications: 43%
  • Financial services: 38%
  • Energy: 37%
  • Industrial and automotive: 33%
  • Retail: 28%

Generative AI: risks and opportunities

The spread of generative artificial intelligence (AI) is increasing cyber‑security concerns because it can produce highly convincing fraudulent content — text, images, video or code — that can make targeted scams more effective. Fifty‑two percent of respondents said they believe generative AI could lead to catastrophic cyber attacks within the next 12 months.

At the same time, many leaders see business upside: 77% want to use generative AI ethically and responsibly, 77% agree it will help create new business lines within three years, and 75% expect it to boost employee productivity over the next 12 months.

Poor awareness and weak preparedness

Although cloud-related risks, attacks on connected devices, and hacking/leaks were identified as the top cyber threats, more than one-third of organizations did not take risk-management actions in the past year. Only 2% of organizations continuously optimize and build resilience against cyber attacks across all areas. Moreover, over 40% of respondents said they do not understand the cyber risks posed by emerging technologies such as virtual environment tools, generative AI, enterprise blockchain, quantum computing and extended reality.

Benefits of sound cyber practices

Fewer than one-third of companies consistently apply core cyber-security practices, even though they are key to preventing incidents. Only 5% of surveyed firms have cyber teams that consistently follow information‑security practices; PwC refers to these organizations as “keepers of digital trust.”

Those organizations experienced fewer high‑value incidents during the study period: while 36% of all respondents reported cyber incidents with losses exceeding $1 million, that share was 29% among the digital‑trust keepers.

Compared with other respondents, these organizations are also more positive about generative AI’s potential impact:

  • More likely to say it will create new business lines (49% vs. 33% of all respondents);
  • More likely to plan to use generative‑AI tools for cyber defence (44% vs. 27%);
  • Less likely to believe generative AI will cause catastrophic cyber attacks (33% vs. 22%);
  • Unlikely to deploy generative‑AI tools before introducing appropriate internal policies.

Why this matters

The survey clearly indicates that both the frequency and the financial impact of significant cyber attacks are increasing, while a large share of organizations remain unprepared for the risks associated with emerging technologies. Generative AI’s dual role as a business enabler and a potential attack vector poses a particular challenge for leaders and cyber-security teams.

PwC’s findings imply that companies need to expand cyber‑risk management capabilities and adopt consistent information‑security practices if they want to reduce future financial and operational losses.

Methodological note

The 2024 Digital Trust Insights survey was conducted between May and July 2023 and is based on 3,876 responses from business and technology leaders across 71 geographies. Participating organizations varied in size and industry; 40% of respondents represent companies with annual revenues over $5 billion. Eighty‑eight percent of responses were collected via an external provider platform and 12% through the PwC network.