Cybersecurity 2027: How should businesses prepare for emerging trends?
Cybersecurity 2027 should be included in business planning as soon as a company decides to expand its use of AI, move systems to the cloud, or connect with more partners. Each of these changes requires clear answers about data, access rights, and how operations will continue during an incident.
PwC’s Global Digital Trust Insights 2027 report provides a reference point for planning. Combined with publications from WEF, ENISA, Verizon, and NIST, it can help businesses develop a set of priorities suited to their systems and resources.
This article brings together 8 priority areas for 2027 and suggests ways to prepare. These are forward-looking assessments for the coming year based on sources published by 5 October 2026; the percentages below are not statistics on incidents occurring in 2027.
What does PwC’s report reveal about how businesses are preparing for 2027?
PwC published the report on 1 October 2026, based on a survey of 3,934 executives across 71 countries conducted from May to July 2026.
PwC Finding | Respondent Group |
50% consider attacks on AI systems to be one of the major gaps in preparedness | Security executives |
84% expect to increase cybersecurity budgets | Security and finance executives |
39% have fully formalized and integrated business continuity plans that account for cyber risks | Security, risk, and operations executives |
22% are ready to allow AI agents to carry out fully autonomous defense | Respondents to the question on AI agent autonomy |
These percentages reflect an international survey and different question groups; they do not specifically represent Vietnamese businesses.
For those responsible for planning, these figures raise three questions: Are new systems already under control? Which risks will the budget address? And how thoroughly has the business tested its recovery capabilities?

8 cybersecurity priorities businesses should monitor in 2027
1. AI security and shadow AI need to be included in technology governance
WEF reports that 64% of organizations in its 2026 survey have a process for assessing the security of AI tools. ENISA also identifies AI’s dual role: supporting attackers’ activities and becoming a target for exploitation when integrated into businesses.
Preparation for 2027: inventory the AI tools in use, identify who is responsible for them, and distinguish approved applications from Shadow AI - tools used outside formal management oversight.
Each application should be reviewed in terms of its input data, access rights, and ability to take action. For example, a content drafting tool has a different scope of impact from an agent connected to a CRM with permission to modify customer records.
Businesses can start with AI governance in the enterprise, then develop a separate assessment process for each application category.
2. Data protection must cover sharing with AI tools and partners
When planning cybersecurity for 2027, businesses should track where data goes after it leaves its original application. A document may be sent by email, copied into an AI tool, and then shared with a supplier within a single workflow.
Preparation: select important data categories and identify where they are stored, who is authorized to use them, and which sharing channels are acceptable. For each category, define how it may be handled in AI tools and how access will be revoked when an employee or partner finishes their work.
Rather than issuing a broad policy that is difficult to apply, test it against specific scenarios: summarizing contracts, analyzing customer spreadsheets, or processing recruitment documents. These scenarios can also help develop training on the risks of data exposure when using AI.
3. Vulnerability, identity and cloud management should be viewed as part of the same attack surface
Verizon’s 2026 DBIR states that 31% of data breaches in the report’s dataset began with the exploitation of software vulnerabilities. The incident data for this edition covers 1 November 2024 to 31 October 2025.
Preparation: review Internet-accessible systems, administrator accounts, application permissions, and cloud configurations. For each finding, record its impact, the person responsible for remediation, and the deadline for rechecking it.
The asset inventory should be practical enough to answer: Which systems are still running? Who manages them? And which log sources help detect unusual access? Unused accounts, integration permissions granted during testing, and forgotten cloud services should be included in the same review.
More detailed content can start with common cloud security vulnerabilities and expand into a checklist tailored to the business’s systems.
4. Fraud and impersonation need to be addressed through business processes
WEF identifies cyber-enabled fraud as the leading concern among CEOs in its 2026 survey. ENISA continues to identify social engineering and phishing as methods of exploiting trust to support attacks.
Preparation: identify requests that could lead to financial loss or loss of access, then design an independent verification step. Scenarios to test include changes to payment recipient accounts, urgent fund transfer requests, and requests to reset administrator accounts.
For example, when receiving a request to change a supplier’s bank details, employees need a previously established confirmation channel. Contact information included in the new request should not be the sole basis for approval.
Businesses can connect process improvements with cybersecurity awareness training for employees, using scenarios that reflect each department’s work.
5. Digital supply chains need plans for incidents affecting partners
ENISA Threat Landscape 2026 emphasizes that digital dependencies expand the attack surface. WEF reports that 65% of large businesses by revenue in its survey consider third-party and supply chain vulnerabilities the biggest challenge to resilience.
Preparation: map the partners involved in critical business services. For each partner, identify the data shared, access rights, notification contact, and alternatives if the service is disrupted.
The assessment should also cover operational relationships: How quickly can the business revoke access? How can it retrieve its data? And who coordinates the response when an incident affects multiple parties?
Articles on software supply chain attacks can provide context for developing a supplier assessment checklist for 2027.
6. Preparedness for ransomware and service disruptions must be validated through recovery testing
Verizon’s 2026 DBIR reports that ransomware was involved in 48% of data breaches in the report’s dataset. ENISA also identifies ransomware as an incident type with a particularly significant short-term impact.
Preparation: choose a critical business process and run an exercise in which the system supporting that process is unavailable. The exercise should clarify notification procedures, decision-making authority, temporary working arrangements, and the conditions for recovery.
A recovery test should produce evidence of actual recovery times, the data that can be restored, and any missing dependencies. Business teams should participate to assess whether the restored system meets operational needs.
Businesses can use content on developing a disaster recovery plan as a starting point for exercises and measurements of recovery capabilities in 2027.
7. AI in the SOC needs defined authority, evaluation criteria and oversight
One approach for 2027 is to test AI on clearly scoped tasks before granting it permissions that affect production systems. For example, a business could evaluate its ability to summarize alerts using a set of events that experts have already reviewed.
Preparation: define which data may be used, who reviews the output, and which actions require approval. For tasks such as locking accounts or isolating devices, there should be ways to record decisions, intervene, and reverse actions when necessary.
Trial effectiveness should be assessed through the quality of handling and the operational impact. The number of alerts processed automatically is only part of the result; businesses also need to know whether important alerts were missed and whether actions caused disruptions.
This content group can link to the article on applying AI in the SOC. If working with a partner, agree on response authority and escalation procedures within the service scope.
8. Post-quantum cryptography should begin with an inventory and a migration roadmap
NIST/NCCoE guidance on migrating to post-quantum cryptography calls for identifying where public-key algorithms vulnerable to quantum computers are used, then developing a prioritized roadmap. The program also focuses on cryptographic inventories and interoperability testing. [6]
Preparation: businesses with data that requires long-term confidentiality or systems that are difficult to change should discuss upgrade capabilities with their suppliers. A starting point is a list of services that use certificates, digital signatures, and key exchange mechanisms.
Priorities depend on the data, the system’s expected lifetime, and technical dependencies. Businesses should not treat 2027 as a date when quantum computers will definitely be able to break current cryptographic systems.
The article on quantum cybersecurity risks provides background for developing more detailed preparation guidance.
Where should businesses start with cybersecurity planning for 2027?
The NIST Cybersecurity Framework 2.0 has six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is an outcomes framework for managing risk, rather than a fixed action checklist for every business.
Businesses can use this framework to compare their current position with their goals for 2027. The table below is an editorial suggestion for organizing work, rather than a mandatory NIST requirement.
Work Area | Questions to Answer During Planning |
Govern | Who is responsible for each risk and approves the investment? |
Identify | Which services are critical, what data do they use, and whom do they depend on? |
Protect | Are access rights, configurations, and data sharing practices appropriate? |
Detect | Is there enough monitoring data, and are people available to handle alerts? |
Respond | When an incident is detected, who has the authority to act and communicate? |
Recover | Has the recovery of critical services been tested under realistic conditions? |
For each gap, record the owner, the required outcome, and the evidence used to confirm completion. This helps leadership assess budgets based on business impact and track progress after approval.
A 90-day preparation roadmap
Businesses can adapt the reference roadmap below to their resources. Each phase should have a verifiable deliverable.
Phase | Focus | Deliverable |
Days 1–30 | Inventory critical services, AI, data, accounts, and suppliers | A list of priority risks and accountable owners |
Days 31–60 | Address priority gaps; test verification and monitoring processes | Tested measures and evaluation criteria |
Days 61–90 | Run incident response and recovery exercises; assess internal and partner capabilities | Test records and the next investment plan |
Metrics may include the proportion of critical services with assigned owners, overdue unresolved findings, and the number of recovery scenarios successfully tested. Businesses should agree on measurement methods before setting targets.
If external capabilities are needed, define the system scope, log sources, coordination timeframes, and response authority before choosing a model. SOC and MDR: a detailed guide can support this initial research.
Businesses developing a cybersecurity plan for 2027 can discuss 24/7 SOC services with IPSIP Vietnam, starting with their current monitoring capabilities and coordination procedures when an incident is detected.
Frequently asked questions about cybersecurity 2027
Which trends should businesses prioritize?
This article organizes the content into eight groups: AI security, data protection, vulnerabilities and identity, protection against impersonation, supply chains, recovery, AI in the SOC, and post-quantum cryptography. Implementation priorities should be adjusted according to their impact on the business.
How should small businesses get started?
Choose one critical business service and assess it from end to end: data, access rights, monitoring, partners, and recovery capabilities. This scope helps produce verifiable results before expanding the assessment.
Are the percentages in this article forecasts of incidents in 2027?
No. The article uses published surveys, incident data, and guidance to suggest preparation steps. When reading each source, distinguish the edition name, survey period, and data collection period.
---------------
References
PwC — Global Digital Trust Insights 2027. Moving targets: Cybersecurity in a dynamic digital world. Published on 1 October 2026. Source for the survey scope and the figures in the PwC table. Read the PwC source.
World Economic Forum, in collaboration with Accenture — Global Cybersecurity Outlook 2026. Published on 12 January 2026. Additional source on AI security assessments, fraud, and supply chain risks. Report and key findings.
ENISA — ENISA Threat Landscape 2026. Published on 22 September 2026; analyzes events observed in 2025. Source on digital dependencies, ransomware, social engineering, and AI’s dual role. Report page; press release analyzing the findings.
Verizon — 2026 Data Breach Investigations Report (DBIR). Source for the percentages related to vulnerability exploitation and ransomware; the incident data period is stated in the page’s FAQ. Report page and key findings.
NIST — Cybersecurity Framework 2.0, Frequently Asked Questions. Source for the six functions and the CSF’s nature as an outcomes framework. NIST FAQ.
NIST/NCCoE — Migration to Post-Quantum Cryptography. Guidance on cryptographic inventories, migration roadmaps, and interoperability testing. PQC migration program page.












