Two-thirds of industry professionals identify cyber-attacks as the single biggest threat, far outweighing economic pressures and regulatory change
Cyber-attacks have overwhelmingly emerged as the number one concern for professional firms in 2026, according to new research from insurance experts Everywhen, highlighting a growing sense of vulnerability as businesses navigate an increasingly complex risk environment.
In a recent Everywhen industry survey, 65% of respondents identified cyber-attacks as the single biggest risk facing professional firms this year, more than three times higher than the next closest concern. Economic pressures ranked second at 18%, followed by professional negligence claims (9%) and regulatory changes (8%).
These findings reflect a significant shift in the risk landscape, with digital threats now dominating boardroom agendas across sectors including legal, financial, and consultancy services. As firms become more reliant on technology and data, their exposure to cyber risks, from ransomware attacks to data breaches, continues to intensify.
At the same time, traditional risks such as professional negligence and regulatory compliance appear to be taking a back seat, suggesting a reprioritisation, driven by both the frequency and severity of cyber-related incidents.
Further pressure on an already challenging environment
The survey’s results come at a time when professional firms are also grappling with economic uncertainty, rising operational costs, and evolving client expectations, all of which add further pressure to an already challenging environment.
A spokesperson at Everywhen, commented: “What this data shows very clearly is that cyber threats represent a fundamental and growing business risk. Professional firms are custodians of highly sensitive client data, and that makes them a prime target.
“From an insurance perspective, cyber incidents rarely sit in isolation. They can lead to business interruption, regulatory investigations, and even professional indemnity claims if clients are affected. That’s why it’s critical for firms to understand how their cover responds and where potential gaps may exist.
“There is still a tendency to view cyber insurance as optional, but the reality is that it is becoming a core component of a firm’s risk management strategy.”


