2025 Cyber Losses: The Data-Driven Lessons | Resilience Risk Briefing

Resilience’s claims leaders unpack the year’s most instructive cases and what they teach about changing tactics and loss dynamics.

3 Min Read

The 2025 cyber claims data, and what it means for 2026

Bad actors don’t need a technical vulnerability to get into a network — they need someone to trust a voice, a message, or a login that looks real. A person manually talking a help desk into a password reset and an AI-generated voice authorizing a wire transfer are different mechanisms aimed at the same target.

Autonomous ransomware kits and AI-generated impersonation just made that approach faster and cheaper to run at scale. Identity, not infrastructure, is now the center of enterprise defense.

Jud Dressler, Director of Resilience’s Risk Operations Center, will moderate a conversation with Stephanie Barnes, Senior Threat Intelligence Analyst at Resilience, and Max Henderson, Managing Director and Global Head of DFIR at Kroll. They’ll cover what’s actually showing up in the threat data right now and how to defend against it.

About Speakers

Any company that sells hardware or software with network connectivity into an EU member state has to report vulnerabilities and incidents affecting that product. The regulation calls these products with digital elements, and it applies to the manufacturer regardless of where the manufacturer is based, so a US firm with no EU presence is covered from the moment its first unit ships into the single market.