The cyber resilience test
Forget the Hollywood hackers. Today's cybercriminals are automated, AI-powered and operating at industrial scale. Vanessa Macdonald explores why no organisation is too small to become a target—and why cyber resilience is now a business necessity.
Here is a sobering thought: cybersecurity company Fortinet said in its 2026 Fortinet Global Threat Landscape Report that cybercrime was predicted to cost an average of over €20 trillion per year by 2027.
Put that into context: that is higher than the GDP of the whole of China for 2026.
And as cybercrime grows, so too does the cost of fighting it: Fortinet said that global security spending was expected to be 12.2% higher in 2025 than the previous year, reaching a staggering €330 billion by 2028.
The report also warns about the growing impact of a data breach: the average cost of a data breach was over €4.27 million, enough to cause any enterprise to catch its breath.
The Fortinet report makes sobering reading, but it also captures what has been happening out there, from more malware attacks and phishing scams to AI-driven threats. The latter played a part in the 47% of organisations that reported deepfakes and identity fraud.
And business leader Gartner's conclusions are just as worrying: it predicted that almost half – 45% – of organisations would not be targeted directly but through their supply chains.
Finian Massa, strategic marketing manager at ICT Solutions and the cybersecurity service providers representative of the National Cybersecurity Consultation Council, explained that the situation in Malta is increasingly worrying: "Malta is a small market that thinks small-market rules still apply to it, and they don't. Fortinet's 2026 Global Threat Landscape Report clocked 122 billion exploitation attempts globally in 2025, with the time from a vulnerability being disclosed to it being actively exploited now sitting at 24 to 48 hours - down from just under five days a year earlier. Attackers don't choose targets by geography anymore; they choose by opportunity.
"We see that on our own Security Operations Centre (SOC) floor – the volume of alerts against Maltese customers has roughly doubled in a year, and the share of alerts that turn out to be genuinely malicious has moved from around 0.5%, historically, to 3-5% every month. The Maltese market is not being ignored. It's being industrialised against, like everywhere else."
The size of the Maltese market plays a significant role when taken in the context of EU attempts to counter these crimes: "Regulations like the Network and Information Security Directive (NIS2) and the Digital Operational Resilience Act (DORA) are written for a European economy of large, layered institutions. Malta's economy is a mid-market economy – most of the entities in scope here are a fraction of the size of the ones the drafters had in mind. The instinct is to complain about proportionality, and there's a fair argument to be had there. But the more honest observation is this: the threat doesn't care about your headcount," he said.
"Fortinet identified 7,831 confirmed ransomware victims globally in 2025, a 389% jump year-on-year, fuelled by off-the-shelf AI crimeware like WormGPT and FraudGPT that has lowered the cost of running an attack to almost nothing."
What does this mean in practice? A 20-person Maltese firm is now inside the economics of an attack that, three years ago, would only have been aimed at a bank, he explained.
"The uncomfortable truth for Malta's mid-market is that the attack economics have flipped. Fortinet's telemetry shows ransomware victims up 389% year-on-year. Being small is no longer camouflage – it's just a smaller target that costs the same to hit."
He also stressed that AI needed to be approached with the right mindset: "Two AI stories are running in parallel in Malta and business leaders keep collapsing them into one. The first is the productivity story – Copilot, agents, automation – and it's real, and most Maltese businesses are still under-adopting it. The second is the threat story: attackers are already using agentic AI to compress the kill chain and to industrialise phishing, deepfakes and credential theft at a scale small teams cannot match manually.
"The businesses that will do well over the next two years are the ones that treat those as one governance conversation, not two. You cannot roll out AI internally without also assuming your attackers have rolled it out first. The good news is that the same shift creates the case for AI-enabled defence: the honest answer is that human-speed response is no longer a viable strategy against machine-speed attack."
Leslie Causon, general manager at GasanMamo insurance, recently wrote in the Times of Malta about the islands being in the top three EU countries for businesses affected by cybersecurity incidents, saying the highly connected economy made it particularly vulnerable.
"We're a digital hub for financial services and international business, which makes us an attractive target. Attackers know Maltese companies handle significant financial transactions and sensitive data," he said.
What does the future hold? Alas, technological progress works for both criminals and victims. Prof. André Xuereb, from the University of Malta & Merqury Cybersecurity, explained that quantum computing would have a dramatic impact.
"Quantum computers are amazing machines, somewhere in the borderlands between fact and science fiction. Much like ordinary computers use bits (which can be 0 or 1), a quantum computer uses qubits, which through a quirk in the laws of the universe can somehow exist as both a 0 and a 1 at the same time. This makes it possible to use quantum computers to tackle problems which could otherwise be impossible to solve.
"One such problem is factoring, or breaking down, large numbers. Although it is straightforward to show that 323 is equal to 19 multiplied by 17, what about 69,672,964,777,107,193? The difficulty of factoring large numbers is what keeps the internet secure. The advent of quantum computers will break this security," he explained.
The effects of this cannot be overstated, he warned.
"An example I often cite is the DORA regulation, which applies to financial entities: if you are not protected against the quantum threat, you cannot be compliant with DORA. How should our organisations and critical infrastructure operators face this challenge? First, they should upgrade their communication systems to use post-quantum cryptography everywhere. Second, all essential and critical communication channels should be protected by quantum key distribution, which provides the only provable means of protection."
The reality is that most companies are driven to protect themselves against cybercrimes for compliance reasons, as well as to meet the conditions laid down by cyberinsurance providers.
How much should companies be spending? Internationally, between 5-15% of the IT budget is dedicated to cybersecurity, although this range does not cover highly regulated sectors. What is the solution for an SME that does not have in-house expertise? Many companies are now relying on outsourced security providers.
The most important thing is for companies to be aware of the increasing risks and to tackle them head-on, just as they did when the risks were shoplifting and physical hold-ups.
As Causon said in his article: "In some cases, the technology issue is resolved quickly, but the financial and reputational fallout lasts much longer."


Rockets can take us to Mars. Keeping humans alive when we get there is the harder problem. Prof Joseph Borg charts Malta’s remarkable journey from orbital biology to the frontier of autonomous medicine in deep space.