A growing sense of unease is gripping boardrooms as 88% of cybersecurity and information security leaders surveyed at UK and US organizations now express concern about state-sponsored cyber attacks. The latest State of Information Security Report from IO states that geopolitical cyber threats have become a pressing business risk and should now be a board-level concern.
The figure comes amid a sharp escalation in hostile activity targeting critical national infrastructure (CNI) and the private sector. 33% of organizations surveyed were concerned about an expanded threat landscape targeting their own systems.
Despite the increase in nation-state threats, a third of UK and US organizations surveyed also believe that governments aren’t doing enough to support and protect businesses, a sentiment that underscores the growing expectation for stronger public–private collaboration in defending both national and commercial interests, says IO.
When it comes to threats facing CNI, there is a significant national effort going into protecting vital assets. However, at the same time, it also carries a stark warning. If an organization is connected to the right systems, servicing critical infrastructure, or simply handling sensitive data, it could be targeted by nation-state adversaries.
Chris Newton-Smith, CEO, IO
The most pressing issue linked to nation-state threats is the threat of widespread data loss or inaccessibility, such as through DNS attacks or major cloud outages, cited by 41% of survey respondents. Close behind are anxieties over reputational damage if systems are compromised indirectly (40%) and the potential for supply chain-driven operational disruption (38%). Organizations are also worried about the possibility of interruptions to critical national infrastructure, including power, transport, and communications (36%), as well as the security and availability of data hosted in regions considered to be key adversaries (35%).
These concerns are mounting amid rising regulatory scrutiny and a growing expectation from customers and partners to demonstrate resilience, each cited by around one-third of organizations. IO’s research indicates that 74% of cybersecurity leaders are actively investing in resilience measures to counter nation-state-linked threats. Among organizations concerned about state-sponsored attacks, 97% are tailoring their incident response and recovery plans, 97% are increasing their investment in threat intelligence, and another 97% are bolstering the security and resilience of their supply chains.
State-level cyber activity is now a real concern for businesses and resilience, not retaliation, will be the accurate measure of national and corporate defence in 2026. Organizations that understand their exposure, test their defences, and secure their supply chains will be best placed to withstand the next wave of attacks.
Sam Peters, Chief Product Officer, IO






