Aon plc has released its 2025 Cyber Risk Report, which shows that major cyber incidents led to an average 9 percent decline in shareholder value over the following year. The report is based on an analysis of more than 1,400 cyber events around the world, identifying which types of attacks are most likely to evolve into reputation risk events and which can be the most damaging when they do.
Key findings include:
- Of the 1,414 cyber events analysed, 56 developed into reputation risk events. These are defined as cyber incidents that attract significant media attention and lead to a measurable decline in share price.
- Malware and ransomware attacks were the most likely to trigger reputational damage, accounting for 60 percent of all reputation risk events, despite representing only 45 percent of total cyber incidents.
- Five drivers of value recovery – preparedness, leadership, swift action, communication, and change – were identified as critical levers for mitigating reputational fallout.
The report also highlights the growing challenge of managing uninsurable risks. While cyber insurance can help transfer some financial exposure, reputation risk remains largely non-transferable, making proactive risk management and crisis response essential.
Cyber risk is no longer just a technology issue – it’s a boardroom issue. Our latest research underscores the importance of proactive risk mitigation. Organizations that invest in preparedness and resilience are far better positioned to avoid the reputational and financial fallout that can follow a cyber event.
Brent Rieth, Global Cyber Leader, Aon






