Is cybersecurity becoming too expensive to sustain?

From the Editor’s Desk

Cybersecurity teams are being asked to defend more systems with tighter budgets, while attackers are gaining speed through automation and AI. Recent reports also show how critical infrastructure remains exposed to attacks that can affect physical operations, not just data. Is the answer more security tools, or better use of the tools already in place?

🔎 Deep Brief

Is cybersecurity becoming too expensive to sustain?

Cybersecurity spending is rising as organizations face higher breach costs, growing attack volumes, and pressure to adopt AI. Dark Reading reports that the average global cost of a data breach reached $4.99 million in 2025, up 12% from the previous year. At the same time, global cybersecurity spending is expected to reach $239.8 billion in 2026.

The pressure is especially high for small and midsized businesses. Many lack large security teams but remain attractive targets and form part of larger supply chains. Security teams also face tool sprawl, with enterprises often running dozens of security products that can produce duplicate findings.

AI is adding another cost. Security teams may pay for premium AI services and large volumes of processing without reducing risk. The better approach is to prioritize exposures based on business risk rather than simply trying to fix every finding.

Takeaway

Security leaders need to measure the risk reduced by each security investment, not simply the number of alerts, tools, or vulnerabilities handled.

Find the AI models and research worth paying attention to

AIModels.fyi tracks the fast-moving world of AI models and research so you don’t have to. Discover trending models, browse new research papers, and get concise summaries of what matters for developers and teams building AI products.

🧠 Strategy in Action

Turning ICS security training into hands-on attack practice

SecurityWeek and MTSI are bringing back the Cyber Attack Methods course at the 2026 ICS Cybersecurity Conference. The three-day course puts participants inside an intentionally vulnerable virtual cyber-physical environment where they work through system discovery, vulnerability exploitation, and mission-focused attacks.

The approach moves beyond classroom-based threat theory. Engineers, developers, testers, and security professionals can work through the same stages an attacker would use against a cyber-physical system. This matters because attacks against industrial environments can affect safety, production, revenue, and essential services.

Takeaways: 

Hands-on testing can help security teams better understand how weaknesses in connected physical systems can be chained into real operational attacks.

🕵️ Threat Actor Spotlight

The Gentlemen ransomware group accelerates its attacks

During the first seven months of 2026, The Gentlemen carried out an average of 2.8 ransomware attacks per day. Since emerging in mid-2025, the group has claimed responsibility for 675 attacks, including 600 in the first seven months of 2026. That makes it the second-most active ransomware strain this year, behind Qilin, which recorded 771 victims during the same period.

The Gentlemen operates a Ransomware-as-a-Service (RaaS) model and is believed to have formed after Qilin affiliate ArmCorp split from the group following a payment dispute. The Gentlemen reportedly offered affiliates up to 90% of ransom payments, above the typical 70–80% share.

🛠️ Tool Check

Zabbix alternatives for infrastructure monitoring

Zabbix remains a strong open-source monitoring option, but its learning curve, resource demands, and database management can make it a poor fit for some organizations. Comparitech's guide evaluates alternatives based on automated discovery, inventory, network mapping, status monitoring, alerts, value, and access to free trials or free versions.

🗣️ Community Signal

As quantum computing evolves, organizations must ask a strategic question: Will today’s digital proofs still be secure, verifiable, and defensible in the future? Contracts, certificates, intellectual property records, compliance archives, identity proofs, and legal evidence may need to remain trusted for years — or even decades. This is why Post-Quantum Cybersecurity is no longer a distant technical topic. It is becoming a strategic priority for digital trust infrastructure. - Alessandro Civati

📚 Don’t Miss This

Advertise with Comparitech
Does your business offer services or products in cybersecurity? Get your product seen by IT leaders and professionals.

Advertise with us →

Until Friday’s edition - Let’s keep that zero-day count at zero!