Cybersecurity in 2026: AI Threats, NIS2 and the Growing Cost of Cyberattacks

Share This Post

An average ransomware incident can disrupt a business for 25 days and generate losses of millions of dollars. As artificial intelligence transforms both cyber defence and cybercrime, cybersecurity is rapidly moving from the IT department to the boardroom.

These were among the key messages from the Cyber-Security and Digital Sovereignty Conference, held on 16 September 2026 at Planet Schwarz in Sofia and attended by the Hellenic Business Council in Bulgaria (HBCB).

Organised by the German-Bulgarian Chamber of Industry and Commerce (AHK Bulgaria), the conference brought together representatives of business, public institutions, academia, the legal community and the technology sector to examine some of the most pressing challenges facing today’s digital economy – from technological sovereignty and the European regulatory framework to artificial intelligence, emerging cyber threats, corporate responsibility and cyber insurance.

Against a backdrop of rapid technological development, growing geopolitical uncertainty and increasing dependence on digital infrastructure, one message resonated throughout the discussions: cyber risk is no longer solely an IT issue. It has become a strategic business, governance and financial risk.

Digital Sovereignty: From Technology to Strategic Resilience

The first panel examined the relationship between the state, industry, cloud infrastructure and digital sovereignty.

Among the speakers was Assoc. Prof. Dr. Velizar Shalamanov from the Institute of Information and Communication Technologies at the Bulgarian Academy of Sciences, who addressed sovereignty in the digital age in the context of Bulgaria’s participation in NATO and the European Union.

The panel also included Mihail Petrov, CEO of Schwarz Digits, and Georgi Sulev, Senior Associate at Djingov, Gouginski, Kyutchukov & Velichkov, whose presentation focused on the evolving EU regulatory framework and its impact on business.

A recurring theme was that technological sovereignty should not be understood simply as technological independence. Modern organisations operate through complex ecosystems of cloud providers, software platforms, data infrastructure and international supply chains. The more interconnected these systems become, the more important it is for organisations to understand where their critical dependencies lie and how those dependencies affect operational resilience.

The discussion also placed cybersecurity within the much broader European regulatory landscape, including NIS2, DORA, the Cyber Resilience Act, the Data Act, the Digital Markets Act, the AI Act and eIDAS 2.0.

One of the presentations underlined a particularly important reality for European businesses: dependence on external technology cannot simply be eliminated. Instead, organisations need to understand, map and actively manage that dependence.

Artificial Intelligence Creates a New Generation of Cyber Risks

The second panel moved from infrastructure and regulation to one of the fastest-changing areas of cybersecurity: artificial intelligence and autonomous systems.

Kalin Primov, Managing Partner at IDVKM, focused on the rapid growth of non-human identities within corporate environments. Lyubomir Tulev of the Bulgarian Cybersecurity Association examined how AI agents can transform seemingly harmless content into executable instructions, while Dr. Lyuben Todev, Partner at Dobrev & Lyutskanov Law Firm, addressed the human dimension of cybersecurity, including responsibilities, training and fundamental rights.

One particularly striking point concerned the growing number of non-human identities used by applications, automated processes, APIs and AI agents.

Traditional corporate security processes are largely built around the lifecycle of a human employee: a person joins a company, receives access rights, changes roles and eventually leaves, at which point those rights should be removed.

Machines do not necessarily follow this lifecycle.

Service accounts, API credentials, automated agents and other machine identities may remain active long after their original purpose has disappeared. If access rights are not regularly reviewed, these identities can quietly accumulate privileges and become an attractive entry point for attackers.

The message for companies was straightforward: the principle of least privilege must increasingly apply not only to employees, but also to machines and AI systems.

The discussion of AI agents added another layer of complexity. As AI systems gain access to tools such as repositories, project-management platforms and internal corporate systems, the distinction between information and instruction becomes increasingly important.

Content itself can become part of an attack vector.

This means that companies adopting AI cannot rely exclusively on conventional perimeter security. They also need clear governance over what an AI agent can access, what actions it is authorised to perform and how those permissions are monitored.


The Human Factor: Lessons from Real Cybercrime Cases

One of the most practically focused sessions of the conference came from Senior Commissioner Vladimir Dimitrov, Director of the Cybercrime Directorate at Bulgaria’s General Directorate for Combating Organised Crime (GDBOP), Ministry of Interior.

In his presentation, “Building Critical Thinking in Cybersecurity – Practical Examples,” he moved the discussion beyond technology and regulation and into the reality of cybercrime, using cases from practice to demonstrate how attackers exploit human behaviour, trust and established business processes.

Photo © Engineer.bg

A particularly important message was that a successful cyberattack does not always require sophisticated technical intrusion. In many cases, criminals target the person behind the system.

Modern fraud increasingly combines technology with social engineering. Attackers may impersonate business partners, suppliers, customers or logistics providers and use convincing communication to manipulate employees into making decisions that appear entirely legitimate.

Artificial intelligence is making this considerably easier. Fraudulent messages can be produced faster, written in convincing professional language, personalised to a particular company or employee and adapted across languages. As a result, some of the traditional warning signs of phishing – poor grammar, unusual wording or obviously suspicious messages – are becoming less reliable.

Senior Commissioner Dimitrov noted that the Cybercrime Directorate receives reports from Bulgarian companies affected by such attacks on a weekly basis, illustrating how common these schemes have become in everyday business operations.

The practical cases presented during the session also showed how attackers can exploit ordinary commercial processes. A request to change bank details, an unexpected invoice, a new contact supposedly representing an existing partner, or communication involving a transport provider may appear routine – yet can form part of a carefully constructed fraud.

This is particularly relevant for small and medium-sized enterprises, where established relationships and informal communication can sometimes replace more formal verification procedures.

The lesson for businesses was highly practical: cybersecurity depends not only on whether an employee recognises a suspicious email, but also on whether the organisation has procedures that prevent one mistake from becoming a financial loss.

Independent verification of unexpected payment instructions, confirmation of changes to bank details through a separate communication channel, additional checks of unfamiliar suppliers or carriers, and clear internal escalation procedures can provide an essential layer of protection.

Technology can protect systems, but critical thinking and verification remain essential for protecting business decisions.


NIS2 Turns Cybersecurity into a Management Responsibility

The final panel focused directly on cyber threats as a business risk.

Boris Strizlev, Partner at Penkov, Markov & Partners, presented the new regulatory challenges resulting from the transposition of the NIS2 Directive, while Hristo Charkov, CEO of GrECo Bulgaria, examined cyber insurance and the possibilities for transferring part of the financial risk associated with cyber incidents.

The NIS2 discussion made clear that cybersecurity obligations can no longer simply be delegated to an IT department.

The framework expands the range of organisations subject to cybersecurity requirements and places greater emphasis on governance, risk management, supply-chain security, business continuity, incident handling and management accountability.

The presentation highlighted several practical responsibilities for businesses, including organisational and technical measures, internal policies and procedures, risk analysis, business continuity arrangements, supply-chain management and employee training.

Another important element is the speed at which serious cyber incidents must be reported.

For significant incidents, the framework envisages an early warning within 24 hours, followed by an incident notification containing an initial assessment within 72 hours, with further reporting obligations as the incident develops.

This fundamentally changes the level of organisational preparedness required from companies. Discovering an attack is no longer enough. Businesses need to know who makes decisions, who investigates, who communicates and who reports the incident before an attack actually occurs.


The Financial Impact of Cybercrime Is Becoming Impossible to Ignore

Perhaps some of the most striking figures presented during the conference concerned the financial consequences of cyber incidents.

Data shown during the cyber-insurance discussion demonstrated that cyber claims arise from a broad range of events, including theft of funds, accidental data disclosure, ransomware, phishing, data breaches, cyber extortion and malware.

Ransomware remains particularly costly.

One of the datasets presented at the conference indicated that the average ransomware event lasts approximately 25 days and produces an average loss of USD 5.3 million, while the largest individual loss in the cited dataset exceeded USD 500 million.

Even after excluding that exceptional case, the presentation indicated an average ransomware loss of USD 2.9 million in 2025, representing an increase of approximately 7.5% compared with 2024.

These figures illustrate why cybersecurity is increasingly being discussed alongside insurance, business continuity and enterprise risk management rather than solely within IT departments.

Cyber insurance cannot replace preventive security measures, but it can form part of a broader risk-management strategy by helping organisations address the financial consequences of incidents that cannot be completely prevented.


From Cybersecurity to Business Resilience

Across the different panels, one common message emerged.

The question facing companies today is no longer simply:

“How do we prevent a cyberattack?”

A more realistic question is:

“How prepared are we to continue operating when one occurs?”

Cyber resilience increasingly depends on a combination of technology, regulation, governance, employee awareness, supply-chain management, incident-response procedures and financial preparedness.

At the same time, the rapid adoption of artificial intelligence is expanding both sides of the equation. AI can strengthen defence and automate security processes, but it also provides attackers with powerful new tools for reconnaissance, social engineering, phishing and automated exploitation.

For businesses, particularly SMEs that may have limited cybersecurity resources, awareness and preparation therefore become critical.

The Cyber-Security and Digital Sovereignty Conference demonstrated that cybersecurity can no longer be treated as an isolated technical discipline. It is becoming an integral part of corporate governance, operational resilience and long-term business strategy.

HBCB would like to thank the German-Bulgarian Chamber of Industry and Commerce (AHK Bulgaria) for organising the conference and for creating a valuable platform for dialogue between business, institutions, academia, legal experts and cybersecurity professionals.

The official programme included four thematic panels covering digital sovereignty, AI-related threats and autonomous cyber defence, critical thinking in cybersecurity, and cyber threats as a business risk.

More To Explore