Skip to content
Ekontrol
Back to Resources

Information Security Threats and Problems for Business in 2026: How to Assess and Close the Risks

Information security threats to business in 2026: phishing, ransomware, wartime attacks. Assess your real risks with ISO/IEC 27001 instead of ad-hoc defense.

Published July 28, 202613 min read
Information security threats to business: cyber defense and risk assessment under ISO/IEC 27001

Information Security Problems: Why 2026 Won't Forgive Improvisation

Information security problems stopped being an issue for the IT department on some technical floor a long time ago. Today they decide whether your business will still be running next week. A phishing email a sales manager opened. Ransomware that took down accounting the day before the reporting deadline. An online store's site knocked offline on Black Friday. None of these is a hypothesis from a slide. They're the everyday reality Ukrainian companies face weekly.

In 2024 the government team CERT-UA processed 4,315 cyber incidents, 69.8% more than the year before, when there were 2,541 (figures from the CERT-UA 2024 report). And those are only the cases that reached the state response team; most attacks on private business never make it into any statistics at all. The point isn't even that there are more threats, though there are. It's that most companies still defend themselves as if it were 2015: antivirus, a Wi-Fi password, and the hope that it won't happen to them.

Below we look at which information security threats are real for Ukrainian business right now, why a defense built from separate tools loses systematically, and how risk assessment inside ISO/IEC 27001 turns chaotic protection into a managed system. If you'd first like the wider picture of the standard, start with our complete guide to ISO/IEC 27001, then come back here for the detail on threats.

Threat, Vulnerability, and Risk Are Three Different Things

People often use these words as synonyms, and that's exactly where the confusion starts. A threat is what can harm you: a phishing campaign, ransomware, an attacker. A vulnerability is the hole the threat comes through: an unpatched server, a weak password, an untrained employee. Risk is the combination of likelihood and impact: how probable it is that a specific threat exploits a specific vulnerability, and what it will cost you. ISO/IEC 27001 works with risks, not with individual threats one by one.

The Scale: What Incidents Cost a Business

Let's start with money, because money is the most convincing argument. According to the IBM Cost of a Data Breach 2025 report, the global average cost of a single data breach is USD 4.44 million. This year the figure dipped for the first time in five years thanks to faster detection, but even reduced it's larger than the annual turnover of many companies. In the US the average breach already costs USD 10.22 million.

Ukrainian businesses are usually far from those sums, yet the logic is the same: an incident means more than stolen data. It means downtime, reputation damage, fines, a scramble across the team, and customers who left for a competitor while your service was down. And time, too: recovery after a serious attack is measured not in hours but in days and weeks, during which the business either stands still or works at half capacity.

In its 2024 report CERT-UA names directly who gets attacked most often: local government, government organizations, the security and defense sector, energy, commercial companies, and telecom. If it seems to you that your business is "too small to interest anyone," remember that most mass attacks don't pick their victim by name. They hit everyone whose door is open.

Types of Information Security Threats: Who Attacks Business and How

To defend yourself specifically, you have to know against what. Here are the main types of information security threats a Ukrainian business runs into, from the most widespread to the most expensive. This isn't a textbook list, it's what actually shows up in practice.

One class of threat concerns personal data, and there Ukrainian law and the GDPR sit on top of ISO/IEC 27001. That combination is covered in personal data protection and ISO/IEC 27701.

Phishing and Social Engineering

Phishing remains threat number one, and that's not an exaggeration. According to ENISA Threat Landscape 2025, it dominates intrusion vectors, accounting for around 60% of all recorded intrusions. The reason is simple: hacking a person is cheaper than hacking a system. An email from the "director" asking to urgently pay an invoice, a fake corporate login page, a call from the "bank security service": all of it works because it presses on emotion and haste.

Worse, phishing has grown in quality. That same IBM report notes that in 16% of breaches attackers already used artificial intelligence, mostly to generate more convincing emails and deepfakes. The days of clumsy, typo-ridden messages you could spot a mile off are ending.

Ransomware

A ransomware program gets into the network, quietly spreads across the servers, then encrypts everything it can reach all at once and shows a ransom demand. For a business this is the worst case: data locked, work halted, and paying the ransom is neither a guarantee of getting it back nor anything other than funding the next attack. Per Verizon DBIR 2025, ransomware is already present in 44% of all data breaches and hits small and medium businesses disproportionately, since they rarely have a dedicated security team. One piece of good news: the median ransom paid last year fell to USD 115,000, and 64% of companies refused to pay at all.

Attacks Through Partners and the Supply Chain

You can be breached not directly but through a contractor you've trusted with access. That same Verizon DBIR 2025 found that third-party involvement in breaches doubled over the year, from 15% to 30%. For IT companies this is especially painful: one compromised library or service provider drags all of its clients down with it. That's exactly why clients from the EU and US increasingly demand an ISO/IEC 27001 certificate before they even sign a contract: they need to know you won't become a hole in their own defense.

DDoS, Vulnerabilities, and Stolen Credentials

Three threats different in nature but equally common. A DDoS attack floods your site or service with requests until it falls over, and per ENISA it's the most frequent incident type in Europe. Exploitation of vulnerabilities is when an attacker walks in through an unpatched hole in software; per Verizon this vector grew 34% over the year. And stolen or guessed credentials remain the most common way to simply log in under someone else's name, without any "hack" in the movie sense.

Insiders and the Human Factor

Not every data loss is the result of an external attack. An administrator dismissed with a grudge, an employee who leaked the customer database to a competitor, or just someone who lost an unencrypted laptop. The human factor runs through all the previous points: technology holds a threat back only as long as the people around it behave predictably. That's why staff training isn't a formality, it's part of the defense on par with the firewall.

Type of threatHow it worksTypical business impact
Phishing and social engineeringTricks a person into handing over access or moneyCompromised email, fraudulent transfers
RansomwareEncrypts data and demands a ransomDowntime, data loss, recovery costs
Supply chain attacksEnters through a hacked contractor or serviceCompromise even when your own defense holds
DDoSOverloads a service with a flood of requestsSite downtime, lost sales
Vulnerabilities and stolen credentialsUses unpatched holes and someone else's loginsUnauthorized access to systems and data
InsidersAbuse of access from the insideDatabase leak, sabotage, data theft

Wartime Threats: The Ukrainian Context

Ukrainian business lives in conditions you won't find in any Western security textbook. Here a cyberattack often works as an instrument of war, not just a way to make money. And the targets aren't always military: often the blow lands on civilian infrastructure, to hurt everyone at once. Three examples worth keeping in mind for every executive.

Kyivstar, December 2023. The attack knocked out the network of the country's largest mobile operator. Parent company VEON estimated the incident's impact on 2024 revenue at roughly UAH 3.6 billion, about USD 95 million. One incident, and tens of millions of subscribers left without connection while the company counts losses by the quarter.

FrostyGoop, Lviv, January 2024. Malware that reached heating equipment through the industrial Modbus protocol left around 600 buildings without heat for nearly two days, in the middle of winter. It's a rare example of a cyberattack with a direct physical consequence for ordinary people, not just for a company's balance sheet.

State registries, December 2024. A large-scale attack halted the Ministry of Justice registries, including the Unified State Register of Legal Entities and Sole Proprietors. For weeks businesses couldn't properly register companies, carry out notarial acts, or run part of their operations; full restoration stretched to almost a month. Ukrainian authorities publicly linked the attack to Russia.

What all three share isn't the technology but the lesson: business resilience now depends on whether a company is ready to keep working when something big breaks. And it does break.

Why Piecemeal Defense Fails

Here we get to the heart of it. The trouble with most companies isn't the absence of defense, it's how patchy it is. They bought antivirus. Installed a firewall. Forced password changes every quarter. Each thing on its own looks useful, but together they don't add up to a system, and incidents live in exactly the gaps between them.

Here's how piecemeal defense loses in practice:

  • No owner. A notional sysadmin is responsible for antivirus, HR for passwords, department heads for access. When an incident happens, it turns out no one owns the overall picture.
  • Reacting to what's trendy, not what's real. A company buys an expensive tool against a threat from the news, while the basic backup has never once been tested for restoration.
  • Defense not weighted by risk. The critical customer database and an outdated printer get equal attention, though their value to the business isn't remotely comparable.
  • No one reviews it. Set up once and forgotten, while the threats have changed several times over.

The difference between a set of tools and a system comes down to one word: priorities. A system starts not with "what should we buy" but with "what are we most afraid to lose, and what is most likely to happen to it." That is risk assessment, and it's exactly what ISO/IEC 27001 requires.

Antivirus Isn't a Security System Yet

The most common executive mistake is to assume that bought tools equal protection. Antivirus, a firewall, and complex passwords are necessary, but they're separate bricks, not a house. Without risk assessment, assigned owners, and regular review, you don't know the main thing: what exactly you're protecting, from what, and how well. An incident exposes those gaps at the worst possible moment, when it's already too late to pay for them.

Working With EU and US Clients?

Clients increasingly demand ISO/IEC 27001 before the contract. See how Ekontrol prepares IT and SaaS companies for information security certification, from risk assessment to the certification audit.

ISO/IEC 27001 preparation for IT companies

Information Security Risk Assessment in ISO/IEC 27001

ISO/IEC 27001 isn't a list of technical requirements like "install this particular antivirus." The standard deliberately doesn't dictate tools. Instead it requires one thing: build a process in which you systematically identify your information security risks and consciously decide what to do about each. The heart of that process is risk assessment, described in clause 6.1.2 of the standard.

In practice it runs through several steps:

  1. Define what you're protecting. Draw up an inventory of assets: customer databases, source code, financial data, access rights. You can't protect what you've forgotten exists.
  2. Find the threats and vulnerabilities. For each asset, what threatens it and through which hole. This is where all the threat types from the previous sections come in handy.
  3. Assess the risk. How likely the threat is to materialize, and how hard it will hit. That's how a priority appears: what to put out first.
  4. Choose what to do. A risk can be reduced by implementing a control, accepted by consciously living with it, transferred by insuring it, or avoided by stopping the risky activity.
  5. Record and review. Decisions are documented, and the assessment itself repeats regularly, because threats don't stand still.

The real value here isn't the paperwork, it's that defense becomes weighted. You no longer spend equal effort on the critical and the secondary. Resources go where the risk is highest, and that's visible to an executive now, not only to technical staff. We laid out in detail how this process fits into the overall certification path in our ISO/IEC 27001 guide.

Risk Assessment Hands You Ready Priorities

The moment you've been through risk assessment, you have something no single tool gives you: a justified plan. You can see which threats are most dangerous for your business specifically, where to direct budget first, and what can wait. The security conversation shifts from "buy us one more antivirus" to "here are our three top risks and what we're doing about them." Management finally sees the picture, not a stack of technical requests.

From Threats to Controls: How ISO/IEC 27001 Closes the Gaps

Risk assessment shows what hurts. Then the standard offers a tool to treat it: the set of controls in Annex A (93 of them in the 2022 edition, grouped into four themes: organizational, people, physical, and technological). You don't have to implement all of them, only those matching your risks. Here's how typical threats map onto the standard's controls:

ThreatWhat you implement in responseISO/IEC 27001 control theme
Phishing and social engineeringStaff training, multi-factor authenticationPeople and organizational controls
RansomwareBackups, network segmentation, a response planTechnological controls, incident management
Supply chain attacksContractor risk assessment, security clauses in contractsSupplier relationship security
Stolen credentialsAccess control, logging, login monitoringAccess control and technological controls
InsidersSegregation of rights, revoking access on departureAccess management, people controls

See the logic? You don't chase every new threat separately. You build a system once that tells you where you're weak and hands you a ready framework of responses. That's the difference between patching holes and managing security.

Where to Start This Month

Full certification is a project of several months. But you can start putting things in order right now, before any audit. Here's where it's worth starting:

  • Draw up a simple list of what you protect. Half an hour and a table: which data and systems are critical to the business. That's already half of a risk assessment.
  • Test your backups by restoring them. Not "do they exist" but "can you actually bring a system back up from them." The difference is enormous.
  • Turn on multi-factor authentication everywhere you can. It's the cheapest way to make a stolen password worthless.
  • Assign an owner for information security: one person who sees the whole picture, not fragments scattered across departments.
  • Write down what to do during an incident. One page is enough: who calls whom, what gets disconnected, who gets notified.

If you don't yet have a confident "yes" for most of these points, that's not cause for embarrassment but a to-do list. And almost every item is already an element of an information security management system under ISO/IEC 27001, not separate paperwork for its own sake.

How Ekontrol Helps Assess Information Security Risks

Ekontrol supports preparation for ISO/IEC 27001 as part of its information security practice. We start not with paperwork but with a conversation about your real threats: what data you hold, who your clients are, what your contracts demand, and where things are actually thin. Then comes risk assessment, choosing controls to fit your priorities, implementation, and preparation for the certification audit.

For IT and SaaS companies working with EU and US clients, an ISO/IEC 27001 certificate is also a tender advantage: a ready answer to the security questionnaires clients send before the contract. We know the questions they ask, and we build the system so there's something to answer with.

If information security problems at your company are still handled on a "we'll fix it when it breaks" basis, it's time to move to a system. You can start with the complete guide to ISO/IEC 27001 or write to our team right away to discuss where you specifically should begin. Ekontrol has worked as a Bureau Veritas partner in Ukraine since 2014.

FAQ: Questions About Information Security Threats and Problems

The questions executives most often ask when they first start thinking about information security threats and problems systematically, rather than in firefighting mode.

Tags