“Ransomware.” “Supply chain attacks.” “AI risk.” I suspect a lot of people let these words, which they keep seeing in the news, slide past without ever quite working out how much they actually apply to their own company.
One yearly resource you can use to make that judgment is the 10 Major Threats to Information Security published by IPA (the Information-technology Promotion Agency, an independent administrative institution). It’s chosen by deliberation and vote among a selection committee of roughly 250 people, including researchers and working professionals from companies, covering the threats that had the largest societal impact in the previous year; the 2026 edition was published on January 29, 2026.
This article walks through the top 10 of the 2026 organizational edition and works out which of them an SME should treat as its own problem, and where to start.
1. The Bottom Line First
- In the 2026 organizational edition, the top spots are frozen in place: #1 ransomware attacks (11 years running), #2 supply chain attacks (8 years running). In other words, it isn’t that “the trend has changed” — it’s that “the same attacks keep working”
- “Cyber risk around AI use,” selected for the first time, comes in at #3. It covers not just attackers abusing AI, but also information leaks from your own employees’ use of AI
- The ones especially relevant to SMEs are ransomware attacks, supply chain attacks (as the party being targeted), exploitation of vulnerabilities, and business email compromise
- Most of the top-ranked threats rest on a foundation of basic countermeasures — updating the OS and software, backups, stronger passwords, and knowing the attackers’ methods. Before buying a new product because of the ranking, check how thoroughly you’re actually applying the basics
- Use the ranking as a once-a-year trigger for revisiting your own countermeasures. Decide priority by the impact on your own company if it happened, not by the rank itself
2. The Organizational Edition Top 10 (2026 Edition)
| Rank | Threat | Selection history |
|---|---|---|
| 1 | Damage from ransomware attacks | 11th time, 11 years running |
| 2 | Attacks targeting supply chains or subcontractors | 8th time, 8 years running |
| 3 | Cyber risk around AI use | First selection |
| 4 | Attacks exploiting system vulnerabilities | 9th time, 6 years running |
| 5 | Targeted attacks aimed at confidential information | 11th time, 11 years running |
| 6 | Cyberattacks driven by geopolitical risk | 2nd time, 2 years running |
| 7 | Information leaks and the like from internal wrongdoing | 11th time, 11 years running |
| 8 | Attacks targeting remote-work environments and mechanisms | 6th time, 6 years running |
| 9 | DDoS attacks | 7th time, 2 years running |
| 10 | Business email compromise | 9th time, 9 years running |
There’s also an individual edition, but it lists its 10 items in syllabary order without ranking them — a deliberate design to avoid the misreading of “it’s ranked low, so it’s fine.” The same mindset applies just as directly to how you should read the organizational edition.
Looking at the list, what stands out is how frozen the lineup is. Ranks 1 and 2 haven’t changed in over four years, and most of the top 10 have been selected for five years or more running. Attack methods get more sophisticated year by year, but what gets targeted hasn’t changed. Which means the direction of your countermeasures doesn’t need to be rethought from zero every year either — the core of it is just continuing to raise how thoroughly you apply the basics.
3. The Top Threats, Seen From an SME’s Perspective
#1: Ransomware Attacks — “Holding Data Hostage to Stop the Business”
This is an attack that encrypts your data, among other things, and demands a ransom. It’s not just a large-company problem — SMEs with thin security measures get targeted precisely because they’re easy to break into. The damage isn’t limited to a data leak; it goes straight to a business stoppage where you can no longer take orders or ship anything.
The pillars of the countermeasure are closing off the routes of entry (updating VPN appliances, the OS, and software; strengthening passwords) and preparing to resume business even if you are breached (taking backups, storing them in isolation, and verifying you can restore them). When IPA’s “Information Security Guideline for SMEs” Version 4.0 added “Take backups!” to its “6 Articles of Information Security,” that was precisely to prepare for this threat (see our article on the Guideline’s 4th edition for details).
#2: Attacks Targeting Supply Chains or Subcontractors — SMEs Get Targeted as the “Entry Point”
Rather than attacking the target company directly, this attack uses a business partner or subcontractor with weaker security as a stepping stone in. For an SME, this threat carries a double meaning: not only can “your own company be the victim,” but “your own company can be turned into the entry point for harming your business partner.”
This is exactly why security-check sheets have started arriving from business partners. Going forward, the movement to verify the level of countermeasures across the entire supply chain is only going to strengthen, never weaken. Getting your own countermeasures far enough along that you can explain them is becoming a business requirement for continuing the relationship, as much as it is a security measure.
#3: Cyber Risk Around AI Use — First Selection
This became a candidate threat for the first time and was immediately selected at #3. Its content spans both attack and usage. IPA’s press release cites unintended information leaks or infringement of others’ rights arising from an insufficient understanding of AI, problems that arise from taking AI-processed or AI-generated output at face value without adequate verification, and cyberattacks being made easier and more sophisticated through the abuse of AI.
For an SME, the practically relevant issue is less the attackers’ own use of AI, and more your own employees’ use of generative AI. Is it okay to feed customer information or design information into an AI service? Is it okay to use generated text or code without checking it? Both an outright ban and complete laissez-faire lead to trouble, so the first step is deciding simple in-house rules for “what’s okay to input” and “how to verify the output.”
#4: Attacks Exploiting System Vulnerabilities — “Neglected Updates” Become the Way In
This attack strikes a known weakness in software. Devices and software where a patch has already been released but never applied get targeted. Typical examples are VPN appliances, an OS whose support has ended, and a WordPress site that’s stopped receiving updates.
This isn’t a technically sophisticated issue — it’s an operational one, about whether it’s actually decided who updates what, and when. If your own website might fall into this category, also see our article on IPA’s “How to Secure Your Website”.
#7: Internal Wrongdoing and #10: Business Email Compromise — Threats of People and Procedure
Information leaks from internal wrongdoing are a threat involving current or former employees — a departing employee walking off with customer data, for example. The countermeasure is a stack of unglamorous procedures: tidying up access privileges, disabling accounts on departure, and wiping data from PCs being disposed of.
Business email compromise is a scam that impersonates a business partner or an executive to induce a wire transfer to a fake account. Alongside technical measures, a business rule like “always confirm a change of transfer destination by phone” is the decisive factor. When reviewing your email practices, our piece on ditching PPAP is worth considering in the same context.
4. The Right Way to Use the Ranking
The 10 Major Threats gets talked about every year, but use it the wrong way and you end up putting the cart before the horse — “buy a product aimed at this year’s #1 threat and call it done.” What IPA actually emphasizes is continuously gathering threat information and identifying and addressing the risks relevant to your own organization.
In practice, it’s realistic to turn this into the following yearly routine.
- When it’s published every year at the end of January, look through the top 10 and think through, one by one, “what would stop functioning if this happened to us”
- For the threats deeply relevant to your company, check how thoroughly you’re applying the basic countermeasures (updating the OS and software, backups, passwords, sharing settings, knowing the attackers’ methods)
- Where there’s a gap, fill it in using the self-assessment and appendices of the Information Security Guidelines for SMEs
IPA also publishes a 64-page explanatory booklet and presentation materials for the organizational edition free of charge, and you can use them as-is for a morning meeting or in-house training. “Know the threats and attackers’ methods” is itself one of the 6 Articles of Information Security, and simply sharing the 10 Major Threats internally once a year already counts as putting it into practice.
Summary
Here’s a recap of the key points of the Information Security 10 Major Threats 2026.
- The organizational edition has ransomware attacks at #1, supply chain attacks at #2, and AI risk, selected for the first time, at #3. The top spots have been frozen for years now, which shows that the same attacks keep working
- SMEs should treat ransomware, supply chain attacks, vulnerability exploitation, and business email compromise as especially their own problem
- AI risk isn’t just about the attack side — it also includes information leaks and taking output at face value through employees’ own use of generative AI. Start with simple in-house rules
- The foundation of countermeasures for the top threats is thorough application of the basics. Use the ranking as a once-a-year trigger for review
- The rank reflects impact on society as a whole; your own priority order should be decided from the impact on your own business
If You’re Struggling to Identify the Threats Relevant to Your Business
Judging “which threats are relevant to us” requires actually understanding your own system configuration and business workflow. Do you have a VPN? Where’s old software still running? Can your backups actually be restored? This kind of inventory is individual verification work, not a matter of general theory.
Komura Software LLC, drawing on our experience developing and maintaining Windows business applications and web systems, takes on consultations for identifying risks around business systems and for modifying and maintaining existing software that’s stopped receiving updates. We’re happy to talk even at the stage of “I don’t even know where to start checking.”
Related Articles
Recent articles sharing the same tags. Deepen your understanding with closely related topics.
Where Should SMEs Start on Security? — A Walkthrough of IPA's 'Information Security Guidelines for SMEs,' 4th Edition
Where should small and medium-sized businesses start on security? Drawing on IPA's 'Information Security Guidelines for Small and Medium ...
What Website Clients Should Know Too — Using IPA's 'How to Secure Your Website' as a Checklist
What standard should you use to check your company website's security against? This article explains the 11 vulnerabilities and counterme...
Don't Forget to Decide 'How Many Seconds Is Fast Enough' — Organizing Non-Functional Requirements With IPA's Non-Functional Requirements Grade
Disputes like 'it's too slow' or 'we didn't expect that failure response' usually trace back to non-functional requirements nobody decide...
How Should You Structure a Contract Development or Operations & Maintenance Contract? — Learning the Quasi-Mandate vs. Contract-for-Work Distinction from IPA's 'Model Contract'
When you outsource system development, how should the contract be structured? Drawing on the 'Information System Model Transaction and Co...
Website Development Costs for SMEs — A Quick-Reference Price Guide and How to Read a Quote
What SMEs should know before requesting a website development quote: price guides broken down by purpose and scale, how to read the line ...
Related Topics
These topic pages place the article in a broader service and decision context.
Windows Technical Topics
Topic hub for KomuraSoft LLC's Windows development, investigation, and legacy-asset articles.
Where This Topic Connects
This article connects naturally to the following service pages.
Technical Consulting & Design Review
Identifying the threats most relevant to your business and pinpointing where your system configuration and operations are weak fall within the scope of technical consulting that includes a design review.
Windows Software Maintenance & Modernization
Countering 'attacks that exploit system vulnerabilities' is inseparable from modifying and maintaining business systems that keep running old, no-longer-updated Windows installations or software.
Frequently Asked Questions
Common questions about the topic of this article.
- What is the Information Security 10 Major Threats?
- It's an annual ranking, published by IPA (the Information-technology Promotion Agency, an independent administrative institution), of the information security threats that had the largest societal impact in the previous year. IPA selects the candidate threats, and the final ranking is decided by deliberation and voting from the '10 Major Threats Selection Committee,' made up of roughly 250 people including researchers and working professionals from companies. There's an organizational edition and an individual edition, and the 2026 edition was published on January 29, 2026. For the organizational edition, an explanatory booklet and presentation materials are also released free of charge, and they can be used for in-house training as well.
- Is there a new threat in the 2026 organizational edition?
- 'Cyber risk around AI use' became a candidate threat for the first time and was immediately selected at third place. It covers risks on both the usage side and the attack side: unintended information leaks or infringement of others' rights caused by an insufficient understanding of AI, problems arising from taking AI-generated output at face value without verifying it, and cyberattacks being made easier and more sophisticated through the abuse of AI.
- Which item on the ranking should an SME address first?
- The basic rule is to choose by 'the impact if it happened to your own company,' rather than by rank, but the threats that tend to be deeply relevant across most SMEs are: #1, ransomware attacks (backups and entry-point defenses); #2, supply chain attacks (being targeted as, or asked to prove security as, a business partner); #4, attacks exploiting system vulnerabilities (neglected VPN appliances or outdated software); and #10, business email compromise (fraud such as fake changes to a transfer destination). In every case, basic countermeasures — updating the OS and software, taking backups, and strengthening passwords — form the foundation.
- Is it fine to ignore threats that didn't make the ranking?
- No, that's not a good idea. The 10 Major Threats is nothing more than a ranking of what had a large societal impact in the previous year; how important something is to your own organization is a separate matter from its rank. IPA itself stresses the importance of continuously gathering threat information and identifying and addressing the risks relevant to your own organization. The right way to use the ranking is as a trigger for learning general trends and revisiting your own countermeasures.
Author Profile
Profile page for the article author.
Go Komura
Representative of KomuraSoft LLC
Focused on Windows software development, technical consulting, and investigations into failures that are difficult to reproduce.
Public links