The New Cyber Calculation CFOs Must Make | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


There’s a new number in cybersecurity for CFOs to track, and it’s not the list of what was stolen. It’s the number of obligations created.

Headlines this week offered a glimpse of what that new cyber math looks like.

Manchester Airports Group disclosed that an unauthorized third party accessed information associated with roughly 8.7 million customers across Manchester, London Stansted and East Midlands airports. The compromised information included contact, vehicle and booking-related data, although the company said payment information and aviation security were not affected.

In Australia, a cyberattack against Alliance Distribution Services, owned by Hachette Australia, has disrupted book distribution for roughly six weeks, demonstrating how an IT incident at an intermediary can become an inventory, revenue and working-capital problem for businesses down the line.

Boston Scientific disclosed Wednesday (Aug. 26) that an incident detected the previous day caused a network outage affecting operating systems and business applications, including its ability to process and ship customer orders. The company filed an 8-K and said it could not yet estimate when full operations would be restored.

And perhaps most consequentially, investigations into OpenAI’s July security incident showed how experimental AI agents escaped their intended boundaries and reached real external infrastructure, including Hugging Face. OpenAI has described the episode as unprecedented and said it has tightened infrastructure controls while conducting further investigation.

Taken together, these incidents expose the same underlying corporate vulnerability. Companies have built interconnected enterprises. Their incident-response models still largely assume discrete incidents.

See also: AI Gives Cybersecurity a Backlog CFOs and CISOs Can’t Patch Away

The Cyberattack Blast Radius Is Becoming the Business Graph

Traditional cyber planning tended to begin with infrastructure: What systems could be compromised? What data could be stolen? How quickly can the attacker be contained?

But the architecture of the modern enterprise has changed faster than the architecture of incident response. Companies have spent years connecting cloud environments, APIs, SaaS applications, payment systems, data platforms, suppliers and customers. Agentic AI promises to make those connections more productive by allowing software to move across them and take action autonomously.

The emerging risk for CFOs and CISOs is therefore not simply a larger attack surface. It is a larger obligation surface: every system an autonomous process touches can potentially bring another customer agreement, regulator, insurer, jurisdiction, disclosure requirement or business dependency into an incident. The administrative cost of a cyberattack correlates not only with the amount of data compromised, but with the connectivity of the company experiencing it.

We’d love to be your preferred source for news.

Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

PYMNTS covered on Thursday (Aug. 27) how the rise of artificial intelligence-powered hacks already has cyber insurance firms rethinking their policies.

A conventional software application generally performs predetermined functions inside relatively stable boundaries. An enterprise AI agent is valuable precisely because those boundaries are more permeable. Give an AI agent access to email, CRM, ERP software, cloud storage, payment infrastructure and procurement systems, and it can potentially complete an entire workflow without requiring a person to move information between applications.

The PYMNTS Intelligence report “Vendors and Vulnerabilities: The Cyberattack Squeeze on Mid-Market Firms” found that hackers increasingly target middle market firms. These companies depend on third-party cloud providers, software-as-a-service platforms and managed service providers, which can leave them exposed.

Read more: Innovation Keeps Expanding Compliance for Mid-Market Firms 

Agentic AI Turns Permissions Into Potential Liabilities

Every permission also represents another possible path through which an incident can acquire financial, regulatory or contractual significance. During OpenAI’s cybersecurity evaluations, models found and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure. OpenAI said it subsequently imposed stricter infrastructure controls, accepting an impact on research velocity while vulnerabilities were addressed.

The broader lesson for companies deploying agents is that agent permissions need to be understood as financial exposures, not merely technical configurations. Depending on the incident, companies can simultaneously face state privacy requirements, international data-protection rules, sector-specific regulators, customers, cyber insurers, lenders, payment networks, vendors and contractual notification clauses.

A company that tells a customer one version of an incident, an insurer another and investors a third has created a second-order governance problem even if each individual disclosure was produced in good faith as the investigation evolved. A payment orchestration platform touching thousands of merchants may carry a radically different exposure from an internal application containing a comparable amount of data. A SaaS administrator credential connected to dozens of applications may create more consequential downstream obligations than a much larger isolated database.

IBM said last month that a higher percentage of companies were planning to up their security spending after finding out about the cyber capabilities of frontier AI models, and 68% of financial institutions increased their fraud-detection budgets year over year, according to the “2025 State of Fraud and Financial Crime in the United States,” a PYMNTS Intelligence report produced in collaboration with Block. That spending comes as 46% of institutions report increasingly sophisticated fraud schemes, up from 35% a year earlier.

For all PYMNTS B2B coverage, subscribe to the daily B2B Newsletter.

——————————————————-


Click Here For The Original Source.