Market value may drop by 27% following a reputational cyberattack

Cyber incidents that damage a company’s reputation can lead to an average shareholder value decline of 27%, according to Aon plc’s 2025 Cyber Risk Report.
The study analyzes over 1,400 cyber events worldwide and builds upon findings from its 2023 edition, which recorded an average 9% drop in shareholder value following major cyber incidents.
In this latest report, Aon identifies which types of attacks are most likely to escalate into reputational crises and which are the most damaging in this regard.
Edwin Sabogal, Cyber Manager for Latin America at Aon, explains:
“Cyber risk is no longer just a technology issue—it’s an organizational issue. Our latest research highlights the importance of proactive risk mitigation. Organizations that invest in preparedness and resilience are significantly better positioned to avoid the reputational and financial consequences of cyber events, primarily by minimizing business disruption, which is the main driver of reputational impact.”
Sabogal also emphasized that in Latin America:
“Companies have made progress in combating cyber threats, resulting in a slight improvement in the region’s overall risk score. Local firms are now better positioned to secure cyber insurance policies thanks to internal training initiatives—including at the executive level—which are fostering greater cyber maturity and awareness, alongside a more accommodating insurance market.”
Key Findings from the Report
Among the report’s main insights:
– Of the 1,414 cyber events analyzed, 56 escalated into reputational incidents—defined as those that attract significant media attention and lead to a measurable drop in share price.
– Companies affected by these incidents saw an average 27% decline in shareholder value.
– Malware and ransomware attacks accounted for 60% of reputational incidents, despite representing only 45% of total cyberattacks.
– The report identifies five critical factors in value recovery: preparedness, leadership, swift action, communication, and transformation.
Latin America Overview.
Regarding Latin America, the report highlights that in 2024 the region experienced the fastest growth in reported cyber incidents.
There was an average annual increase of 25% over the past decade, according to World Bank data.
The most affected countries in the region were Brazil (47% of attacks), followed by Mexico (23%) and Colombia (8%), based on data from industry sources.
Despite these figures, Latin American companies slightly improved their overall risk scores, reaching an average of 2.59 out of 4 in 2024.
This score indicates a maturity level between basic and managed preparedness, though still below the global average of 2.71.
The report also notes that low investment in cybersecurity and the predominance of small and medium-sized enterprises—accounting for 99.5% of the market—make Latin America an attractive target for ransomware groups.
This conclusion is based on findings from the Organisation for Economic Co-operation and Development (OECD).
Finally, Aon warns of the growing challenge posed by non-insurable cyber risks.
While cyber insurance helps transfer certain financial risks, reputational damage remains largely uninsurable.
Therefore, proactive risk management and rapid crisis response are essential.
The 2025 Cyber Risk Report is based on proprietary data from Aon’s Cyber Quantification Assessment.
This is a global platform that supports cyber insurance underwriting and provides organizations with insights to improve their risk exposure and management strategies.

