Geopolitical Cyber Risk
Index (GCRI)

Next Peak developed the GCRI to provide global clients with a multi-dimensional view of cyber risks across country-level jurisdictions. The GCRI translates qualitative intelligence into measurable risk to support strategic decision-making and can customize country profiles based on client organizations' sectors, country of origin, operations, and more.

36
Countries
~87%
of World GDP
48
Indicators
40+
Sources
4
Risk Categories

Enterprise Risk in Numbers

Methodology

The GCRI is built from 48 indicators across 36 countries. The indicators draw from 40+ authoritative sources — including the Lowy Cyber Capabilities index, the International Telecommunication Union (ITU), the National Cyber Security Index (NCSI), the Oxford Cybercrime Index, Freedom House, the Global Peace Index, and Stanford's AI Index — subject-matter expert insights, and the ICR team analytical review.

The Index creates a geo-cyber risk profile of every country by assessing four categories:

01 State Cyber Risk

To what extent a host or foreign government uses offensive cyber, espionage, regulatory mandates, and control over infrastructure, AI, and data to disrupt or coerce organizations operating in the country.

02 Criminal Cyber Risk

How prevalent cybercrime is — malware, ransomware, data theft, scams — and how well local enforcement, anti-corruption, and AML environments contain it.

03 Socioeconomic & Geopolitical Risk

Exposure to instability from economic fragility, inequality, restricted civil liberties, sanctions, and volatile geopolitics.

04 Commercial Capabilities & Cyber Literacy Gaps

Maturity level of local business, infrastructure, education, and R&D regarding cyber defense and security.

Benchmark your exposure

Use the GCRI to understand, analyze and stress-test your supply chain, subsidiaries, and target markets against the state, criminal, and geopolitical threats they actually face.