The latest 2026 Voice of the CISO findings show that cyber risk is changing rather than simply increasing. The research, based on more than 1,600 CISOs across 16 countries, shows that some traditional indicators have improved. The number of CISOs expecting a material cyberattack within the next 12 months fell from 76% in 2025 to 61% in 2026, while reported material data loss dropped from 66% to 53%. However, the wider five-year trend shows that cybersecurity is becoming more connected to everyday business operations. Risk is increasingly moving into the systems, people, applications, data, and workflows that employees use every day.
Artificial intelligence is one of the biggest reasons behind this change. In 2026, 78% of CISOs identified generative AI as a security risk, compared with 60% in 2025 and 54% in 2024. At the same time, 85% said enabling the safe use of AI assistants, copilots, and automation is a major priority for the next two years. However, 79% said they are expected to manage AI-related risks without a proportional increase in resources or expertise. Many organizations are also restricting employee use of GenAI, but simply blocking these tools is becoming less practical as AI becomes part of normal business workflows.
Human behavior remains another major concern for security leaders. In 2026, 79% of CISOs identified human risk as their organization’s biggest cyber vulnerability, rising from 66% in 2025. The problem is not limited to accidental mistakes or poor security awareness. Among organizations that experienced material data loss, malicious or criminal insiders were reported as a leading cause by 46%, while careless and compromised insiders were each cited by 38%. Departing employees were also involved in material data loss at 93% of organizations that experienced such losses. This shows why human risk is increasingly being treated as a wider systems, identity, access, and data-security problem.
Although fewer organizations reported material data loss, the consequences became more serious for those that were affected. Regulatory sanctions increased from 34% to 40%, financial losses increased from 27% to 38%, and post-attack recovery costs increased from 32% to 38%. Reputational damage also rose from 31% to 37%. CISOs are particularly concerned about technologies that are deeply connected to everyday work, including collaboration platforms, AI assistants and autonomous agents, SaaS applications and third-party integrations, public GenAI tools, and cloud storage and file-sharing platforms. This means data security can no longer be separated from the tools employees depend on to perform their jobs.
The relationship between CISOs and company boards has also changed. In 2026, 85% of CISOs said they see eye to eye with their boards on cybersecurity, a major increase from 64% in 2025. However, stronger board alignment has not reduced pressure on security leaders. Seventy-seven percent of CISOs said excessive expectations are placed on them, while 86% believe cybersecurity expertise should be required at the board-director level. Boards are increasingly looking at cyber risk through a business perspective, focusing on issues such as enterprise value, downtime, reputation, operational disruption, sensitive data loss, customer trust, and revenue.
The main message from the 2026 findings is that cyber risk has moved closer to the actual flow of work. Security teams now have to consider how people, identities, data, applications, cloud services, AI systems, and automation interact with each other every day. AI governance needs to include data protection and control over what systems can access or do, while human risk needs to be managed throughout the employee lifecycle, especially when access or responsibilities change. For CISOs, the challenge is no longer only stopping attacks at the perimeter. It is protecting the business wherever modern work happens and making sure productivity does not create uncontrolled security exposure.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news