Report by AuditBoard
Risk trends to stay ahead in 2026
Key Findings
45% of enterprises are updating existing frameworks.
35% of enterprises are adopting new frameworks.
40% of enterprises plan to increase cybersecurity staffing.
The median enterprise maps its controls to about seven frameworks.
The median enterprise maps its controls to about 2,700 requirements.
The GDPR is one of the top 5 frameworks adopted by organizations.
Fewer than 30% of enterprises feel prepared for upcoming AI governance requirements.
ISO 27001 is one of the top 5 frameworks adopted by organizations.
NIST Cybersecurity Framework (CSF) 2.0 is one of the top 5 frameworks adopted by organizations.
Enterprises conducting six or more risk assessments per year report stronger overall risk discipline and telemetry scores.
The Secure Controls Framework (SCF) is one of the top 5 frameworks adopted by organizations.
SOC 2 is one of the top 5 frameworks adopted by organizations.