Report by MetaCompliance

78% of CISOs say C-level do not fully understand employee-driven cyber risk

10 FINDINGSPublished Jul 9, 2026
View Original Report →

Key Findings

41% of CISOs are concerned about malicious insiders using AI to support fraud, cybercrime or data theft.

Insider ThreatAIHuman Risk

68% of CISOs identify employees as their organisation’s biggest security risk as AI amplifies human-targeted attacks.

Human RiskAIInsider Threat

Almost a quarter of CISOs identify improving resilience against AI-enabled social engineering attacks as a key focus for the next 12 months.

Social EngineeringAIResilienceHuman Risk

79% of CISOs say leadership support for security awareness initiatives fades over time.

LeadershipSecurity AwarenessHuman Risk

More than four in ten CISOs are concerned about AI increasing the speed and impact of social engineering attacks.

AISocial EngineeringThreat LandscapeHuman Risk

In the UK, more than half of CISOs identify deepfake impersonation attacks as a major threat to their organisation.

DeepfakesAIThreat LandscapeHuman Risk

40% of CISOs fear employees are sharing sensitive information with generative AI platforms.

Data SecurityGenerative AIInsider RiskHuman Risk

76% of CISOs report struggling to satisfy competing demands for human-risk metrics from different stakeholders.

Human Risk

More than three quarters of CISOs across Europe say C-level senior decision-makers do not fully understand the cyber risk posed by employees.

LeadershipHuman Risk

Nearly a quarter of CISOs identify aligning stakeholders across different functions as one of the areas where they feel least confident when managing human cyber risk.

Stakeholder AlignmentHuman Risk