Report by Mimecast

The State of Human Risk 2026

14 FINDINGSPublished Mar 4, 2026
View Original Report →

Key Findings

36% of organizations still relying on manual monitoring of communications data.

Manual Monitoring

Only 40% of respondents have specific strategies to counter AI-driven attacks.

AI-Driven AttacksResilience

Just over half of organizations now use AI for threat detection and real-time monitoring, up from 46% the prior year.

AI Use CaseThreat DetectionReal Time Monitoring

96% of organizations admit they have incomplete protection against human risk.

Human Risk

Organizations that succeed in integrating cybersecurity tools report 40% faster threat remediation and far more comprehensive visibility.

Cybersecurity ToolsTool IntegrationTool SprawlRemediationVisibility

48% of organizations are investing in AI-powered monitoring tools.

AI-Powered Monitoring ToolAI Use Case

59% of respondents lack confidence they can quickly locate communications data for regulatory or legal requirements.

Regulatory RiskLegalVisibility

23% of organizations manage policies manually.

Policy Management

69% of respondents see AI-driven attacks as inevitable within 12 months.

AI-Driven Attacks

65% of organizations find integrating cybersecurity tools too complicated.

Cybersecurity ToolsTool IntegrationTool Sprawl

71% of respondents expect negative business impact from attacks via Slack, Teams, Zoom, and similar platforms in 2026.

Communication Platform AttacksSlackTeamsZoomResilience

91% of organizations face obstacles ensuring employee compliance.

Human RiskEmployee Compliance

44% of organizations are training employees to recognize AI-driven exploitation.

AI-Driven ExploitationEmployee Training

41% of organizations have created specific AI usage policies.

AI Usage Policies