Key Findings
85% of UK CISOs believe cybersecurity expertise should be required at the board-director level, up from 63% in 2025.
72% of UK CISOs report that their organisations block or restrict employee GenAI use.
62% of UK organisations experience material data loss, down from 74% in 2025.
69% of UK CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 60% in 2025.
61% of UK CISOs say their organisation is unprepared to cope with a targeted cyberattack.
Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.
95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.
Among UK organisations that experienced material data loss, regulatory sanctions rose to 35% from 30% in 2025.
Among UK organisations that experienced material data loss, financial losses increased to 40% from 24% in 2025.
Among UK organisations that experienced material data loss, post-attack recovery costs rose to 36% from 26% in 2025.
Among UK organisations that experienced material data loss, reputational damage increased to 45% from 36% in 2025.
87% of UK CISOs believe their controls effectively mitigate risks introduced by AI, SaaS, and modern work patterns.
66% of UK CISOs believe employees are likely to use AI in ways that could expose sensitive data.
71% of UK CISOs are concerned about customer data loss through public GenAI tools.
71% of UK CISOs view GenAI as a security risk, a 13 percentage-point increase year-over-year.
74% of UK CISOs say excessive expectations are placed on them.
87% of UK CISOs say they see eye-to-eye with their boards on cybersecurity, up from 57% in 2025.
74% of UK CISOs believe their organisation is at risk of a material cyberattack in the next 12 months, up from 63% in 2025.
72% of UK CISOs expect to manage AI-related risks without a proportional increase in resources or expertise in the next two years.
UK CISOs identify the following technologies as top concerns: SaaS applications and third-party integrations (33%), Collaboration platforms (32%), Active Directory/Identity infrastructure (32%), Perimeter network devices (32%), and AI assistants/copilots/autonomous agents (30%).
80% of UK CISOs say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years.