The 2026 Voice of the CISO findings highlight a significant shift in the cybersecurity landscape. Instead of a linear escalation of external threats, cyber risk is now converging within the systems where work is performed, encompassing resilience, AI governance, and human risk.
This marks a departure from previous years where the narrative focused primarily on increasing attacks and data loss. While these concerns persist, the core challenge for CISOs has evolved due to the relocation of risk closer to operational workflows.
The 2026 report shows some positive developments, with fewer CISOs anticipating a material cyberattack in the next 12 months and a decrease in reported material loss of sensitive information compared to 2025. However, these improvements are part of a broader, less stable trend over five years.
Over this period, attack expectations have fluctuated, board alignment has varied, and human risk has remained a consistent concern. AI has also transitioned from an emerging issue to a defining mandate for security leaders.
The shift in risk location necessitates a change in how security leaders optimize their strategies. The primary question for CISOs is no longer just about identifying the next external threat.
Instead, the focus is now on understanding where critical work occurs, who or what has access to it, and how to protect sensitive data as it moves across various elements like people, cloud platforms, collaboration tools, SaaS applications, and AI-enabled workflows.
A five-year perspective reveals that the cybersecurity profession has absorbed multiple waves of change rather than following a smooth maturity curve. While attack expectations cooled in 2026, they remain higher than in 2022. Reported data loss decreased year-over-year, but over half of CISOs still report material loss.
Board alignment has rebounded to its highest level, yet excessive expectations from boards have also risen concurrently. These trends indicate that the security function is gaining visibility and support while simultaneously facing increased demands.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The 2026 Voice of the CISO report indicates a shift in cyber risk, moving closer to daily workflows, AI governance, and human risk factors. This change requires security leaders to focus on protecting sensitive data within people, cloud platforms, collaboration tools, SaaS applications, and AI-enabled workflows, rather than solely on external threats.