The images in this article were generated with artificial intelligence. How we publish
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving to daily workflows. It is not just that there are more attacks; it is that the data, decisions and authorizations are now circulating on collaborative platforms, SaaS and IA assistants, and there finds the risk their new critical point. In 2025, several indicators show specific improvements compared to 2025, but the five-year trend reveals volatility and an expansion of the CISO mandate that combines identity, human behaviour, IA governance and leadership pressure.
Confirmed facts of the report: the concern for the IA clearly increased between 2024 and 2026 (54% → 60% → 78% of CISUS that consider GenAI a risk). Control of access to generative tools also increased: 78% of organizations block or limit their use in 2026 (compared to 59% in 2025). In addition, 79% of CISUS say they must manage risks linked to IA without a proportional increase in resources. In the area of "human risk," the percentage of those responsible for the increased vulnerability was 56% (2022), 60% (2023), 74% (2024), 66% (2025) and 79% (2026). The relationship with the boards of administration has been volatile: alignment reported 51% (2022), 62% (2023), 84% (2024), 64% (2025) and 85% (2026). Reports also indicate that, although the expectations of a material attack fell by 2026 over 2025, they remain above 2022 and more than half of the CISUS report material loss of information in the period.

These figures force you to stop thinking of cybersecurity as a perimeter barrier and start treating it as a government of digital work. Technically, the emergency comes from three dynamics that match: (1) SaaS proliferation and collaborative platforms that multiply data output points; (2) integration of assistants and IA agents that expand who or what can access, transform or act on information; and (3) persistence of the human factor - malice, neglect, compromised accounts or work outflows - which remains a dominant vector of data loss (the report notes that in organizations with material loss, 93% involved outgoing employees).
The mechanism is clear: identities with excessive permissions, poorly managed tokens and APIs, or automatic flows that transfer sensitive data to external models or services - sometimes without purpose records or output controls - allow for exfiltering or filtering information without a traditional edge attack. When an IA assistant moves from "responding" to "acting" (running a mail, loading a file, investing in a process), the attack surface incorporates automated decisions and third-party dependencies that need to be audited.
Practical consequences: companies face operational risks (interruptions and loss of continuity), regulatory (exposure of personal data or commercial secrets) and reputational effects that impact valuation and billing - precisely the concerns that the councils point out in their dialogue with CISUS. At the same time, the greater visibility of the ciber role increases pressure and expectations without always accompanied by resources.
What a security officer can and must do - and what a reader with an operational or managerial role can require - requires to prioritize concrete and applicable measures now. First of all, treating IA governance as a data security and decision control problem: inventory of IA integrations, classification of data that can touch models, access policies by context (what data can you see each role), registration of prompts and outputs, and exfiltration controls in the integration layer (APIs, gateways). Validation of "team network" models and tests to detect unwanted data leaks or behaviors should be part of the cycle.
In the employee's identity and life cycle: apply minimum privileges principle with periodic rights reviews, conditional access (MFA + device risk assessment), just-in-time for critical privileges and offboarding automation (revoke SSO, rotate secrets, disable tokens and remove access to SaaS). For privileged accounts, use PAM and credentials rotation with audit. These actions directly attack the main causes of data loss linked to outgoing employees or overpermits.
In technical controls and detection: deploy SaaS-oriented DLP and collaboration, CASB or SSPM that give visibility to application configurations, API gateway with data type limitation, and UEBA / analytics to detect abnormal behaviors. Integrate telemetry of IA applications and models in SIEM / SOAR to demonstrate chains of events involving attendees and automations. Where feasible, apply tokenization or masked in automatic outputs that feed external models.
In governance and report: translate technical risk to business impact for the directory (valuation, downtime, customer loss), set control metrics focused on "where the work occurs" (for example, percentage of sensitive repositories with active DLP protection, rate of revised privileges completed, coverage of prompts records). And accept the evidence from the report: If 79% of CISUS manage IA without additional resources, the immediate step is to ask for and justify risk mapping and ROI-based investment from critical workflow mitigation.

What is safe to say and what is uncertain: it is confirmed that IA and human risk have increased in importance in recent years and that IA governance and identity management are critical points. It is a reasonable interpretation - supported by this series - to say that the "centre of gravity" of the risk has moved towards daily work interactions; however, the exact pace at which specific controls (for example, block lists against allowing contextual access) will reduce losses in different types of organizations remains uncertain. Nor is it certain how the specific regulations on IA and liability will evolve - that combination will condition priorities and costs.
If you want to deepen frameworks and practical guides to govern IA and zero-confidence architecture, see resources such as the NIST initiative on risk management of IA ( NIST TO RMF) and patterns of zero-confidence architecture ( NIST SP 800-207). For the context of the above-mentioned study and trend comparison, you can review the supplier's website that published the survey series ( Proofpoint).
In short, the immediate priority is not just "preventing the next intrusion," but redesigning controls and reports to protect the way we work today: identities, data and smart agents. That is the lever that reduces real exposure; asking for resources to open that lever is, according to the data, the next conversation that CISUS should bring to the executive committee and to the council.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...

Denmark confirms unauthorized access to the RCP that affected 8.8 million records
The Danish government confirmed that for about ten days in September there were unauthorized access to the Central Peru Register (CPR) the national population database. Accordin...