CISO Research Shows Cyber Risk Has Moved Into Everyday Work Tools
The 2026 Voice of the CISO findings show some progress. Fewer chief information security officers (CISOs) expect a material cyberattack in the next 12 months, and fewer report a material loss of sensitive information than in 2025. But the research, covered by The Hacker News, argues that these gains should be read against a much less settled five-year trend.
Over that period, expectations of attack have risen, fallen and risen again. Board alignment has swung sharply, and human risk has remained a central concern. AI has moved from an emerging worry to a defining part of the CISO mandate. The source suggests the story is not simply one of improvement or decline. Instead, risk is changing location and moving closer to the way work now gets done.
This changes the questions security leaders should ask. Rather than only wondering what threat will strike next, they are being pushed to ask where critical work happens, who or what has access to it, and whether sensitive data can be protected as it moves across people, cloud platforms, collaboration tools, software-as-a-service (SaaS) applications and AI-enabled workflows. The five-year view shows a profession absorbing wave after wave of change rather than following a smooth path to maturity.
This summary is based on the opening of the article only, so it does not cover the full research findings.