Bottom line: Over 75 percent of European CISOs report that their executives underestimate cyber risks from employee errors, while AI-driven attacks increasingly exploit these vulnerabilities with precision.
A European survey shows: Over 75 percent of CISOs see their executive management insufficiently informed about cyber risks arising from human error. At the same time, AI-driven attacks are increasingly exploiting human vulnerabilities with growing sophistication.
According to a survey among security leaders in Europe, the majority of executive boards lack adequate understanding of the cyber risks arising from employee mistakes and negligence. More than three-quarters of the surveyed CISOs indicated that this risk perception among management is incomplete or fragmented.
For CISOs, the problem is exacerbated by the increasing automation of attacks: cyber criminals are using artificial intelligence to exploit human vulnerabilities more precisely, convincingly, and at scale. Phishing campaigns, pretexting, and social engineering benefit from the lowering of technological barriers and increasing psychological effectiveness. This development makes the human factor a strategic risk that can no longer be managed through training alone.
The disconnect between CISO perception and management awareness has immediate consequences: budgets for awareness programs and technical controls in the user domain are often treated as a cost factor rather than an essential protective measure. As a result, many organizations lack the speed and depth to keep pace with current attack levels, let alone confront emerging threats posed by AI-driven attacks.
Source: itwelt.at · Published 14 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.