Bottom line: While AI-powered attackers refine social engineering methods, CISOs lose management support for employee security and must meet conflicting stakeholder expectations.
A survey of 200 European CISOs shows: 79 percent report declining management engagement for security awareness, while at the same time AI-driven social engineering attacks are increasing. Security leaders find themselves increasingly isolated.
The MetaCompliance survey covered 200 CISOs from the United Kingdom, France, Germany, and Sweden. It reveals a significant security trend: attacks are increasingly targeting people rather than system vulnerabilities. Almost half of CISOs who rate their company’s cyber resilience as worse than the previous year attribute this to AI-driven social engineering methods. Overall, 68 percent identify their workforce as the greatest vulnerability.
CISOs’ specific concerns center on three key areas: Over 40 percent see AI as a driver for faster and more accurate social engineering attacks. 40 percent report that employees enter confidential data into public AI tools. 41 percent warn of insider threats using AI for fraud or data theft. A country comparison additionally shows: In the United Kingdom, more than one in two CISOs consider deepfakes for identity fraud as a serious threat – the highest proportion among the four countries surveyed.
At the same time, the conditions for effective countermeasures are eroding. 79 percent of CISOs report that executive engagement for security awareness is declining. 76 percent struggle to meet conflicting stakeholder expectations for human risk management metrics. Nearly a quarter cite cross-functional alignment as their own weakness – a sign of how difficult it is to enforce a unified security strategy across department boundaries.
The study authors recommend transitioning security awareness from the status of a one-time training project into a continuous management responsibility. Nearly a quarter of surveyed CISOs already list strengthening defenses against AI-driven social engineering among their top priorities for the coming twelve months. However, without company-wide understanding of the risk and reliable support from above, CISOs cannot manage this transformation alone.
Source: www.it-daily.net · Published 14 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.