Over the past year, the cybersecurity conversation has changed. For several years, CISOs have been leading a landscape in which every major threat seemed to be rising at once. This year’s findings suggest a more nuanced picture. Fewer security leaders expect their organization to experience a material cyberattack in the next 12 months, and fewer report material loss of sensitive information than in 2025.
That progress is encouraging. It shows that investments in security controls, governance, and response are making a difference. But it should not be mistaken for a simpler operating environment. Cyber risk is not disappearing; it is moving deeper into the systems, identities, and workflows that power modern work.
AI sits at the center of that shift. As assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied upon to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role.

