It's not just technology that creates cyber risk, people do too. Yet a CISO survey by Metacompliance shows that three-quarters of executives aren't aware of this risk. The survey covered 200 CISOs from companies with at least 250 employees in France, Germany, Sweden, and the UK. Nearly half of them told Metacompliance that increasingly sophisticated AI-driven social engineering attacks were the main reason for that assessment. More than two-thirds of CISOs see their own employees as the biggest security risk to their organization, not least because AI is exploiting human weaknesses ever more skillfully.
How AI is reshaping the threat landscape
Nearly a quarter of CISOs named resilience against AI-driven social engineering attacks as one of their top priorities for the next twelve months. The biggest concerns that emerged from this: more than four in ten CISOs worry that AI makes social engineering attacks faster and more effective. 40 percent fear employees are entering sensitive information into generative AI platforms. Another 41 percent are concerned that malicious insiders could use AI for fraud, cybercrime, or data theft.
"Organizations that treat human cyber risk as an ongoing management task, rather than a recurring training event, will be best positioned going forward," says James Mackay, CEO of Metacompliance. "Employees need support exactly when they're exposed to a risk. That requires companies to use behavioral insights, intervene in a targeted way in real time, and give employees contextual guidance."
When executives leave CISOs on their own
The survey also shows that many CISOs can't automatically count on executive support. Nearly four in five report that participation in security training declines over time. At the same time, 76 percent struggle to meet the sometimes conflicting human-risk metric requirements of different stakeholders. Nearly a quarter named alignment across different business units as one of the tasks they feel least equipped to handle, an indication of how hard it is to embed a shared human risk management strategy across an entire company.
"AI has significantly increased the risks from human error. Attackers have long since moved past obvious scams or poorly written phishing emails. Today they can convincingly impersonate people, launch social engineering attacks, and fake communications at scale," Mackay explains. "This rapid development makes executive support more important than ever. Human cyber risk is no longer just a question of awareness or training, it's a strategic risk for every company. Our study shows that many CISOs still stand alone when trying to drive change. They often lack reliable backing from above, clear responsibilities, and a company-wide baseline understanding of the risks."
If executive interest fades after the initial push, organizations remain exposed. Building resilience against AI-driven threats requires sustained support within the company, better alignment among stakeholders, and a behavior-based approach to human cyber risk management.