惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
J
Java Code Geeks
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
MyScale Blog
MyScale Blog
G
Google Developers Blog
Microsoft Azure Blog
Microsoft Azure Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
Google DeepMind News
Google DeepMind News
Engineering at Meta
Engineering at Meta
The Cloudflare Blog
Martin Fowler
Martin Fowler
酷 壳 – CoolShell
酷 壳 – CoolShell
N
Netflix TechBlog - Medium
MongoDB | Blog
MongoDB | Blog
I
InfoQ
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Help Net Security

Latest from TechRadar in Security

Robots are fighting wars and helping to quash riots — China is arming riot police with squads of AI controlled drones and Ukraine wants to man the frontlines with 25,000 robots US security agency still using Mythos despite ban – government using new security tool despite Pentagon's… Struggling to launch Teams? Microsoft recalls update causing failed startup and infinite loading loops –… How to meaningfully measure the effectiveness of cyber resilience 'We've identified a security incident': Vercel breach confirmed after hackers claim stolen data for sale… How EU organizations can turn sovereign cloud theory into action 'Update immediately': 60,000 WordPress websites at risk after experts discover flaw that allows hackers to… 'They mopped the floor with me and pulled every childish game they could': Disgruntled researcher releases second major Windows zero-day — claims Microsoft 'would ruin my life, and they did' 'As threats evolve, Gemini keeps our defenses one step ahead': Google claims its AI helped it block over 8.3… Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe Solving the shadow IT crisis in travel Agentic swarms will change how everyone uses AI – but how can organizations deploy them securely? Europol launches Operation PowerOFF — warns 75,000 DDoS users and takes down 53 domains China completes testing on ‘deep-sea electro-hydrostatic actuator’ capable of slicing undersea cables as deep as 3.5 kilometers – new compact subsea vessel testing bridges the ‘last mile’ and could deploy in 2026 Many are still leaving the door open': Security experts warn FIFA World Cup partners could be putting customers at… 'Anyone with $10 could have walked straight through': Report warns this legit-looking software is actually… An ancient Microsoft Excel security flaw could let hackers hijack your entire system, so patch now 'This is not a traditional coding error': Experts flag potentially critical security issues at the heart of Anthropic's MCP, exposes 150 million downloads and thousands of servers to complete takeover Your OpenClaw agents can empty your inbox and leak your data. Here's how to secure them Russia hits European thermal power plant in attempted ‘destructive’ cyberattack – Pro-Kremlin hackers are engaging in ‘riskier and more reckless behavior’ in latest attempt to cripple Western critical infrastructure The war in Iran is reaching cyberspace - here’s how to prepare Millions of hotel goers may have been exposed after hackers steal data and leak it on Telegram 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… Dozens of WordPress plugins hijacked to target thousands of sites 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… McGraw Hill becomes latest to see its Salesforce data hacked Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts OpenAI reveals its Mythos rival designed for cybersecurity pros When cyberattacks are inevitable, recovery becomes the strategy
Gartner: GenAI has broken traditional cybersecurity aware...
Alex Michael · 2026-05-11 · via Latest from TechRadar in Security

Cybersecurity awareness has long relied on a simple premise: educate employees, reduce risk. But in 2026, that model is no longer holding.

Director Analyst at Gartner.

This highlights the gap between traditional awareness programs and modern cyber risk.

For security and risk management leaders, awareness alone is no longer enough.

The human risk surface is expanding

GenAI adoption has surged across organizations, with more than 86% now piloting or deploying these tools. What began as experimentation has quickly become embedded in day-to-day workflows, often without corresponding governance or oversight.

Employees are not waiting for formal approval. Many are turning to personal GenAI accounts for work tasks, inputting sensitive data into public tools, or downloading unapproved applications. This phenomenon, often described as “shadow AI,” is increasing employee-initiated cybersecurity risk.

According to Gartner’s 2025 Cybersecurity Innovations in AI Risk Management and Use Survey, over 57% of employees use personal GenAI accounts for work, and 33% admit to inputting sensitive work information into public or unapproved GenAI tools.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

External threats are evolving as well. Deepfakes and advanced phishing attacks are becoming more sophisticated due to GenAI capabilities. The survey finds 35% of organizations have been affected by deepfake attacks, and AI-assisted phishing emails have doubled over the past two years, making some threats harder for employees to detect.

This creates a dual challenge: organizations are exposed both internally, through unmanaged AI use, and externally, through AI-augmented attacks.

Why traditional awareness programs are failing

Most cybersecurity awareness programs were built for a different era. They focus on static training, periodic campaigns, and generic guidance such as “don’t click suspicious links”.

But GenAI changes the rules.

First, it reduces the visibility of threats. AI-generated content is often indistinguishable from legitimate communications, making it far harder for employees to rely on traditional cues.

Second, it increases the speed and scale of attacks. What once required time and effort can now be automated and personalized at volume.

Third, it introduces entirely new risk behaviors. Prompt injections, insecure use of AI tools, and the inadvertent sharing of sensitive data through GenAI platforms are not covered by legacy training models.

The outcome is clear: despite continued investment in awareness, human-related risk exposure is not decreasing.

From awareness to behavior: a necessary shift

Cybersecurity leaders must focus on security behavior and culture programs (SBCPs), which emphasize how employees act in real-world scenarios rather than only what they know.

SBCPs aim to drive secure GenAI-related work practices, recognizing that employees will make judgement calls and use AI tools. The goal is not to eliminate these behaviors, but to shape them safely.

In practice, this means embedding security into daily workflows rather than treating it as a periodic intervention. Training evolves from generic modules to simulations that replicate AI-driven attacks, including deepfakes and advanced phishing.

Policies become clear and actionable, covering GenAI usage, data handling, and prompt design. Reporting mechanisms are streamlined to encourage faster escalation of suspicious activity.

Behavior change requires reinforcement. One-off training sessions are replaced by continuous engagement, microlearning, and real-time feedback.

Securing human interaction with AI

As GenAI becomes embedded across business processes, securing the interaction between people and AI systems becomes a critical control point.

This introduces new priorities for security and risk management leaders.

First, organizations must establish clear boundaries for GenAI use. This includes defining approved tools, setting data classification rules, and ensuring employees understand the risks of sharing sensitive information.

Second, governance must extend beyond IT. GenAI risk intersects with legal, compliance, data protection and executive decision-making. Without senior leadership involvement, efforts to manage these risks will remain fragmented.

Third, organizations must invest in AI literacy. Employees need to understand not only how to use GenAI tools, but how those tools can be manipulated. This includes recognizing hallucinations, validating outputs, and maintaining human oversight.

Finally, security teams must tactfully accept a degree of operational friction. Slowing down to verify an unusual request or validate an AI-generated output is no longer inefficiency, it is resilience.

A cultural, not technical, inflection point

There is a temptation to view GenAI-related cyber risk as a technical problem that can be solved with better tools, more controls, or stricter policies.

But the evidence suggests otherwise.

Overreliance on technical controls does little to address the behavioral drivers of risk. Employees will continue to find workarounds if security measures are perceived as barriers to productivity. Meanwhile, attackers will continue to exploit human trust, curiosity and urgency.

What is required is a cultural shift.

Security must be reframed as an enabler of safe AI adoption, empowering employees to act responsibly and report suspicious activity. The aim is not to eliminate all risk but to build an environment where secure behavior is the default.

What comes next

GenAI is a foundational shift in organizational operations and cyber threats. Cybersecurity awareness programs must evolve to focus on behavior, embed security into daily practices, and treat human risk as dynamic and continuously managed.

In an AI-driven world, security and risk management leaders must remember that risk is defined less by knowledge and more by how employees behave in the moments that matter.

We've featured the best encryption software.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit