惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
Recent Announcements
Recent Announcements
B
Blog
D
Docker
V
V2EX
GbyAI
GbyAI
L
LangChain Blog
博客园 - Franky
U
Unit 42
T
The Blog of Author Tim Ferriss
A
About on SuperTechFans
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Vercel News
Vercel News
博客园_首页
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
Y
Y Combinator Blog
量子位
Blog — PlanetScale
Blog — PlanetScale
罗磊的独立博客

Latest from TechRadar in Pro

VodafoneThree gets Ofcom approval to bring satellite connectivity to your smartphone Is this the tipping point for AI at work? New Gallup survey finds half of all US employees now use it in some way 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… 'Makes it even more disappointing': Microsoft backs fossil fuel big time with $7 billion deal in race for AI… 'Maybe it’s not science fiction': Solar panels are causing rainwater to fall in one of the driest places… Maine becomes first US state to pass data centre construction ban Dozens of WordPress plugins hijacked to target thousands of sites Drone-killing laser weapons greenlit for use in US airspace – FAA and Defense Department say high-energy weapons are ‘ready to protect all air travelers from illicit drone use’ despite airspace restrictions and friendly-fire incidents 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… I tried 7 free MTD software – now I've ranked my top picks as a freelancer Jackery McGraw Hill becomes latest to see its Salesforce data hacked Looking for a new PC? Now might be great time to upgrade, as Gartner figures claim shipments are rising — while… The new engineering playbook: how AI design copilots are reshaping product development Farewell Surface Hub — Microsoft kills off its super-sized touchscreen displays, but you might still be able to get one if you act fast 'We have no interest in patient data in the UK': Palantir UK head defends record as criticisms rise Amazon’s new AI Bio Discovery tool can provide ‘every researcher’ with ‘lab-in-the-loop drug discovery’ – 40+ AI biology models can filter 300,000 novel antibody candidates down to the top results for testing in just weeks Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts Europe wants tech sovereignty but is this realistic? Enterprise AI governance cannot live in a prompt. So where is the safety net? Why 2026 is the year of flexibility without friction: solving the multi-platform crisis OpenAI reveals its Mythos rival designed for cybersecurity pros When cyberattacks are inevitable, recovery becomes the strategy Closing the cloud complexity gap LaLiga uses AI to fight illegal streaming that costs its clubs $800m a year Intel and Google expand long-term chip partnership to power AI systems 'Chatbots respond not just to what you ask, but how you ask it': Report finds AI agents might be sucking up to… 'Smartphones have physical limitations': Report explains why AI is kickstarting a billion-dollar hardware arms… 'I’m pretty sure actually we really do not need to work for five days' Zoom CEO calls for end of traditional work schedules — says 3-day working week should become the norm 'It's more common than you think': Experts reveal how hackers are trying to hijack your inbox with these…
Gartner: GenAI has broken traditional cybersecurity aware...
Alex Michael · 2026-05-11 · via Latest from TechRadar in Pro

Cybersecurity awareness has long relied on a simple premise: educate employees, reduce risk. But in 2026, that model is no longer holding.

Director Analyst at Gartner.

This highlights the gap between traditional awareness programs and modern cyber risk.

For security and risk management leaders, awareness alone is no longer enough.

The human risk surface is expanding

GenAI adoption has surged across organizations, with more than 86% now piloting or deploying these tools. What began as experimentation has quickly become embedded in day-to-day workflows, often without corresponding governance or oversight.

Employees are not waiting for formal approval. Many are turning to personal GenAI accounts for work tasks, inputting sensitive data into public tools, or downloading unapproved applications. This phenomenon, often described as “shadow AI,” is increasing employee-initiated cybersecurity risk.

According to Gartner’s 2025 Cybersecurity Innovations in AI Risk Management and Use Survey, over 57% of employees use personal GenAI accounts for work, and 33% admit to inputting sensitive work information into public or unapproved GenAI tools.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

External threats are evolving as well. Deepfakes and advanced phishing attacks are becoming more sophisticated due to GenAI capabilities. The survey finds 35% of organizations have been affected by deepfake attacks, and AI-assisted phishing emails have doubled over the past two years, making some threats harder for employees to detect.

This creates a dual challenge: organizations are exposed both internally, through unmanaged AI use, and externally, through AI-augmented attacks.

Why traditional awareness programs are failing

Most cybersecurity awareness programs were built for a different era. They focus on static training, periodic campaigns, and generic guidance such as “don’t click suspicious links”.

But GenAI changes the rules.

First, it reduces the visibility of threats. AI-generated content is often indistinguishable from legitimate communications, making it far harder for employees to rely on traditional cues.

Second, it increases the speed and scale of attacks. What once required time and effort can now be automated and personalized at volume.

Third, it introduces entirely new risk behaviors. Prompt injections, insecure use of AI tools, and the inadvertent sharing of sensitive data through GenAI platforms are not covered by legacy training models.

The outcome is clear: despite continued investment in awareness, human-related risk exposure is not decreasing.

From awareness to behavior: a necessary shift

Cybersecurity leaders must focus on security behavior and culture programs (SBCPs), which emphasize how employees act in real-world scenarios rather than only what they know.

SBCPs aim to drive secure GenAI-related work practices, recognizing that employees will make judgement calls and use AI tools. The goal is not to eliminate these behaviors, but to shape them safely.

In practice, this means embedding security into daily workflows rather than treating it as a periodic intervention. Training evolves from generic modules to simulations that replicate AI-driven attacks, including deepfakes and advanced phishing.

Policies become clear and actionable, covering GenAI usage, data handling, and prompt design. Reporting mechanisms are streamlined to encourage faster escalation of suspicious activity.

Behavior change requires reinforcement. One-off training sessions are replaced by continuous engagement, microlearning, and real-time feedback.

Securing human interaction with AI

As GenAI becomes embedded across business processes, securing the interaction between people and AI systems becomes a critical control point.

This introduces new priorities for security and risk management leaders.

First, organizations must establish clear boundaries for GenAI use. This includes defining approved tools, setting data classification rules, and ensuring employees understand the risks of sharing sensitive information.

Second, governance must extend beyond IT. GenAI risk intersects with legal, compliance, data protection and executive decision-making. Without senior leadership involvement, efforts to manage these risks will remain fragmented.

Third, organizations must invest in AI literacy. Employees need to understand not only how to use GenAI tools, but how those tools can be manipulated. This includes recognizing hallucinations, validating outputs, and maintaining human oversight.

Finally, security teams must tactfully accept a degree of operational friction. Slowing down to verify an unusual request or validate an AI-generated output is no longer inefficiency, it is resilience.

A cultural, not technical, inflection point

There is a temptation to view GenAI-related cyber risk as a technical problem that can be solved with better tools, more controls, or stricter policies.

But the evidence suggests otherwise.

Overreliance on technical controls does little to address the behavioral drivers of risk. Employees will continue to find workarounds if security measures are perceived as barriers to productivity. Meanwhile, attackers will continue to exploit human trust, curiosity and urgency.

What is required is a cultural shift.

Security must be reframed as an enabler of safe AI adoption, empowering employees to act responsibly and report suspicious activity. The aim is not to eliminate all risk but to build an environment where secure behavior is the default.

What comes next

GenAI is a foundational shift in organizational operations and cyber threats. Cybersecurity awareness programs must evolve to focus on behavior, embed security into daily practices, and treat human risk as dynamic and continuously managed.

In an AI-driven world, security and risk management leaders must remember that risk is defined less by knowledge and more by how employees behave in the moments that matter.

We've featured the best encryption software.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit