惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
Microsoft Azure Blog
Microsoft Azure Blog
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
博客园_首页
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
小众软件
小众软件
F
Fortinet All Blogs
Microsoft Security Blog
Microsoft Security Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
宝玉的分享
宝玉的分享
有赞技术团队
有赞技术团队
J
Java Code Geeks
WordPress大学
WordPress大学
The Cloudflare Blog

Latest from TechRadar

Quordle hints and answers for Monday, April 13 (game #1540) NYT Strands hints and answers for Monday, April 13 (game #771) NYT Connections hints and answers for Monday, April 13 (game #1037) Morbid Metal developer explains why he ditched an origami art direction in favor of gritty sci-fi — 'It worked, but it didn't really feel like me' '71% of US households get routers from ISPs': Why new FCC rules could leave millions stuck with outdated,… 'The CPU is the system’s executive layer': Intel joins SambaNova as both face existential threat from… ‘More bang for your buck’: 7 easy ways to boost your MacBook Neo’s performance for free DJI Romo P vs Roborock Saros 10R — which robot vacuum comes out on top when it comes to dodging obstacles? I put… I spent 6 hours with Genshin Impact on the Galaxy S26 Ultra, and I can't believe how far mobile gaming has come What is the release date for The Testaments episode 4 on Hulu and Disney+? I reviewed the LG G6 for 3 weeks, and it's a fantastic OLED TV that's the new best option for brighter rooms Is your bird feeder camera doing more harm than good? 3 tips for using it safely as RSPB issues urgent disease warning Chelsea vs Man City Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news How to watch Alcaraz vs Sinner for FREE: TV Channels for Monte-Carlo Masters Final Sunderland vs Tottenham Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news Are these the best-designed workout headphones ever? I used them for a month to find out How to watch Snooker 900 John Virgo online (it's free) – stream O'Sullivan vs Higgins anywhere I've only just discovered the Walk With Frodo app on Garmin's Connect IQ store — and as as a huge LOTR nerd, it's going to make the next 1,800 miles fly by 'Just not sustainable': Why your monthly £25 broadband internet bill could soon hit £45 How to watch Paris-Roubaix 2026: Free Streams & TV Info as Tadej Pogacar chases third Monument How to watch Euphoria season 3 online – stream Zendaya & Sydney Sweeney drama from anywhere today '$15K bill destroyed a solo developer’s startup': How hackers are using leaked Google API keys to… There's a sneaky way to watch UFC 327 really cheap... NYT Connections hints and answers for Sunday, April 12 (game #1036) NYT Strands hints and answers for Sunday, April 12 (game #770) Quordle hints and answers for Sunday, April 12 (game #1539) Amazon's Ring cameras are the perfect solution to secure your home on a budget — shop today's best deals… I've tested every iPhone since the iPhone 12, and Ceramic Shield 2 is the first iPhone glass I fully trust UFC 327 live stream: how to watch Procházka vs Ulberg, start time, preview, full card We're officially getting the DJI Pocket 4 on April 16, but here's how Insta360 could beat it
Gartner: GenAI has broken traditional cybersecurity aware...
Alex Michael · 2026-05-11 · via Latest from TechRadar

Cybersecurity awareness has long relied on a simple premise: educate employees, reduce risk. But in 2026, that model is no longer holding.

Director Analyst at Gartner.

This highlights the gap between traditional awareness programs and modern cyber risk.

For security and risk management leaders, awareness alone is no longer enough.

The human risk surface is expanding

GenAI adoption has surged across organizations, with more than 86% now piloting or deploying these tools. What began as experimentation has quickly become embedded in day-to-day workflows, often without corresponding governance or oversight.

Employees are not waiting for formal approval. Many are turning to personal GenAI accounts for work tasks, inputting sensitive data into public tools, or downloading unapproved applications. This phenomenon, often described as “shadow AI,” is increasing employee-initiated cybersecurity risk.

According to Gartner’s 2025 Cybersecurity Innovations in AI Risk Management and Use Survey, over 57% of employees use personal GenAI accounts for work, and 33% admit to inputting sensitive work information into public or unapproved GenAI tools.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

External threats are evolving as well. Deepfakes and advanced phishing attacks are becoming more sophisticated due to GenAI capabilities. The survey finds 35% of organizations have been affected by deepfake attacks, and AI-assisted phishing emails have doubled over the past two years, making some threats harder for employees to detect.

This creates a dual challenge: organizations are exposed both internally, through unmanaged AI use, and externally, through AI-augmented attacks.

Why traditional awareness programs are failing

Most cybersecurity awareness programs were built for a different era. They focus on static training, periodic campaigns, and generic guidance such as “don’t click suspicious links”.

But GenAI changes the rules.

First, it reduces the visibility of threats. AI-generated content is often indistinguishable from legitimate communications, making it far harder for employees to rely on traditional cues.

Second, it increases the speed and scale of attacks. What once required time and effort can now be automated and personalized at volume.

Third, it introduces entirely new risk behaviors. Prompt injections, insecure use of AI tools, and the inadvertent sharing of sensitive data through GenAI platforms are not covered by legacy training models.

The outcome is clear: despite continued investment in awareness, human-related risk exposure is not decreasing.

From awareness to behavior: a necessary shift

Cybersecurity leaders must focus on security behavior and culture programs (SBCPs), which emphasize how employees act in real-world scenarios rather than only what they know.

SBCPs aim to drive secure GenAI-related work practices, recognizing that employees will make judgement calls and use AI tools. The goal is not to eliminate these behaviors, but to shape them safely.

In practice, this means embedding security into daily workflows rather than treating it as a periodic intervention. Training evolves from generic modules to simulations that replicate AI-driven attacks, including deepfakes and advanced phishing.

Policies become clear and actionable, covering GenAI usage, data handling, and prompt design. Reporting mechanisms are streamlined to encourage faster escalation of suspicious activity.

Behavior change requires reinforcement. One-off training sessions are replaced by continuous engagement, microlearning, and real-time feedback.

Securing human interaction with AI

As GenAI becomes embedded across business processes, securing the interaction between people and AI systems becomes a critical control point.

This introduces new priorities for security and risk management leaders.

First, organizations must establish clear boundaries for GenAI use. This includes defining approved tools, setting data classification rules, and ensuring employees understand the risks of sharing sensitive information.

Second, governance must extend beyond IT. GenAI risk intersects with legal, compliance, data protection and executive decision-making. Without senior leadership involvement, efforts to manage these risks will remain fragmented.

Third, organizations must invest in AI literacy. Employees need to understand not only how to use GenAI tools, but how those tools can be manipulated. This includes recognizing hallucinations, validating outputs, and maintaining human oversight.

Finally, security teams must tactfully accept a degree of operational friction. Slowing down to verify an unusual request or validate an AI-generated output is no longer inefficiency, it is resilience.

A cultural, not technical, inflection point

There is a temptation to view GenAI-related cyber risk as a technical problem that can be solved with better tools, more controls, or stricter policies.

But the evidence suggests otherwise.

Overreliance on technical controls does little to address the behavioral drivers of risk. Employees will continue to find workarounds if security measures are perceived as barriers to productivity. Meanwhile, attackers will continue to exploit human trust, curiosity and urgency.

What is required is a cultural shift.

Security must be reframed as an enabler of safe AI adoption, empowering employees to act responsibly and report suspicious activity. The aim is not to eliminate all risk but to build an environment where secure behavior is the default.

What comes next

GenAI is a foundational shift in organizational operations and cyber threats. Cybersecurity awareness programs must evolve to focus on behavior, embed security into daily practices, and treat human risk as dynamic and continuously managed.

In an AI-driven world, security and risk management leaders must remember that risk is defined less by knowledge and more by how employees behave in the moments that matter.

We've featured the best encryption software.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit