CISOs Are Losing Confidence in Their Defenses: 72% Say Threats Are Now Critical
Security leaders are sounding the alarm: nearly three-quarters of chief information security officers (CISOs) and senior technology leaders now describe the cybersecurity threats facing their organizations as "critical" or "very critical," according to a new global survey. The findings paint a picture of an industry struggling to keep pace with rapidly evolving threats, even as organizations invest heavily in AI-powered defenses.
The CISO Outlook 2026 report surveyed 300 senior technology and cybersecurity executives across North America, Europe, and the Asia-Pacific region in early 2026. The research reveals a troubling gap: while organizations increasingly rely on artificial intelligence (AI) to strengthen monitoring, detection, and threat response, cybercriminals are simultaneously using AI to launch more sophisticated attacks, impersonation schemes, and domain-based threats. The result is an escalating arms race that's leaving many security leaders feeling outgunned.
What Are the Top Threats Security Leaders Fear Most?
When asked to identify their greatest cybersecurity concerns, CISOs and technology leaders pointed to a specific category of attacks that may surprise many organizations: domain and domain name system (DNS) hijacking and subdomain takeover attacks ranked as the top cyber threat. These attacks involve criminals taking control of a company's domain or DNS records, allowing them to redirect traffic, steal data, or launch further attacks from what appears to be a trusted source.
Beyond domain-based threats, the survey identified several other critical concerns facing organizations today:
- Ransomware: Attacks that encrypt an organization's data and demand payment for its release, disrupting operations and threatening sensitive information.
- Social media impersonation: Criminals creating fake accounts or hijacking legitimate ones to deceive customers, employees, or partners.
- Deepfake-related fraud: AI-generated audio, video, or images used to impersonate executives or employees for financial gain or data theft.
- Cybersquatting: Registering domain names similar to legitimate ones to trick users or capture traffic intended for the real organization.
The threat landscape is expanding faster than defenses can adapt. Almost nine in 10 senior C-level executives, or 89%, expect cybersecurity incidents to increase over the next 12 months, suggesting that current security measures may prove insufficient in the year ahead.
Why Are CISOs Skeptical About AI Security Solutions?
Paradoxically, even as organizations deploy AI to defend against threats, security leaders express deep concerns about the technology itself. Nearly all CISOs and senior technology leaders, or 98%, express concern about giving third-party AI systems access to company data. This hesitation reflects a fundamental trust issue: organizations worry that AI tools designed to protect them could become a liability if the AI vendor is breached, the data is misused, or the system is compromised.
The concern extends to AI-powered domain generation algorithms (DGAs), which are tools that automatically create large numbers of domain names. Criminals use DGAs to generate thousands of malicious domains quickly, making it nearly impossible for security teams to block them all. A striking 86% of organizations surveyed view AI-powered DGAs as a cybersecurity threat, underscoring how AI itself has become a weapon in the attacker's arsenal.
Despite these concerns, nearly three-quarters of organizations, or 72%, acknowledge that AI-driven automation plays a protective role in defending against DNS and similar attacks. However, this protection comes with a caveat: it requires oversight or careful management. In other words, security leaders believe AI can help defend their networks, but only if they maintain tight control over how it's deployed and what data it accesses.
How to Strengthen Your Organization's Cybersecurity Posture
Given the escalating threat landscape, security leaders are taking steps to improve their defenses. Based on the survey findings, organizations are focusing on several key areas:
- Supply chain risk controls: Seven in 10 organizations apply cybersecurity risk controls only to key suppliers, meaning many third-party vendors remain inadequately vetted. Expanding these controls to all vendors and regularly auditing their security practices can reduce the risk of breaches originating from trusted partners.
- DNS resilience strategies: Only 14% of CISOs and senior technology leaders say they are "very confident" in their organization's ability to mitigate domain attacks, indicating a critical gap in DNS protection. Organizations should invest in DNS monitoring, redundancy, and threat detection to reduce vulnerability to hijacking and takeover attacks.
- Regulatory compliance alignment: Just 15% of organizations report full compliance with all NIS2 requirements, the European Union's updated cybersecurity directive. Conducting a compliance audit and implementing missing controls can reduce regulatory risk and improve overall security posture.
- AI governance frameworks: Establishing clear policies for how AI systems are deployed, what data they can access, and how they are monitored can help organizations realize the benefits of AI-driven security while limiting exposure to data breaches or misuse.
The gap between threat severity and organizational confidence is stark. While 72% of CISOs describe threats as critical or very critical, only 14% express high confidence in their ability to stop domain attacks, the top threat identified in the survey. This confidence gap suggests that many organizations recognize the danger but lack the tools, expertise, or resources to effectively defend against it.
The CISO Outlook 2026 report underscores a fundamental challenge facing the cybersecurity industry: as threats grow more sophisticated and AI-powered, organizations must balance the need for advanced defenses with legitimate concerns about data privacy, vendor security, and regulatory compliance. The result is a security landscape where leaders feel increasingly pressured to act, but uncertain about the best path forward.