New research from CoreView, a company that specialises in Microsoft 365 tenant resilience, reveals that more than half of large organizations (51%) have reversed AI-driven changes within Microsoft 365 due to security or governance concerns.
Research
A library of resilience-related research. Including operational resilience, business continuity, cyber resilience, and enterprise risk management research.
Kiteworks has released its 2026 Data Security and Compliance Risk: Data Sovereignty Report, a cross-regional survey of risk management, compliance, IT, and security professionals that reveals a striking data sovereignty disconnect.
Black Duck has released the 2026 Open Source Security and Risk Analysis (OSSRA) report, which highlights the largest increases in open source security, licensing, and operational risk since the report’s inception 11 years ago.
According to the recently published Thales 2026 Data Threat Report, many organizations say that the rapid pace of AI-driven transformation is now their biggest security challenge.
Sophos has released the 2026 Sophos Active Adversary Report. The findings highlight how attackers continue to exploit compromised credentials, weak or missing multifactor authentication, and poorly protected identity systems…
Barracuda Networks has released data showing that 90% of ransomware incidents in 2025 exploited firewalls through unpatched software or a vulnerable account.
Enterprises deploying AI systems with excessive permissions are experiencing 4.5x more security incidents than those that enforce least-privilege controls according to a new research report from Teleport.
Guidance based on artificial intelligence may be uniquely placed to foster biases in humans, leading to less effective decision-making, say researchers…
Ivanti has published findings from its 2026 State of Cybersecurity Report: Bridging the Divide. Drawing on insights from more than 1,200 cyber security professionals worldwide…
Organizations need to fundamentally shift their cybersecurity strategies: away from focusing solely on preventing access and towards limiting what IT assets intruders can reach and exploit once they have achieved initial access.









