Research findings in the CSC CISO Outlook 2026 report show that social media impersonation and defamation have emerged as the top cyber security threat for 2026 and beyond, followed by domain and DNS hijacking, DDoS attacks, and cybersquatting. This marks a significant rise from last year, when social media impersonation and defamation ranked fifth.
The report also found that employee and executive impersonation, including deepfakes, has now entered the top five biggest areas of risk for CISOs and senior technology leaders for the first time. This suggests identity-based attacks are moving higher up the cyber security agenda, as criminals increasingly look to exploit trusted people and brands to deceive both employees and customers.
AI is also continuing to complicate the threat landscape, making impersonation, domain abuse, and third-party risk harder to manage. According to the report, 86% of respondents now see AI-powered domain generation algorithms as a threat. And yet, CISO optimism around AI remains high. The report found that 73% of respondents say AI is more of an opportunity than a risk for cyber security, while only 16% see it as equally an opportunity and a risk.
Despite this optimism, supplier and partner AI use remains a major concern. In fact, 79% are concerned that suppliers’ and partners’ AI tool use poses a cyber security risk to their organization. However, only 15% apply their organization’s risk controls to all suppliers, while 70% apply risk controls only to key suppliers.
Demographics
The CISO Outlook 2026 is based on a global survey of 300 senior technology and cyber security executives, including CISOs, chief technology officers (CTOs), chief information officers (CIOs), and heads of cyber security. Respondents were surveyed in early 2026 and are evenly split across North America, Europe including the UK, and the Asia-Pacific region.






