CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your survey with us: editor@corporatecomplianceinsights.com.
Social engineering tops more than 75% of security experts concerns
Cyber crooks tricking employees into handing over access to company information is the top human risk for more than three-fourths of cybersecurity personnel, a survey by SANS Institute concluded.
The global survey of more than 1,700 cybersecurity practitioners found that 77% say social engineering is their organization’s top human risk, while phishing remained the primary attack method. But fake texts and voice scams are on the rise, the survey said.
AI has made it easier for hackers to research victims and launch social engineering attacks, the survey reported, and, reflecting this reality, AI jumped from the fourth spot two years ago to second place this year in cybersecurity experts’ ranking of human risks. More than two in five (42%) respondents said AI was a top risk as they’re particularly concerned with organizations not having policies in place to govern AI and not knowing how employees are using unauthorized AI, a practice known as shadow AI.
With 39% of respondents naming incorrect handling of sensitive data as a human risk, the issue ranked third, while password and authentication risk ranked fourth with 22% saying cyber attackers getting ahold of these credentials is a major concern. Password and authentication risk have dropped two spots over the past two years in the rankings.
More finance functions turning to AI
Companies have increasingly turned to AI to make money predictions. with a nearly 20-percentage-point jump over the past year in leaders using the technology to forecast financials, according to a new survey by Protiviti. Over the past year, the percentage of leaders using AI for financial forecasts increased from 58% to 76%, the survey of 902 worldwide executives found.
Despite the rise in usage, how much cash AI brings in is still hard for companies to measure, Protiviti said. Only 35% of finance functions say they are highly or moderately effective at measuring AI return on investment. That may be due to a lack of an AI plan. Just 14% deploy AI with a defined strategy, the survey found.
Finance leaders are also concerned about security as AI adoption increases and the technology’s access to data ramps up, according to the survey. Data privacy and security ranked as the top finance priority for a third year in a row.
“Finance leaders have moved beyond asking whether to adopt AI. Today’s challenge is to use AI to make more informed business decisions and prove that it is delivering measurable value,” Christopher Wright, global leader of Protiviti’s CFO solutions and business performance improvement practice, said in a statement. “Organizations that pair strong data governance with clear business objectives are better positioned to navigate economic uncertainty, shifting market conditions and rising expectations for finance transformation.”
Other key findings include:
- 77% of finance organizations now use AI.
- 67% use AI for risk assessment and management.
- 56% use the technology for process automation.
Ransomware attacks reached year high in July
Hackers had a prolific summer as ransomware activity spiked in July to its highest point since February 2025, according to a report by NCC Group, representing a 22% increase from June.
The ransomware activity remains concentrated in North America, where 41% of cyber attacks occurred, and Europe, which accounted for 29%. Industrials were the most targeted sector, with 250 attacks (28%), followed by consumer discretionary with 165 (18%) and information technology with 103 (12%) attacks.
The report also highlighted what cybersecurity group Sysdig in early July called the first documented case of agentic ransomware, giving the AI agent the name JADEPUFFER and describing the attack as “a complete extortion operation driven end-to-end by a large language model.”
“AI is changing the speed and scale of cyber attacks,” Matt Hull, NCC Group vice president of cyber intelligence and response, said in a statement. “It’s allowing attackers to automate more of what they do, operate at greater scale and create increasingly convincing phishing, social engineering and other malicious content. That can make threats harder for both organizations and individuals to identify.”








