Cyber Benchmark 2026: Regulation Strengthens Cyber Defense – AI Shifts the Security Agenda

The cybersecurity maturity of large companies continues to rise: Regulatory requirements such as DORA and NIS2 are having an impact. At the same time, new vulnerabilities are emerging around the use of artificial intelligence, for which many organizations are still inadequately prepared. This is shown by Wavestone’s latest Cyber Benchmark 2026, which is based on an analysis of more than 200 companies worldwide.

Countering Constant Change: Companies Are Strengthening Their Cyber Defenses Against New AI Risks. Source: Wavestone / zvg

The average cyber maturity of large companies rose to 55.3 percent in 2026. The Wavestone Cyber Benchmark 2026 is based on an analysis of more than 200 organizations worldwide, including over 100 companies with annual revenue exceeding one billion euros. The assessment was conducted using internationally recognized standards such as the NIST Cybersecurity Framework 2.0 and ISO 27001/27002—and, for the first time, included an in-depth analysis of the security of AI systems across 17 cybersecurity domains.

Regulation Promotes Investment and Organizational Maturity

The impact of regulatory requirements is particularly evident: Companies in regulated industries demonstrate a significantly higher level of maturity than organizations without comparable regulatory pressure. The financial sector remains the frontrunner, having once again significantly increased its cyber maturity compared to the previous year. The study highlights progress particularly in the areas of governance, risk management, cyber threat detection, and incident response. Human and financial resources also continue to grow: Companies invest an average of 6.7 percent of their IT budget in cybersecurity and now employ more cybersecurity specialists than they did a year ago.

«The results show that regulatory requirements play an important role in professionalizing cybersecurity,» says Dr. Daniel Nussbaumer, a cybersecurity expert at Wavestone Switzerland. «Especially in regulated industries, we’re seeing that cybersecurity is increasingly being established as a strategic issue at the executive level and is no longer viewed exclusively as an IT task.»

Companies invest 6.7% of their IT budget in cybersecurity. Source: Wavestone

AI Creates New Risks for Businesses

While many organizations are making progress in addressing traditional cyber risks, a new area of risk is emerging around the use of AI. Although 76 percent of the companies surveyed already have policies in place for the secure use of AI, there are still significant gaps in technical safeguards. For example, only 10 percent of companies have implemented specific protective measures against AI-specific attacks such as prompt injection or the manipulation of AI systems. Overall, the maturity level in the area of AI security stands at just 38 percent.

«Many companies have already integrated AI into their processes or are in the process of scaling up such applications,» said Nussbaumer. «However, security mechanisms are not evolving at the same pace everywhere. This creates a new vulnerability that will become significantly more important in the coming years.»

Resilience remains the biggest challenge

Despite this positive trend, there is still a need for action. There is a clear need to catch up, particularly in the areas of resilience and recovery from cyberattacks. While companies are becoming increasingly better at detecting and responding to attacks, the ability to quickly restore critical business processes after an incident remains a challenge. The «Recover» category, at 44 percent, has the lowest maturity level of all the security dimensions examined.

25 percent of small and medium-sized businesses are in a critical cybersecurity situation. Source: Wavestone

Cybersecurity is becoming a competitive factor

For Wavestone, the results show that companies will need to align their cybersecurity strategies even more closely with regulatory requirements, technological innovations, and organizational resilience in the future. «Cybersecurity is increasingly becoming a strategic capability that goes beyond mere risk mitigation,» says Armando Chiodi, a partner at Wavestone. «Companies that comply with regulatory requirements, securely integrate new technologies, and simultaneously strengthen their resilience lay the foundation for sustainable business success.»

Source: www.wavestone.com

This article originally appeared on m-q.ch - https://www.m-q.ch/de/cyber-benchmark-2026-regulierung-staerkt-die-cyberabwehr-ki-verschiebt-die-sicherheitsagenda/

More articles on the topic