Supply Chain World Volume 13 Issue 4 August 2026 | Page 11

________________________________________________________________________________________________
Main
Interview attack surface and very strong capabilities, and it’ s a dynamic that’ s genuinely getting harder to keep in check in some cases. As for what earns Cye’ s research attention, a big part of it comes directly from our clients. They see developments happening and come to us with concerns, and that steers a lot of our roadmap. The other part comes from being a cybersecurity company ourselves. We must develop secure code and face these same challenges internally, and what we learn from operating in that space, we bring back to the rest of the industry.
6. Can you give us an overview of the research behind Cye’ s 2026 Global Cybersecurity Maturity Report? What data points surprised you the most? The report draws on more than 2400 assessments across 21 countries and
16 industries, scored against NIST’ s Cybersecurity Framework( CSF 2.0) and, for the first time this year, against the NIST AI Risk Management Framework( AI RMF 1.0). We derived that by mapping existing CSF function scores onto the four AI RMF functions, with AI-specific findings pulled out through keyword and NIST subcategory analysis. Connecting data we already had to a genuinely new, AI-oriented framework, since there wasn’ t an established benchmark for AI risk maturity before this.
The data point that stands out most to me is that 88 percent of organizations are already using AI, yet their average AI risk maturity sits at just 2.35 out of 5, barely inside the‘ Managed’ band. It’ s not that organizations are unaware of the risk, as governance is consistently the highestscoring function in both frameworks we measured. It’ s the functions that turn
scw-mag. com 11