In 2026, CISOs are prioritizing AI-enablement projects, such as AI usage and governance [link to use case page], but they remain vulnerable and exposed to the oldest trick in the book: social engineering. According to the 2025 FBI IC3, phishing is the most-reported cybercrime type.
Social engineering attacks evade cybersecurity defenses by targeting the human edge, an attack surface of unmanaged and unprotected human decision points that exists beyond the traditional perimeter.
Social engineering attacks manipulate these unprotected moments with psychological techniques designed to lure employees into divulging sensitive information or initiating fraudulent financial transactions.
However, just because social engineering attacks are one of the oldest tricks in the book does not mean they remain old-fashioned. Just as CISOs are embracing AI enablement, so are social engineering attackers. According to the 2026 Verizon Data Breach Investigations Report, phishing accounts for 44% of AI-assisted initial access.
Social engineering is a blind spot for legacy perimeter controls while compensating controls, such as security awareness training, fail to meaningfully change user behavior. Forward-deployed cybersecurity, which embeds the expert judgment of AI guardian agents at the human edge, is a frontier solution for social engineering in 2026.
This blog explores these recent challenges and the pioneering application of forward-deployed cybersecurity in 2026.
The human element is the greatest source of risk in 2026, just as it has been for many years. According to the 2026 Verizon Data Breach Investigations Report, the human element appears in 62% of breaches. However, if you talk to a CISO they will tell you that it feels closer to one hundred percent.
Additional research from IBM’s 2025 Cost of a Data Breach report found that 16% of breaches include phishing, the single most common initial attack vector. Likewise, FBI IC3 statistics rank phishing as the most reported cybercrime in 2025.
However, social engineering is even bigger than just phishing.
For example, business email compromise (BEC) attacks impersonate trusted executives, partners, and vendors to initiate fraudulent financial transactions. According to the FBI IC3, BEC attacks cost organizations $3.05 billion in 2025.
Phishing and BEC are proof of why social engineering attacks have remained so effective for so long: there is no malware, there is no exploit, there is nothing for legacy controls to detect.
These legacy control failures are nothing new for 2026. The point is that decades of cybersecurity investment never produced an effective control for the human edge.
It should come as no surprise that social engineering attacks are the greatest risk in 2026 since attackers have now weaponized artificial intelligence. According to the 2026 Verizon Data Breach Investigations Report, phishing accounts for 44% of AI-assisted initial access. AI-assisted text in malicious emails has doubled year over year.
AI-enabled social engineering attacks have lowered the barrier of entry to create personalized messages (i.e. “pretext”) for phishing attacks at the speed and scale of a machine. For example, a large language model (LLM) can conduct the reconnaissance stage of a social engineering attack, identifying key employees, relationships, and how to exploit them.
Every phishing attack has the potential to be a spear-phishing attack with this level of personalization. Every organization is at risk when even the most unsophisticated attackers can produce social engineering campaigns with AI assistants as their co-pilot.
AI has collapsed the cost of an attack, but users are more distracted than ever.
As organizations operationalize AI programs, knowledge workers are expected to collaborate with their own AI assistants to achieve greater productivity, but ChatGPT, Claude, and Gemini are not present when a user visits a phishing website.
Security awareness training conjures up images of mandatory requirements and check-the-box compliance. The only thing worse than the dread of security awareness training is the fact that it doesn’t work in the first place.
According to Understanding the Efficacy of Phishing Training in Practice, an eight-month randomized study of more than 19,500 employees at UC San Diego Health found “no significant relationship between whether users have recently completed cybersecurity training and their likelihood of failing a phishing simulation.”
There is a significant gap between education and practice. The experience of completing security awareness training is not the experience of being targeted by a social engineering attack. The authors of the study concluded that security awareness training is “unlikely to offer significant practical value in reducing phishing risks.”
Security awareness training fails to remediate the exposed and vulnerable employees who may be exploited by social engineering. Consequently, CISOs must not rely on security awareness training as a primary control.
Over the past two decades, the cybersecurity industry has declared “the perimeter is dead” as it constantly shifted the goal posts from the network, to the device, to the identity. Yet social engineering persists.
That is because none of these shifting perimeter defenses protect the human edge. None protect the human decision point. A point in both “space” and “time.”
Legacy defenses fail to meet users where they are in moments that matter most, unable to intercept risk in real-time. Compensating controls arrive before or after the moment has passed.
In the case of social engineering, security awareness training occurs in the past, far before the moment a user is asked to share their password. This unprotected moment is the source of risk.
Forward-deployed cybersecurity protects these moments. Forward-deployed cybersecurity protects the human edge.
Rather than centralizing protection in infrastructure and waiting for risk to escalate, forward-deployed cybersecurity detects, intercepts, and resolves risk in real-time, before a decision becomes a breach.
Witness the power of guardian agents protecting the human edge for your organization. Let's talk.