Man knielt bij kluisje op de UvA
News

Security & Privacy Awareness Survey 2026: AI use turns out to be the greatest vulnerability

Knowledge of cybersecurity and privacy-conscious working practices is relatively strong amongst staff in education and research, but this has not yet led to consistently secure behaviour. In addition, the use of AI applications is growing faster than policy can keep up with. This is evident from the 2026 sector report on security and privacy awareness by SURF and BDO.

On behalf of SURF, BDO carried out the security and privacy awareness survey for the 5th time, this year involving 30 education and research institutions in further vocational education (MBO), higher professional education (HBO) and university education (WO). A new feature of this report is a study by The Hague University of Applied Sciences into staff members’ experiences of cyber incidents and the impact these have on their work.

AI use: the largest area of tension

A key finding of the survey is that staff are increasingly using AI tools in their day-to-day work, whilst policies and guidelines do not provide sufficient guidance in this regard. The lack of approved, secure AI alternatives means that staff are resorting to public AI tools, which increases the organisation’s vulnerability.

Cyber incidents affect 4 in 10 employees

The supplementary research by The Hague University of Applied Sciences shows that 40.1 per cent of employees have experienced a cyber incident at their institution in the past two years. In most cases, this involved a data breach. Employees find this particularly disruptive to their day-to-day work; it takes them a great deal of time to resolve the incident or inform those affected. It also appears that the necessary guidelines and reporting procedures are sometimes difficult to find, or even non-existent. Of the employees who experienced an incident, 17 per cent say they have been more cautious online ever since.

Recommendations for organisations

With the following advice from the report, you can get started straight away within your organisation to raise awareness of cybersecurity:

  • Set out specific safe working practices for each work situation
    Ensure that awareness and communication strategies are tailored to specific work situations and clearly describe exactly what staff must do.
     
  • Lower the barrier to secure behaviour
    Ensure that measures align as closely as possible with how people already work, for example when sharing data securely or managing authorisations.
     
  • Draw up an AI policy and offer secure alternatives
    Where possible, establish sector-wide agreements on AI use and offer staff accessible, secure tools as an alternative to shadow IT.

In addition, a number of fundamental points for attention remain relevant, which also emerged from previous surveys: continue to invest in organisational culture and exemplary behaviour by managers; make cyber-secure working practices part of the onboarding programme; repeat training sessions with a focus on role-specific risks; and ensure there is a central, easily accessible location for guidelines and reporting channels.

Want to read the full report?

Read more advice and findings in the Security & Privacy Awareness Survey 2026 (in Dutch).

The original article can be found on the Security Expertise Centre’s website.