The fragile state of trust in cybersecurity vendors: a 2026 insight

A recent global study explores the role of trust in cybersecurity and its influence on risk and decision-making, highlighting key challenges organisations face when assessing and managing security partners.

Sophos has released the Cybersecurity Trust Reality 2026 report, a global study examining the role of trust in cybersecurity.

Based on responses from 5,000 organisations across 17 countries, the report explores levels of confidence in cybersecurity vendors and the impact on operational risk and board-level decision-making.

The findings show that 95% of organisations do not have full confidence in their cybersecurity vendors, while 79% report difficulty assessing the trustworthiness of both new and existing partners. The data also indicates that a lack of trust is associated with increased concern about the likelihood of significant cyber incidents, influencing decision-making and vendor relationships.

The report highlights that trust gaps can contribute to operational challenges, including slower decision-making and changes in vendor relationships. It also notes that cybersecurity effectiveness is not assessed solely on technological performance, but also on factors such as transparency and the availability of supporting evidence.

Organisations are placing importance on verifiable security artifacts, including independent assessments, certifications, and demonstrated operational maturity, when evaluating vendors. The report also identifies differences in priorities, with CISOs focusing on transparency and performance, while boards and senior leadership place greater emphasis on independent validation and certifications.

With increasing regulatory scrutiny and the growing use of AI in cybersecurity, the report notes that organisations are expected to demonstrate due diligence in vendor selection. This includes considerations around transparency, governance, and the responsible use of AI.


Cognizant to acquire Astreya

Posted 1 week ago by Phil Alsop
Acquisition will expand Cognizant's AI builder technology stack with production-grade AI operations capabilities.

Integris TO Acquire MSP First Focus

Posted 1 week ago by Phil Alsop
Future-ready managed IT services provider advances long-term growth strategy, with first international acquisition.
inforcer introduces Copilot Manager to support MSPs in delivering AI services, including features related to monitoring and managing Shadow AI usage.
Guardz outlines how AI is influencing cybersecurity, with the report highlighting identity-related issues and vulnerabilities affecting MSPs, based...

Kaseya launches Agentic IT management platform

Posted 1 week ago by Sophie Milburn
Kaseya has introduced an autonomous IT management system that uses AI and unified data to support IT operations and security management.
Westcon-Comstor has integrated its value-added services into the Microsoft Marketplace, aiming to support partner operations and improve scalability.

Opus Technology achieves B Corp certification

Posted 1 week ago by Sophie Milburn
Opus Technology has earned B Corp status, joining a global community aiming for ethical and sustainable business practices.
Nebula Global Services has achieved Cyber Essentials Plus certification, confirming independently assessed cyber security controls across its...