95% do not have full trust in cybersecurity vendors

April 2026 Information Security, Security Services & Risk Management

Sophos has released findings from a global, vendor-agnostic study (based on responses from 5000 organisations across 17 countries), examining one of cybersecurity’s most urgent and overlooked necessities: trust.

The Cybersecurity Trust Reality 2026 report is one of the most comprehensive studies of trust in cybersecurity and its impact on operational risk and board-level decision-making. It reveals a critical challenge facing CISOs: trust in cybersecurity vendors is fragile, difficult to measure, and increasingly shaping risk posture at both operational and board levels.

At a time of relentless cyberthreats, heightened regulatory scrutiny, and accelerating AI adoption, trust has become a defining factor in cybersecurity decision-making. Yet new research reveals that nearly all organisations report a lack of full confidence in their cybersecurity vendors, and many struggle to assess vendors' trustworthiness in the first place.

The independent study found that:

● 95% of respondents said they do not fully trust their cybersecurity vendors.

● 79% struggle to assess the trustworthiness of new cybersecurity partners, and over six in ten (62%) even find it challenging for their existing vendors.

● More than half (51%) report increased anxiety about the likelihood of a significant cyber incident as a direct result of a lack of trust.

These findings underscore a critical reality: cybersecurity effectiveness cannot be measured by technological performance alone, but also by the confidence that organisations have in the partners defending their business. For CISOs, trust gaps create operational friction, slower decision-making, and higher vendor turnover. Trusted cybersecurity partners reduce risk and build more resilient organisations.

“Trust is not an abstract concept in cybersecurity; it is a measurable risk factor,” said Ross McKerchar, CISO at Sophos. “When organisations cannot independently verify a vendor’s security maturity, transparency, and incident handling practices, that uncertainty flows directly into boardrooms and security strategies.”

The survey identifies verifiable security artefacts, including independent assessments, certifications, and demonstrated operational maturity, as the single greatest driver of vendor trust. CISOs prioritise transparency during incidents and consistent technical performance, while boards and senior leadership place greater weight on independent validation, certifications, and analyst performance.

The common thread is clear. Organisations want transparency backed by evidence, not blanket assurances.

“With regulatory pressure increasing globally, organisations must be able to demonstrate due diligence in vendor selection, especially where AI is involved,” said Phil Harris, research director, Governance, Risk and Compliance Solutions at IDC. “Trust is shifting from a marketing message to a defensible compliance requirement.”

As artificial intelligence becomes embedded in cybersecurity tools, services, and workflows, organisations are not only evaluating whether security solutions are effective, but whether AI is deployed responsibly, transparently, and with appropriate governance. Trust is no longer optional. It is foundational.

“CISOs are being asked to prove trust, not assume it,” added McKerchar. “Cybersecurity providers must do the same. Respondents to the survey cited a lack of accessible, sufficiently detailed information as the primary barrier to making confident assessments of trust. Trust must be earned continuously through transparency, accountability, and independent validation.”

These findings elevate trust from a brand attribute to a strategic imperative.

At Sophos, building and maintaining that trust is foundational. Through the company’s Trust Centre, Sophos aims to help security leaders make faster, more defensible decisions in an increasingly hostile threat landscape.

Visit the Sophos Trust Centre: https://www.sophos.com/en-us/trust

Read the full research report: https://www.sophos.com/en-us/content/cybersecurity-vendor-trust-survey-2026




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
A risk-based approach to fire safety
Fire & Safety Security Services & Risk Management Industrial (Industry) Agriculture (Industry)
A report by fire engineering consultancy ASP Fire is challenging blanket assumptions around combustible-core sandwich panels, arguing instead for a rational, risk-based approach that balances fire safety requirements with commercial realities in sectors such as agriculture, manufacturing and industrial processing.

Read more...
Preventing and suppressing lithium fires
SMART Security Solutions Technews Publishing Editor's Choice Fire & Safety Security Services & Risk Management Smart Home Automation
SMART Security Solutions asked Clyde Becker, director of Pyro Brand, for some insight into the mechanics of lithium-ion battery fire risks, especially thermal runaway, and to define a comprehensive, layered approach to fire detection and suppression.

Read more...
Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
Echoes of 2018? Follow-up on Woolworths explosions
Technews Publishing News & Events Security Services & Risk Management Retail (Industry) Facilities & Building Management
SMART Security Solutions follows up with Jimmy Roodt to find out more about an old connection to the Woolworths bombings from 2018. The investigation remains ongoing.

Read more...
NEC XON detects and stops ransomware attack
NEC XON Information Security IoT & Automation
Ransomware attacks rarely begin with chaos. More often, they start quietly, with probing, mapping, and patient reconnaissance inside a target’s network. That was the situation facing a global recruitment firm when cybercriminals attempted to navigate its systems.

Read more...
Next-generation cash-in-transit vehicle
News & Events Security Services & Risk Management
Fidelity Services Group has unveiled a new, purpose-engineered Cash-in-Transit (CIT) vehicle designed to redefine crew protection, deter threats, and enhance operational resilience in an increasingly complex criminal environment.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.