New research from WatchGuard Technologies reveals that employee behavior is creating significant and often invisible cybersecurity risk for small and medium-sized businesses. According to the “Cybersecurity Hygiene Report 2026”, 64% of employees acknowledge using unauthorized AI tools to work, which contributes to quickly aggravating the problem of shadow AI, a phenomenon over which most organizations do not have sufficient visibility to manage the risks it entails.
At the same time, common habits in the work environment continue to amplify the risk. 76% of employees reuse passwords, 70% use public Wi-Fi networks for work, and 50% access corporate resources without VPN protection, exposing organizations to credential theft, data interception, and unauthorized access. When these practices are combined with shadow AI, the level of exposure increases considerably.
“Organizations are investing in security tools, but many still lack visibility into how their employees are actually working,” explains Marc Laliberte, Director of Security Operations at WatchGuard. “Everyday behaviors, from the use of shadow AI to password practices, create risks that traditional controls are not designed to address.”
Visibility gaps widen
Consumer AI tools have given rise to a rapidly growing category of security risk that most organizations still do not address through a formal governance framework. The rise of shadow AI is accelerating this problem, as employees incorporate artificial intelligence applications without knowledge or oversight from IT teams. According to the report, less than 30% of respondents believe their organization maintains an accurate inventory of the software used, and nearly 40% say their company operates without complete visibility into the applications their workers use, including many shadow AI solutions.
This lack of governance, including corporate guidelines on authorized tools and information that can be transmitted externally, creates a dangerous blind spot for IT and cybersecurity teams. Without specific policies to control shadow AI, companies run the risk of sensitive data being entered into unauthorized platforms.
Beyond shadow AI, certain widespread employee behaviors continue to weaken organizations’ security protocols and open opportunities for cybercriminals. Among them:
- 76% of employees admit to reusing passwords across multiple accounts. This means that a single compromised credential can leave the organization exposed to account takeover, lateral movement, and significant data exfiltration across multiple systems, platforms, and applications. Additionally, 30% of respondents say they share their passwords with other people. If these credentials are also used in shadow AI tools, the potential impact may be even greater.
- 70% use public Wi-Fi networks for work, while 50% access corporate resources without VPN protection. This significantly expands the organization’s attack surface and increases exposure to data interception, credential theft, and unauthorized network access through man-in-the-middle attacks and other threats targeting unsecured connections. The use of shadow AI platforms from this type of networks increases the risk even further.
- 55% use work devices for personal activities, increasing the risk of malware infections, phishing attacks, and access to apps or websites that could bypass the organization’s security controls. The widespread adoption of hybrid and remote work has blurred the lines between personal and professional spheres, creating new opportunities for attackers to compromise corporate data and making it difficult for security teams to effectively mitigate risk. This context also favors the expansion of shadow AI, as employees turn to unauthorized tools to speed up their tasks.
MSPs are in a privileged position to address it
Increasing pressure to improve productivity, evolving work environments, and rapid technology adoption are driving risky behaviors among employees, including the growing use of shadow AI.
This offers MSPs a clear opportunity to help SMEs address cybersecurity hygiene gaps before they lead to serious incidents, by incorporating specific controls and policies to detect and manage shadow AI within organizations.
Consumer AI tools have given rise to a category of risk that companies do not address through a formal governance framework
“These results reflect a broader shift in cybersecurity risk. As organizations adopt new technologies and facilitate distributed work, managing human behavior is becoming a critical requirement,” says Laliberte. “For MSPs, it presents an opportunity to go beyond technology and incorporate user risk visibility, policy governance and continuous security awareness, especially in the face of the growth of shadow AI.”
To reduce exposure, WatchGuard recommends that SMBs and their MSP partners focus on six practical measures, including requiring the use of password managers and multi-factor authentication (MFA), identifying the use of unauthorized or shadow AI technologies, establishing clear policies for the safe use of shadow AI and other artificial intelligence tools, extending protection beyond the office through VPN and Zero Trust approaches, and implementing ongoing security training, while monitoring human risk metrics along with technical indicators.
