Cybersecurity and data security remain the biggest concern for every sector Risk in Focus 2026 surveyed and public sector organizations are no exception. But look past the top spot and a different picture emerges: for public sector audit leaders specifically, the second biggest risk isn't a system or a threat actor. It's people.
Here's what Risk in Focus 2026, the IIA and ECIIA's flagship annual research, found for public sector chief audit executives across Europe.
Cybersecurity and data security still top the list
No surprises at the top. Across all three sectors surveyed, cybersecurity and data security ranked as the highest risk facing organizations today. Increasingly sophisticated attack methods and the looming shift to quantum-resistant encryption keep this risk firmly in first place, and CAEs expect it to stay there through 2029.
Human capital is public sector's number two risk and that's telling
Here's where public sector diverges from the other sectors surveyed. While financial services ranked macroeconomic uncertainty as their second biggest risk and private nonfinancial organizations pointed to digital disruption, public sector audit leaders placed human capital, diversity, talent management and retention in second place.
That tracks with what many public sector audit teams are already living through: stretched resourcing, difficulty attracting specialist skills and growing concern about deskilling as AI reshapes how audit work gets done. If your team feels thin and hard to staff, the data confirms you're not alone.
Digital disruption, macroeconomic pressure and climate risk round out the picture
Risk in Focus 2026 tracks five risk categories in depth: macroeconomic and geopolitical uncertainty, digital disruption and AI, cybersecurity, human capital and climate change. All five carry real weight for public sector organizations navigating funding pressure, technology change and evolving regulatory expectations, even where they don't rank as prominently as cybersecurity and human capital.
Notably, climate change fell two places in this year's survey, dropping to tenth overall as CAEs voiced frustration over shifting political attitudes and regulatory uncertainty. Only 24% of CAEs surveyed expect it to be a top five audit focus by 2029, down sharply from 40% the previous year.
What this means for your audit plan
The report's broader finding matters just as much as the individual rankings: the top risks below cybersecurity are bunching closer together than in previous years, at between 45% and 48%. Risks are becoming more interconnected, which makes prioritizing your audit plan harder, not easier.
For a public sector audit function already stretched on talent, that interconnection is exactly why a risk-based approach matters more than ever. When your audit plan is built from a live view of organizational risk, rather than a fixed annual rotation, you can respond as priorities shift instead of discovering the gap months later.
Getting ahead of the pressure
None of these risks are going away and most public sector teams don't have the option of solving them by adding headcount. What you can control is how efficiently your team works and how closely your audit plan tracks the risks that matter most right now.
That's the thinking behind our guide, Risk-based assurance: why integrated audit and risk management matters, which looks at what happens when audit and risk functions stop working in isolation.
Why integrated audit and risk management matters
Our guide draws on Risk in Focus 2026 research from more than 4,000 CAEs to show how connecting your audit and risk functions delivers stronger assurance, better reporting and less duplicated effort.
Explore internal audit solutions
Get more value, more audits and more flexible workflows from your internal audit software.