Proofpoint Report: CISOs Face Growing Human and AI Security Risks

Proofpoint’s 2026 Voice of the CISO report finds cyber resilience improving as human risk and AI-related security challenges reshape the CISO role.
https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-2026-voice-ciso-report-finds-cyber-resilience-improving-while-ai
CISO responsibilities continue to expand as organizations balance cyber resilience with emerging AI and human risks.

CISO responsibilities continue to expand as organizations balance cyber resilience with emerging AI and human risks.

Proofpoint’s 2026 Voice of the CISO report finds that organizations are showing signs of greater cyber resilience while security leaders face increasingly complex risks tied to employees, data, applications and artificial intelligence.

The global study of 1,600 CISOs across 16 countries found that 61% believe their organization is at risk of a material cyberattack in the next 12 months, down from 76% in 2025. Organizations reporting material data loss also declined from 66% to 53%.

Despite those improvements, human risk has become a greater concern. Seventy-nine percent of CISOs identify human risk as their organization’s biggest cyber vulnerability, up from 66% in 2025.

CISOs are also taking on greater responsibility for securing AI use. GenAI security concerns increased 18 percentage points year over year, with 78% of CISOs identifying it as a security risk. Meanwhile, 85% say enabling the safe use of AI assistants, copilots and automation is a top priority over the next two years. Seventy-nine percent are expected to manage AI-related risks without a proportional increase in resources or expertise.

“AI is fundamentally changing the CISO mandate,” said Patrick Joyce, global resident CISO at Proofpoint. “Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly.”

Cyber Resilience Improves as Risk Changes

While expectations of a material cyberattack have declined, 56% of CISOs say their organization remains unprepared to cope with a targeted cyberattack.

Concern is increasingly focused on technologies embedded in everyday work. Collaboration platforms were cited by 34% of respondents, followed by AI assistants, copilots and autonomous agents at 33%. SaaS applications and third-party integrations also reached 33%, while public GenAI tools and cloud storage and file-sharing platforms were cited by 31% and 30%, respectively.

Employee behavior remains a significant source of exposure. Among organizations that experienced material data loss, malicious or criminal insiders were the leading cause at 46%, while careless and compromised insiders were each cited by 38%. Ninety-three percent of CISOs at organizations experiencing material data loss said departing employees played a role.

Data Loss Declines as Impact Increases

Although material data loss declined from 66% in 2025 to 53% in 2026, the consequences became more severe among organizations that experienced it.

Regulatory sanctions increased from 34% to 40%, financial losses rose from 27% to 38% and post-attack recovery costs increased from 32% to 38%. Reputational damage also rose from 31% to 37%.

CISOs expressed confidence in their defenses, with 86% saying their controls effectively mitigate risks introduced by AI, SaaS and modern work patterns. However, 76% believe employees are likely to use AI in ways that could expose sensitive data.

Seventy-seven percent are concerned about customer data loss through public GenAI tools and 78% block or restrict employee GenAI use.

Board Alignment Increases

CISO and board alignment has also improved. Eighty-five percent of CISOs say they see eye-to-eye with their boards on cybersecurity, up from 64% in 2025.

However, 77% say excessive expectations are placed on them. Boards are evaluating cyber risk through a commercial lens, with enterprise value, downtime, reputational damage, operational disruption and sensitive data loss among their top concerns.

The percentage of CISOs who believe cybersecurity expertise should be required at the board-director level rose to 86% from 66% in 2025.

“Improving resilience is an encouraging sign, but it doesn’t mean the risk environment is becoming less complex,” Joyce said. “Risk is increasingly tied to how people, data, applications, and AI interact every day, while CISOs are being asked to manage that exposure in business terms.”

He added that continued progress will depend on security strategies evolving alongside where work and risk are headed.

Sign up for our eNewsletters
Get the latest news and updates