SUNNYVALE, Calif., Sept. 09, 2026 (GLOBE NEWSWIRE) -- Proofpoint, Inc., a global leader in human and agent cybersecurity, today released its 2026 Voice of the CISO report, revealing signs of greater cyber resilience even as the nature of enterprise risk increases in complexity. The percentage of global CISOs who believe their organization is at risk of a material cyberattack in the next 12 months fell to 61%, down from 76% in 2025, while reported material data loss also declined from 66% to 53%.
Yet progress has not made the CISO’s job simpler. The global study of 1,600 CISOs across 16 countries finds risk increasingly concentrated in the people, data, applications, and AI systems embedded in everyday work. Human risk is rising, with 79% of CISOs now identifying it as their organization’s biggest cyber vulnerability, up from 66% in 2025. With that, the consequences of data loss are becoming more severe, and CISOs are assuming greater responsibility for enabling AI securely—with 78% expected to manage AI-related risks without a proportional increase in resources or expertise in the next two years.
“AI is fundamentally changing the CISO mandate,” said Patrick Joyce, global resident CISO at Proofpoint. “Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role.”
Key global findings from the 2026 Voice of the CISO report include:
- CISOs are now expected to secure and champion AI. GenAI security concerns jumped 18 percentage points year over year, with 78% of CISOs now viewing it as a security risk. At the same time, 85% say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years, while 79% are expected to manage AI-related risks without a proportional increase in resources or expertise.
- Cyber resilience improves, but the risk model is changing. Expectations of a material cyberattack fell from 76% in 2025 to 61% in 2026, while material data loss declined from 66% to 53%. Yet 56% of CISOs still say their organization is unprepared to cope with a targeted cyberattack. Concern is increasingly centered on technologies embedded in everyday work, including collaboration platforms (34%), AI assistants, copilots and autonomous agents (33%), SaaS applications and third-party integrations (33%), public GenAI tools (31%), and cloud storage and file-sharing platforms (30%).
- The biggest risk is employee behavior. Nearly eight in 10 CISOs (79%) identify human risk as their organization’s biggest cyber vulnerability, up from 66% in 2025. Among organizations that experienced material data loss, malicious or criminal insiders were the leading cause (46%), while careless and compromised insiders were each cited by 38%. Notably, 93% of CISOs at organizations experiencing material data loss say departing employees played a role.
- Data loss declines, but the consequences grow. While the proportion of organizations experiencing material data loss declined year over year—from 66% in 2025 to 53% in 2026—the business impact for those that did suffer data loss became more severe. Regulatory sanctions rose from 34% to 40%, while financial losses increased from 27% to 38%. Post-attack recovery costs rose from 32% to 38%, and reputational damage increased from 31% to 37%.
- CISOs trust their defenses, but not their own employees’ AI habits. While 86% of CISOs believe their controls effectively mitigate risks introduced by AI, SaaS, and modern work patterns, 76% believe employees are likely to use AI in ways that could expose sensitive data. More than three-quarters (77%) are concerned about customer data loss through public GenAI tools, and 78% block or restrict employee GenAI use.
- Boards are listening to CISOs more and expecting more in return. 85% of CISOs say they see eye-to-eye with their boards on cybersecurity, up significantly from 64% in 2025. But greater alignment is not reducing pressure on security leaders. Boards are evaluating cyber risk through a commercial lens, with enterprise value, downtime, reputational damage, operational disruption, and sensitive data loss among their top concerns. 77% of global CISOs say excessive expectations are placed on them. 86% believe cybersecurity expertise should be required at the board-director level, up from 66% in 2025.
“Improving resilience is an encouraging sign, but it doesn’t mean the risk environment is becoming less complex,” said Patrick Joyce. “Risk is increasingly tied to how people, data, applications, and AI interact every day, while CISOs are being asked to manage that exposure in business terms. The findings make clear that continued progress will depend on security strategies evolving alongside where both work and risk are headed.”
To download the full 2026 Voice of the CISO report, visit https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report.
Methodology
The 2026 Voice of the CISO report polled over 1,600 CISOs at organizations with 1,000 employees or more across different industries. 100 CISOs were interviewed in each market across the following 16 countries: the United States, Canada, Brazil, Mexico, the United Kingdom, France, Germany, Italy, Spain, the Netherlands, the United Arab Emirates, the Kingdom of Saudi Arabia, Australia, Japan, Singapore, and India. The research was conducted by Censuswide in May 2026.
About Proofpoint, Inc.
Proofpoint, Inc. is a global leader in human and agent cybersecurity, securing how people, data, and AI agents connect across email, cloud, and collaboration tools. Proofpoint is a trusted partner to over 80 of the Fortune 100, over 14,000 large enterprises, and millions of smaller organizations in stopping threats, preventing data loss, and building resilience across people and AI workflows. Proofpoint's collaboration, data, and AI security platform helps organizations of all sizes protect their people and adopt AI securely and confidently. Learn more at www.proofpoint.com.
Connect with Proofpoint on LinkedIn
Proofpoint is a registered trademark or tradename of Proofpoint, Inc. in the U.S. and/or other countries. All other trademarks contained herein are the property of their respective owners.
PROOFPOINT MEDIA CONTACT:
Estelle Derouet
Proofpoint, Inc.
pr@proofpoint.com
