Fewer CISOs expect a major cyberattack this year — but AI, human risk and boardroom pressure are reshaping the job faster than budgets can follow, according to Proofpoint’s latest global survey of 1,600 security leaders.

Cybersecurity leaders are, by their own account, getting better at their jobs. Fewer chief information security officers now expect a material cyberattack in the coming year, and fewer report having suffered a serious data loss than twelve months ago. Yet according to Proofpoint’s 2026 “Voice of the CISO” report, published this week, that apparent progress masks a harder truth: the risk has not shrunk, it has relocated — into the AI tools, cloud platforms and identities that now run daily business.

The report, based on a global survey of 1,600 CISOs across 16 countries conducted by Censuswide between May 11 and 18, 2026, describes a profession in transition rather than one bracing for further escalation. According to the company, 61% of CISOs now believe their organization faces a material cyberattack within the next twelve months, down sharply from 76% in 2025. Reported material data loss fell similarly, from 66% to 53%.

Proofpoint cautions against reading this as a sign the problem has been solved. Fully 56% of respondents still describe their organization as unprepared for a targeted attack — barely changed from 58% a year earlier. Traditional threat categories have also cooled: concern over ransomware, malware and email fraud all declined year-over-year. In their place, cloud account takeover has become the most frequently cited threat, at 33%, alongside rising unease about collaboration platforms, AI assistants and SaaS integrations — the everyday tools through which sensitive data now moves.

AI: from concern to core mandate

Nowhere is that shift more visible than in artificial intelligence. Seventy-eight percent of CISOs surveyed now call generative AI a security risk, up from 60% a year ago, and 77% worry specifically about losing customer data through public GenAI tools. At the same time, 85% say enabling safe use of AI assistants and copilots is a top priority, and an equal share are looking to deploy AI-powered defenses of their own.

Many organizations have responded by tightening restrictions — 78% now block or limit employee use of GenAI tools, up from 59% in 2025. But according to Ben McLaughlin, CISO at Proofpoint, restriction alone will not be enough as AI becomes embedded across everyday applications. The more pressing figure, he suggests, may be this: 79% of CISOs say they are expected to manage AI-related risk without a corresponding increase in resources or expertise.

Human risk moves to the center

The report also documents a marked shift in how CISOs frame their biggest vulnerability. Seventy-nine percent now identify human risk as their organization’s single greatest weakness, up from 66% last year — one of the largest year-over-year moves in the study. Among organizations that suffered material data loss, malicious or criminal insiders were the most commonly cited cause (46%), followed closely by careless and compromised insiders (38% each) and AI tool misconfiguration (37%).

Departing employees emerged as a particular flashpoint: 93% of CISOs whose organizations experienced data loss said staff leaving the company played a role — underscoring, the report notes, the importance of controls spanning the full employee lifecycle rather than just onboarding.

Higher stakes when incidents do occur

Even as incident frequency declines, the consequences appear to be intensifying. Among organizations reporting material data loss, regulatory sanctions rose from 34% to 40% year-over-year, financial losses climbed from 27% to 38%, and post-incident recovery costs increased from 32% to 38%. Reputational damage and credential theft each reached 37%.

Boardroom expectations rise alongside alignment

Board engagement with cybersecurity has also rebounded sharply, with 85% of CISOs now reporting that their board is aligned with them on security issues, up from 64% in 2025 — though Proofpoint notes this metric has swung considerably over recent years, from 51% in 2022 to 84% in 2024 before dropping and rebounding again. Boards, CISOs say, are increasingly framing cyber risk in commercial terms: business valuation (42%), downtime and reputational damage (38% each) top the list of board concerns.

That closer attention comes with a cost. Seventy-seven percent of CISOs say expectations placed on their role have become excessive, up from 66% a year ago. Burnout, while easing slightly — from 66% in 2024 to 57% this year — still affects more than half the profession.

Regional variation was pronounced throughout the report. India recorded the highest levels of concern across nearly every metric, including AI risk (92%), human risk (93%) and cyberattack likelihood (94%). France showed the strongest restrictive response to GenAI (95% blocking or limiting use), while Japan consistently reported the lowest concern levels across most categories.

Proofpoint concludes that organizations best positioned for the year ahead will be those pairing AI adoption with proportional governance — and giving CISOs the authority and resources to match an increasingly commercial, and increasingly complex, mandate.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner