Proofpoint Voice Of CISO 2026 Report Reveals Changing Enterprise Cyber Risk Landscape

Published:

Proofpoint’s latest Voice of the CISO 2026 report highlights how the cybersecurity landscape is shifting as risks become increasingly connected with everyday business operations and digital workflows. The sixth edition of the research shows that while some security indicators have improved compared with previous years, CISOs are managing a broader set of responsibilities involving artificial intelligence governance, data protection, human behaviour and organisational resilience. The five year analysis suggests that cybersecurity challenges are no longer limited to defending against external attacks but are increasingly linked with how employees, applications, cloud platforms, collaboration tools and AI enabled systems operate together across modern enterprises.

According to Proofpoint’s findings, fewer CISOs now expect a major cyberattack within the next 12 months, and fewer organisations reported significant sensitive information loss compared with 2025. However, the longer trend reveals that cybersecurity risk continues to evolve rather than follow a simple improvement or decline pattern. Attack expectations have fluctuated over recent years, while human risk has remained a persistent concern and artificial intelligence has moved from an emerging technology topic to a central responsibility for security leaders. The report indicates that CISOs are gaining greater visibility within organisations while also being expected to manage a wider technology environment that includes cloud services, SaaS applications, identity systems, automation tools and AI platforms. This shift is changing the focus of cybersecurity leadership from simply preventing attacks to understanding where critical business activities occur, who has access to sensitive information and how data moves throughout the organisation. Artificial intelligence has become one of the most significant areas influencing cybersecurity strategies, according to the report. Proofpoint found that concerns among CISOs regarding Generative AI security risks increased from 54 percent in 2024 to 60 percent in 2025 and 78 percent in 2026. As organisations adopt AI assistants, copilots, automation solutions and agent based workflows, security leaders are facing the challenge of enabling innovation while maintaining appropriate controls. The report noted that 78 percent of CISOs said their organisations restrict or block employee use of Generative AI tools, compared with 59 percent in 2025. However, Proofpoint highlighted that restricting access alone may not address broader governance questions around data permissions, identity management, user access and AI driven decision making. The research suggests that AI security should be viewed as part of a wider data security strategy, focusing on what information AI systems can access, how users interact with these tools and what controls are required to protect sensitive resources. The report also found that 79 percent of CISOs are expected to manage AI related risks without receiving proportional increases in resources or expertise, creating additional pressure on security teams.

Human risk continues to be another major focus area in the five year analysis. Proofpoint reported that the percentage of CISOs identifying human risk or human error as a major cybersecurity vulnerability increased from 56 percent in 2022 to 79 percent in 2026. The report suggests that organisations need to view human risk as a broader operational challenge rather than only a training issue. Among organisations that experienced material data loss, 93 percent said departing employees played a role. Other leading causes of data loss included insider activity, compromised accounts, misuse or misconfiguration of AI tools, external attacks and third party security issues. These findings highlight the importance of managing access, permissions and user behaviour throughout the employee lifecycle, including during role changes, contractor access and employee departures. Security teams are increasingly required to understand user activity in context by assessing whether access levels remain appropriate and whether changes in behaviour indicate potential risks.

The report also examined the relationship between CISOs and organisational leadership, showing that cybersecurity has gained stronger attention at board level. Board alignment reached 85 percent in 2026, recovering from 64 percent in 2025 and representing one of the highest levels recorded in the report series. However, increased board engagement has also resulted in higher expectations for security leaders. Proofpoint found that 77 percent of CISOs believe excessive expectations are placed on the CISO or CSO role, compared with 66 percent in 2025 and 49 percent in 2022. Boards are increasingly focused on business outcomes, including company valuation, operational disruption, reputation, sensitive information protection, customer confidence and revenue impact. The findings show that cybersecurity discussions are becoming more closely connected with overall business risk management. Proofpoint’s research concludes that the future of cyber resilience will depend on protecting the environments where business activity actually takes place. This includes identity systems, collaboration platforms, cloud infrastructure, SaaS applications, endpoints, APIs and AI enabled technologies. For modern CISOs, the responsibility is expanding beyond traditional security controls toward managing risk across people, data and digital workflows. The report indicates that organisations will need stronger AI governance strategies, improved visibility into human risk and closer alignment between cybersecurity objectives and business priorities to operate securely in an increasingly connected technology environment.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img