Pressure Mounts on Australian Security Leaders as Cyber Fears Rise and AI Mandates Expand
Proofpoint 2026 Voice of the CISO reveals nearly four in five CISOs in Australia are taking on expanding AI responsibilities without proportional resources
SYDNEY, Australia – 9 September 2026 – Proofpoint, Inc., a global leader in human and agent cybersecurity, today released its 2026 Voice of the CISO report, revealing that local security leaders are facing compounding pressure as enterprise risk, AI responsibilities, and the financial fallout of data breaches escalate across Australia.
The global study of 1,600 CISOs across 16 countries, including Australia, finds risk is increasingly concentrated in the people, data, applications, and AI systems embedded in everyday work. More than four in five (85%) Australian CISOs now view Generative AI as a security risk with 89% reporting that enabling safe AI use is a top priority over the next two years. However, 79% of Australian CISOs report managing these expanding AI risks without a proportional increase in resources or expertise.
As a result, threat anxiety among Australian organisations remains high. 78% of Australian CISOs believe their organisation is at risk of a material cyberattack in the next 12 months, similar to 77% last year, and more than two-thirds (68%) say their organisation remains unprepared to cope with a targeted attack.
Compounding this anxiety is the escalating cost of failure. While the proportion of Australian organisations experiencing material data loss fell from 76% to 68%, the business impact for those hit by data breaches has become far more severe. Direct financial losses nearly tripled from 18% to 49%, while regulatory sanctions jumped from 29% to 46%, drastically raising the stakes for local cyber leaders.
“AI is fundamentally changing the CISO mandate,” said Patrick Joyce, global resident CISO at Proofpoint. “Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role.”
Meanwhile, human behaviour continues to drive organisational vulnerability. More than four in five (83%) Australian CISOs identify human risk as their greatest cyber threat, now amplified by the rapid adoption of generative AI. CISO concerns are increasingly centred on technologies embedded in everyday work, including public generative AI tools, AI assistants, copilots, or autonomous agents.
“The human element remains the biggest cyber vulnerability for Australian organisations, but AI is changing what that risk looks like, which is increasingly about how people interact with AI, data and the applications they use every day,” said Adrian Covich, Vice President, Systems Engineering, Asia-Pacific & Japan for Proofpoint. “For Australian organisations, this shift requires a different approach to cybersecurity, which need to understand behaviour and intent, rather than relying solely on policies or perimeter-based controls. As AI becomes embedded in our workspace, protecting data means securing the decisions and actions of both human and AI across the data lifecycle.”
Key Australian findings from the 2026 Voice of the CISO report include:
- CISOs are now expected to secure and champion AI: Australian GenAI security concerns rose 9 percentage points year-over-year, with 85% of Australian CISOs now viewing it as a security risk. At the same time, 89% say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years, while 79% are expected to manage AI-related risks without a proportional increase in resources or expertise.
- Cyber resilience improves, but the risk model is changing: Expectations of a material cyberattack among Australian CISOs rose very slightly from 77% in 2025 to 78% in 2026, while material data loss declined from 76% to 68%. Yet 68% of Australian CISOs still say their organisation is unprepared to cope with a targeted cyberattack. Concern is increasingly centred on technologies embedded in everyday work, including public generative AI tools (41%), SaaS applications and third-party integrations (37%), collaboration platforms (35%), AI assistants, copilots, or autonomous agents (33%), and cloud storage and file-sharing platforms (33%).
- The biggest risk is employee behaviour: More than four in five (83%) Australian CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 72% in 2025. Among organisations that experienced material data loss, compromised insiders were the leading cause (50%), while careless insiders were cited by 47% and malicious or criminal insiders by 44%. Notably, 90% of Australian CISOs at organisations experiencing material data loss say departing employees played a role.
- Data loss declines, but the consequences grow: While the proportion of Australian organisations experiencing material data loss declined year-over-year — from 76% in 2025 to 68% in 2026 — the business impact for those that did suffer data loss became more severe. Regulatory sanctions rose from 29% to 46%, while financial losses increased from 18% to 49%. Post-attack recovery costs rose from 26% to 43%, and reputational damage increased from 21% to 37%.
- CISOs don’t trust their own employees' AI habits: 83% of Australian CISOs believe employees are likely to use AI in ways that could expose sensitive data. More than three-quarters (78%) are concerned about customer data loss through public GenAI tools, and 84% block or restrict employee GenAI use.
- Boards are listening to CISOs more and expecting more in return: 91% of Australian CISOs say they see eye-to-eye with their boards on cybersecurity, up from 82% in 2025. But greater alignment is not reducing pressure on security leaders. Boards are evaluating cyber risk through a commercial lens, with enterprise value, downtime, reputational damage, operational disruption, and sensitive data loss among their top concerns. 83% of Australian CISOs say excessive expectations are placed on them. 90% believe cybersecurity expertise should be required at the board-director level, up from 77% in 2025.
To download the full 2026 Voice of the CISO report, visit https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report.
Methodology
The 2026 Voice of the CISO report polled over 1,600 CISOs at organisations with 1,000 employees or more across different industries. 100 CISOs were interviewed in each market across the following 16 countries: the United States, Canada, Brazil, Mexico, the United Kingdom, France, Germany, Italy, Spain, the Netherlands, the United Arab Emirates, the Kingdom of Saudi Arabia, Australia, Japan, Singapore, and India. The research was conducted by Censuswide in May 2026.
About Proofpoint, Inc.
Proofpoint, Inc. is a global leader in human and agent cybersecurity, securing how people, data, and AI agents connect across email, cloud, and collaboration tools. Proofpoint is a trusted partner to over 80 of the Fortune 100, over 14,000 large enterprises, and millions of smaller organisations in stopping threats, preventing data loss, and building resilience across people and AI workflows. Proofpoint’s collaboration, data, and AI security platform helps organisations of all sizes protect their people and adopt AI securely and confidently. Learn more at www.proofpoint.com.
Connect with Proofpoint on LinkedIn
Proofpoint is a registered trademark or tradename of Proofpoint, Inc. in the U.S. and/or other countries. All other trademarks contained herein are the property of their respective owners.