Proofpoint 2026 Voice of the CISO Report Finds 93% of CISOs in India Rank Human Risk as Biggest Vulnerability, as AI Expands Their Mandate

VOTC_2026_Press-Release

More than nine in ten CISOs are expected to manage AI-related risks without a proportional increase in resources or expertise

BANGALORE, INDIA – September 9, 2026 – Proofpoint, Inc., a global leader in human and agent cybersecurity, today released its 2026 Voice of the CISO report, revealing signs of greater cyber resilience even as the nature of enterprise risk increases in complexity. The percentage of Indian CISOs who believe their organization is at risk of a material cyberattack in the next 12 months remains high, increased from 90% in 2025 to 94% in 2026, although reported material data loss declined from 99% to 76%.

Yet progress has not made the CISO’s job simpler. The global study of 1,600 CISOs across 16 countries finds risk increasingly concentrated in the people, data, applications, and AI systems embedded in everyday work. Human risk is rising, with 93% of Indian CISOs identifying human risk as their organization's biggest cyber vulnerability, up from 67% in 2025. With that, the consequences of data loss are becoming more severe, and CISOs in India are assuming greater responsibility for enabling AI securely—with 92% expected to manage AI-related risks without a proportional increase in resources or expertise in the next two years.

“AI is fundamentally changing the CISO mandate,” said Patrick Joyce, global resident CISO at Proofpoint. “Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role.”

“In India, the cybersecurity conversation has evolved beyond catching threats faster. It’s now about securely enabling the safe use of AI at an unprecedented speed, and CISOs in India are expected to act as business enablers under this intense pressure. With employee behavior overtaking all other risk factors and AI reshaping daily workflows, the priority for security leaders must be establishing intent-based controls that protect people, data, and AI without slowing down innovation,” said Bikramdeep Singh, Vice President, India & SAARC, Proofpoint.

Key India findings from the 2026 Voice of the CISO report include:

  • CISOs are now expected to secure and champion AI. Indian GenAI security concerns jumped 17 percentage points year-over-year, with 92% of Indian CISOs now viewing it as a security risk. At the same time, 92% say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years. However, more than nine in ten (92%) are expected to manage AI-related risks without a proportional increase in resources or expertise.
  • Cyber resilience improves, but the risk model is changing. Expectations of a material cyberattack among Indian CISOs rose from 90% in 2025 to 94% in 2026, while material data loss declined from 99% to 76%. Yet more than three-quarters (77%) of Indian CISOs still say their organization is unprepared to cope with a targeted cyberattack. Concern is increasingly centered on technologies embedded in everyday work, including AI assistants, copilots, or autonomous agents (42%), collaboration platforms (34%), active Directory / Identity infrastructure (34%), SaaS applications and third-party integrations (31%), and public generative AI tools (30%).
  • The biggest risk is employee behavior. 93% of Indian CISOs identify human risk as their organization's biggest cyber vulnerability, up from 67% in 2025. Among organizations that experienced material data loss, malicious or criminal insiders were the leading cause (47%), while 41% cited careless insiders as the leading factor and 38% claimed compromised insiders as the source. Notably, 82% of Indian CISOs at organizations experiencing material data loss say departing employees played a role.
  • CISOs trust their defenses, but not their own employees' AI habits. While 94% of Indian CISOs believe their controls effectively mitigate risks introduced by AI, SaaS, and modern work patterns, almost four in five (79%) believe employees are likely to use AI in ways that could expose sensitive data. 88% are concerned about customer data loss through public GenAI tools, and consequently 91% block or restrict employee GenAI use.
  • Data loss declines, but the consequences grow. While the proportion of Indian organizations experiencing material data loss declined year-over-year, from 99% in 2025 to 76% in 2026, the business impact for those that did suffer data loss became more severe. Regulatory sanctions rose from 34% to 45%, while financial losses increased from 29% to 43%. Post-attack recovery costs rose from 28% to 45%, and reputational damage increased from 33% to 39%.
  • Boards are listening to CISOs more and expecting more in return. 93% of Indian CISOs say they see eye-to-eye with their boards on cybersecurity, up significantly from 72% in 2025. But greater alignment is not reducing pressure on security leaders. Boards are evaluating cyber risk through a commercial lens, with enterprise value, downtime, reputational damage, operational disruption, and sensitive data loss among their top concerns. 87% of Indian CISOs say excessive expectations are placed on them. More than nine in ten CISOs (94%) believe cybersecurity expertise should be required at the board-director level, up from 64% in 2025.

“Improving resilience is an encouraging sign, but it doesn’t mean the risk environment is becoming less complex,” said Patrick Joyce. “Risk is increasingly tied to how people, data, applications, and AI interact every day. Within this context, CISOs are being asked to manage that exposure in business terms. The findings make clear that continued progress will depend on security strategies evolving alongside with everyday workflow and risk factors.

To download the full 2026 Voice of the CISO report, visit https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report.

Methodology

The 2026 Voice of the CISO report polled over 1,600 CISOs at organizations with 1,000 employees or more across different industries. 100 CISOs were interviewed in each market across the following 16 countries: the United States, Canada, Brazil, Mexico, the United Kingdom, France, Germany, Italy, Spain, the Netherlands, the United Arab Emirates, the Kingdom of Saudi Arabia, Australia, Japan, Singapore, and India. The research was conducted by Censuswide in May 2026.

About Proofpoint, Inc.

Proofpoint, Inc. is a global leader in human and agent cybersecurity, securing how people, data, and AI agents connect across email, cloud, and collaboration tools. Proofpoint is a trusted partner to over 80 of the Fortune 100, over 14,000 large enterprises, and millions of smaller organizations in stopping threats, preventing data loss, and building resilience across people and AI workflows. Proofpoint's collaboration, data, and AI security platform helps organizations of all sizes protect their people and adopt AI securely and confidently. Learn more at www.proofpoint.com.

 
Connect with Proofpoint on LinkedIn

Proofpoint is a registered trademark or tradename of Proofpoint, Inc. in the U.S. and/or other countries. All other trademarks contained herein are the property of their respective owners.