Proofpoint’s annual 2026 Voice of the CISO report provides security leaders a global benchmark for the priorities, pressures, and trade-offs shaping the role and function of the CISO. Based on a survey of 1,600 CISOs across 16 markets, the 2026 report captures a decisive shift; security programs are making progress against familiar threats, but the center of risk is moving into the tools and workflows people use every day to both get their jobs done and to innovate across enterprises.
This is not a simple story of more threats or less risk. AI, human behavior, data movement, and business scrutiny are rewriting the CISO mandate, and governance must catch up.
Progress is real—but it should not be mistaken for safety
There are encouraging signs from this year’s survey and report. In 2026, 61% of CISOs believe their organization is likely to experience a material cyberattack in the next 12 months, down from 76% in 2025. Reported material data loss also declined, from 66% to 53%.
But confidence has not translated into readiness. More than half (56%) still say their organization is unprepared for a targeted cyberattack. And while concern about ransomware, malware, and email fraud has fallen, cloud account takeover or compromise now ranks as the most-cited threat.
The lesson is not that traditional threats have disappeared. Risk is shifting into the places where work happens; identities, collaboration platforms, SaaS applications, cloud file-sharing tools, AI assistants, and automated workflows. Security must protect these environments without becoming an obstacle to the business.
AI is now both a security and enablement mandate
AI is the clearest expression of this shift. In 2026, 78% of CISOs view GenAI as a security risk, up measurably from 60% last year. Yet 85% say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years.
Security teams are expected to help the business adopt AI while at the same time protecting sensitive data, privileged access, and critical processes. Restrictions may be necessary—78% of organizations block or limit employee use of GenAI—but guardrails and hurdles cannot comprise the entire strategy as AI becomes embedded in everyday applications.
The harder work is governance; understanding which tools are in use, what data the tools can reach, who is using them, and whether policy can be enforced in context. Meanwhile, 79% of CISOs are expected to manage AI-related risks without a proportional increase in resources or expertise. AI ambition is accelerating faster than many security operating models can adapt.
Human risk is now a core data security challenge
Human risk is no longer a separate awareness issue. In 2026, 79% of CISOs identify it as their organization’s biggest cyber vulnerability, up from 66% in just a year’s time.
The causes of material data loss reinforce the point. Malicious or criminal insiders are the leading cause at 46%, while careless and compromised insiders are each cited at 38%. Misuse or misconfiguration of AI tools follows at 37%. Among organizations that actually experienced material data loss, 93% say departing employees played a role.
A human-centric security approach must connect training with controls that account for behavior, identity, permissions, data sensitivity, and intent. Protecting information across the full employee lifecycle—from onboarding through offboarding—is essential.
Fewer incidents can still create greater business damage
The decline in reported data loss is a positive metric, but the consequences of the loss are becoming more severe. Of those surveyed, those citing consequences of regulatory sanctions rose to 40%, financial loss increased to 38%, post-attack recovery costs reached 38%, and reputational damage climbed to 37%.
For CISOs, frequency and severity can move in different directions. A lower incident count does not necessarily mean lower enterprise risk or reduced impact. Boards are increasingly viewing cyber events through a commercial lens, with business valuation, downtime, reputation, sensitive information, and operational disruption among their leading concerns.
That makes translating security exposure into business impact a core leadership skill. Data loss can affect market value, customer trust, operational resilience, and regulatory standing.
Board alignment is improving—and raising the bar
Encouragingly, 85% of CISOs surveyed say their board sees eye to eye with them on cybersecurity, up from 64% last year. Meanwhile, 86% believe cybersecurity expertise should be required by directors in the boardroom.
Better alignment creates opportunity, but it doesn’t reduce pressure. In 2026, 77% say excessive expectations are placed on the CISO or CSO. Burnout exposure has eased slightly down to 57%, but it remains high. The report also reveals a mismatch: 86% say they have adequate general resources to meet cybersecurity goals, while 79% say AI risk has not been matched with proportional resources or expertise.
Expanding the CISO mandate must be matched with authority, specialist capability, and cross-functional ownership. AI governance, data protection, and human risk cannot be owned by security alone.
Final thoughts
The full report is worth reading because global averages are only part of the story. The report’s country and sector findings illustrate that attack expectations, data loss, AI exposure, and board priorities vary significantly, giving CISOs a better benchmark for challenging assumptions and focusing investment. It also gives security leaders evidence for board, budget, and cross-functional governance discussions.
My strongest takeaway is that cyber risk has moved deeper into the methods and processes for how business gets done. People, identities, data, applications, and AI-enabled systems are now inseparable—they function as a system. The organizations best positioned for the next phase will secure work as it happens, govern AI as it scales, and give CISOs the support required to lead both resilience and responsible innovation.
Download the full 2026 Voice of the CISO report.
Register for our upcoming Voice of the CISO webinar to review our key findings and get live insights from CISOs.