Proofpoint 2026 Voice of the CISO Report Finds Cyber Resilience Improving, While AI Expands the CISO Mandate

VOTC_2026_Press-Release

GenAI security concerns jump 13 points to 71% as UK CISOs take on growing AI responsibilities without proportional resources

Proofpoint, Inc., a global leader in human and agent cybersecurity, today released its 2026 Voice of the CISO report, revealing signs of greater cyber resilience even as the nature of enterprise risk increases in complexity. The percentage of UK CISOs who believe their organisation is at risk of a material cyberattack in the next 12 months rose to 74%, up from 63% in 2025, while reported material data loss  declined from 74% to 62%.

Yet progress has not made the CISO’s job simpler. The global study of 1,600 CISOs across 16 countries finds risk increasingly concentrated in the people, data, applications, and AI systems embedded in everyday work. Human risk is rising, with 69% of CISOs now identifying it as their organisation’s biggest cyber vulnerability, up from 60% in 2025. With that, the consequences of data loss are becoming more severe, and CISOs are assuming greater responsibility for enabling AI securely—with 72% expected to manage AI-related risks without a proportional increase in resources or expertise in the next two years.

“AI is fundamentally changing the CISO mandate,” said Patrick Joyce, global resident CISO at Proofpoint. “Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role.”

Key UK findings from the 2026 Voice of the CISO report include:

  • CISOs are now expected to secure and champion AI. UK GenAI security concerns jumped 13 percentage points year-over-year, with 71% of UK CISOs now viewing it as a security risk. At the same time, 80% say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years, while 72% are expected to manage AI-related risks without a proportional increase in resources or expertise.
  • Cyber resilience improves, but the risk model is changing. Expectations of a material cyberattack among UK CISOs rose from 63% in 2025 to 74% in 2026, while material data loss declined from 74% to 62%. Yet 61% of UK CISOs still say their organisation is unprepared to cope with a targeted cyberattack. Concern is increasingly centred on technologies embedded in everyday work, including SaaS applications and third-party integrations (33%), Collaboration platforms (32%), Active Directory / Identity infrastructure (32%), Perimeter network devices (32%), and AI assistants, copilots, or autonomous agents (30%).
  • The biggest risk is employee behaviour. 69% of UK CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 60% in 2025. Among organisations that experienced material data loss, compromised insiders were the leading cause (48%), while malicious or criminal insiders were cited by 44% and careless insiders by 37%. Notably, 95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.
  • Data loss declines, but the consequences grow. While the proportion of UK organisations experiencing material data loss declined year-over-year — from 74% in 2025 to 62% in 2026 — the business impact for those that did suffer data loss became more severe. Regulatory sanctions rose from 30% to 35%, while financial losses increased from 24% to 40%. Post-attack recovery costs rose from 26% to 36%, and reputational damage increased from 36% to 45%.
  • CISOs trust their defences, but not their own employees' AI habits. While 87% of UK CISOs believe their controls effectively mitigate risks introduced by AI, SaaS, and modern work patterns, 66% believe employees are likely to use AI in ways that could expose sensitive data. 71% are concerned about customer data loss through public GenAI tools, and 72% block or restrict employee GenAI use.
  • Boards are listening to CISOs more and expecting more in return. 87% of UK CISOs say they see eye-to-eye with their boards on cybersecurity, up significantly from 57% in 2025. But greater alignment is not reducing pressure on security leaders. Boards are evaluating cyber risk through a commercial lens, with enterprise value, downtime, reputational damage, operational disruption, and sensitive data loss among their top concerns. 74% of UK CISOs say excessive expectations are placed on them. 85% believe cybersecurity expertise should be required at the board-director level, up from 63% in 2025.

“Improving resilience is an encouraging sign, but it doesn’t mean the risk environment is becoming less complex,” said Patrick Joyce. “Risk is increasingly tied to how people, data, applications, and AI interact every day, while CISOs are being asked to manage that exposure in business terms. The findings make clear that continued progress will depend on security strategies evolving alongside where both work and risk are headed.”

To download the full 2026 Voice of the CISO report, visit https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report.

To learn more about the report’s findings, register for the 2026 Voice of the CISO webinar, taking place on Wednesday 14th October 2026 at 10am BST/11am CEST: https://www.proofpoint.com/uk/resources/webinars/2026-voice-ciso.

Methodology

The 2026 Voice of the CISO report polled over 1,600 CISOs at organisations with 1,000 employees or more across different industries. 100 CISOs were interviewed in each market across the following 16 countries: the United States, Canada, Brazil, Mexico, the United Kingdom, France, Germany, Italy, Spain, the Netherlands, the United Arab Emirates, the Kingdom of Saudi Arabia, Australia, Japan, Singapore, and India. The research was conducted by Censuswide in May 2026.

About Proofpoint, Inc.

Proofpoint, Inc. is a global leader in human and agent cybersecurity, securing how people, data, and AI agents connect across email, cloud, and collaboration tools. Proofpoint is a trusted partner to over 80 of the Fortune 100, over 14,000 large enterprises, and millions of smaller organisations in stopping threats, preventing data loss, and building resilience across people and AI workflows. Proofpoint’s collaboration, data, and AI security platform helps organisations of all sizes protect and empower their people and adopt AI securely and confidently. Learn more at www.proofpoint.com.

 
Connect with Proofpoint on LinkedIn

Proofpoint is a registered trademark or tradename of Proofpoint, Inc. in the U.S. and/or other countries. All other trademarks contained herein are the property of their respective owners.