Proofpoint 2026 Voice of the CISO Report Finds GenAI Security Concerns Rose
5th article in the last 90 days, one of 12 articles referencing Proofpoint. Previous coverage: Proofpoint Introduces SOC Analyst Agent With OpenAI Daybreak Models (Sep 2026).
Companies mentioned
Best suited for
- Seniority
- C Level / Executive Team
- Job function
- Chief Information Security Officer
- Persona
- Security Operations Leader
- Buyer role
- Decision Maker / Budget Holder
- Buyer journey
- Need to Buy
- Adoption curve
- Early Majority
- Technology maturity
- Market Correction
- Industry
- Information Technology / Software & Services / Cybersecurity / Governance, Risk & Compliance (GRC) & Security Ratings
Our classification, not the publisher's statement. Best suited for, not only for.
Proofpoint, Inc. released its 2026 Voice of the CISO report, based on a survey of more than 1,600 CISOs, showing changes in how cyber risk is viewed as AI responsibilities increase. The results reflect a shift in what organizations expect CISOs to manage over the next two years.
According to the report, the share of global CISOs who said their organization is at risk of a material cyberattack in the next 12 months fell to 61% from 76% in 2025. Reported material data loss also declined from 66% to 53%. At the same time, the survey found risk perception concentrating in areas tied to people, data, applications, and AI systems used in everyday work.
Human risk rose, with 79% of CISOs identifying it as their organization’s biggest cyber vulnerability, up from 66% in 2025. GenAI security concerns increased by 18 percentage points year over year, with 78% of CISOs viewing it as a security risk. The report also stated that 85% of CISOs expect enabling the safe use of AI assistants, copilots, and automation to be a top priority over the next two years.
Patrick Joyce, global resident CISO at Proofpoint, said, “AI is fundamentally changing the CISO mandate,” and that security leaders are being asked to protect the business from technology risk while enabling technology safely. The report also cited that 56% of CISOs still said their organization is unprepared to cope with a targeted cyberattack, and it reported higher business impacts among organizations experiencing material data loss, including increases in regulatory sanctions, financial losses, post-attack recovery costs, and reputational damage. “Improving resilience is an encouraging sign, but it doesn’t mean the risk environment is becoming less complex,” Joyce said.
Press release, provided by Globe Newswire on behalf of Proofpoint. Read the original.