Skip to main content

Proofpoint 2026 Voice of the CISO Report Finds GenAI Security Concerns Rose

5th article in the last 90 days, one of 12 articles referencing Proofpoint. Previous coverage: Proofpoint Introduces SOC Analyst Agent With OpenAI Daybreak Models (Sep 2026).

Companies mentioned

Best suited for

Seniority
C Level / Executive Team
Job function
Chief Information Security Officer
Persona
Security Operations Leader
Buyer role
Decision Maker / Budget Holder
Buyer journey
Need to Buy
Adoption curve
Early Majority
Technology maturity
Market Correction
Industry
Information Technology / Software & Services / Cybersecurity / Governance, Risk & Compliance (GRC) & Security Ratings

Our classification, not the publisher's statement. Best suited for, not only for.

Proofpoint, Inc. released its 2026 Voice of the CISO report, based on a survey of more than 1,600 CISOs, showing changes in how cyber risk is viewed as AI responsibilities increase. The results reflect a shift in what organizations expect CISOs to manage over the next two years.

According to the report, the share of global CISOs who said their organization is at risk of a material cyberattack in the next 12 months fell to 61% from 76% in 2025. Reported material data loss also declined from 66% to 53%. At the same time, the survey found risk perception concentrating in areas tied to people, data, applications, and AI systems used in everyday work.

Human risk rose, with 79% of CISOs identifying it as their organization’s biggest cyber vulnerability, up from 66% in 2025. GenAI security concerns increased by 18 percentage points year over year, with 78% of CISOs viewing it as a security risk. The report also stated that 85% of CISOs expect enabling the safe use of AI assistants, copilots, and automation to be a top priority over the next two years.

Patrick Joyce, global resident CISO at Proofpoint, said, “AI is fundamentally changing the CISO mandate,” and that security leaders are being asked to protect the business from technology risk while enabling technology safely. The report also cited that 56% of CISOs still said their organization is unprepared to cope with a targeted cyberattack, and it reported higher business impacts among organizations experiencing material data loss, including increases in regulatory sanctions, financial losses, post-attack recovery costs, and reputational damage. “Improving resilience is an encouraging sign, but it doesn’t mean the risk environment is becoming less complex,” Joyce said.

Press release, provided by Globe Newswire on behalf of Proofpoint. Read the original.