Cybersecurity leaders may be feeling somewhat more confident about their defenses, but that does not mean their jobs are getting easier.
Instead, the risks CISOs manage are moving deeper into the technology employees use every day. Identity and everyday workflows are also becoming a greater part of that risk.
That is one of the clearest findings from Proofpoint’s 2026 Voice of the CISO report, which surveyed 1,600 CISOs across 16 countries.
The report found that fewer security leaders expect a material cyberattack or report significant data loss than last year.
At the same time, artificial intelligence (AI) and human risk are creating new challenges as board expectations continue to grow.
AI becomes the defining CISO challenge
Generative AI (GenAI) has quickly moved from an emerging concern to a core security responsibility.
Approximately 78% of CISOs now consider GenAI a security risk, up from 60% in 2025. Another 77% are concerned about customer data being lost through public GenAI tools.
At the same time, 85% say enabling the safe use of AI assistants and copilots is a top priority over the next two years. That priority also extends to automation technologies.
This creates a difficult balancing act. CISOs are expected to protect data without preventing employees from using tools that can improve productivity.
Many organizations are responding by restricting access. The report showed that 78% of companies block or restrict employee GenAI use, compared with 59% last year. But restrictions alone become harder to enforce as AI functionality is built directly into SaaS platforms and everyday workflows.
The resource gap may be an even bigger concern because 79% of CISOs said they are expected to manage AI-related risks without a proportional increase in resources or expertise.
Cyber risk shifts toward everyday workplace technology
There are also signs that security programs are making progress.
Approximately 61% of CISOs believe their organization faces a material cyberattack within the next 12 months, down from 76% in 2025.
Material data loss also declined from 66% to 53%. However, 56% still say their organization is unprepared to handle a targeted cyberattack.
What worries CISOs is changing as well. Cloud account takeover or compromise was the most commonly selected threat at 33%. Collaboration platforms ranked highest among technologies CISOs worry could introduce risk, followed closely by AI assistants or agents and SaaS applications with third-party integrations.
Human risk becomes a data security problem
Technology is only part of that equation. Human risk was identified by 79% of CISOs as their organization’s biggest cyber vulnerability, up from 66% last year.
Among organizations experiencing material data loss, malicious or criminal insiders were the leading root cause at 46%. Careless and compromised insiders were each cited by 38%, while AI misuse or misconfiguration followed at 37%.
Departing employees deserve particular attention as 93% of CISOs at organizations that experienced material data loss said departing employees played a role.
Fewer data loss incidents carry greater consequences
The decline in reported data loss also hides another problem. Incidents that do occur appear to be becoming more costly to businesses.
Among affected organizations, regulatory sanctions increased from 34% to 40%, while financial losses jumped from 27% to 38%. Recovery costs reached 38%, and reputational damage rose to 37%.
Boards are paying attention, with 85% of CISOs saying their boards see eye to eye with them on cybersecurity, up from 64% in 2025. However, 77% also said excessive expectations are being placed on the CISO or CSO.
The takeaway for CISOs is that progress in traditional security does not necessarily reduce their workload.
AI governance and identity are increasingly interconnected with human behavior. Data protection cuts across each of those areas.
The next step is turning visibility into controls that protect sensitive data as it moves between users and applications. Those controls also need to extend across cloud services and AI-enabled workflows.
Implementing zero trust solutions can help organizations strengthen those controls by continuously verifying access to sensitive data and applications. The same approach can help protect access to cloud resources.





