Tue, 15 Sep 2026

AI expands the CISO mandate despite stronger resilience

Cyber resilience appears to be improving, but the security risks surrounding artificial intelligence, human behaviour and everyday business applications are placing new demands on CISOs, according to Proofpoint’s 2026 Voice of the CISO report.

Source: 2026 Voice of CISO Report, Proofpoint

The global study of more than 1,600 CISOs across 16 countries found that the proportion expecting their organisation to suffer a material cyberattack within the next 12 months fell to 61%, from 76% in 2025. Organisations reporting material data loss also declined, from 66% to 53%.

However, 56% of CISOs said their organisations remained unprepared to deal with a targeted cyberattack. Proofpoint said the risk model is shifting towards the people, data, applications and AI systems embedded in day-to-day work.

Collaboration platforms were identified as a concern by 34% of respondents, followed by AI assistants, copilots and autonomous agents at 33%, SaaS applications and third-party integrations at 33%, public GenAI tools at 31%, and cloud storage and file-sharing platforms at 30%.

GenAI security concerns rose by 18 percentage points year on year, with 78% of CISOs now identifying the technology as a security risk. At the same time, 85% said enabling the safe use of AI assistants, copilots and automation would be a priority over the next two years. Yet 79% expected to manage AI-related risks without a proportional increase in resources or expertise.

“AI is fundamentally changing the CISO mandate,” said Patrick Joyce, global resident CISO at Proofpoint. “Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly.”

Related:  Commvault embeds cyber recovery actions into CrowdStrike Charlotte SOAR workflows

Human behaviour remains a leading weakness. The proportion of CISOs identifying human risk as their organisation’s biggest cyber vulnerability rose to 79%, from 66% in 2025.

Among organisations that experienced material data loss, malicious or criminal insiders were cited by 46%, while careless and compromised insiders were each cited by 38%. Departing employees played a role in data loss at 93% of affected organisations.

Although fewer organisations experienced data loss, the consequences became more severe. Regulatory sanctions rose to 40%, financial losses to 38%, recovery costs to 38% and reputational damage to 37%.

The findings have implications for cyber recovery in Asia in 2026 and 2027. INTERPOL recorded more than 135,000 ransomware-related attacks across Asia and the South Pacific in 2024, with system intrusions accounting for about 80% of data breaches.

Recovery strategies will therefore need to address identity, insider risk, AI-enabled workflows and third-party platforms, alongside backups and infrastructure restoration.

Proofpoint’s findings suggest that recovery readiness will increasingly depend on knowing what data AI tools can access, rapidly revoking compromised permissions and rehearsing recovery across cloud, SaaS and collaboration environments.

Related Stories

MORE STORIES