A report shows CISOs face increased pressures related to cyber resilience and business continuity.
Chief information security officers are largely expected to ensure the security of AI across the enterprise, but many say they are not receiving adequate support, according to findings from Proofpoint.
About 85% of CISOs said ensuring the safe use of AI assistants, copilots and automation is a top priority over the next two years, according to Proofpoint’s annualVoice of the CISOreport. Eight of every 10 CISOs said they are expected to manageAI-related security riskswithout receiving a proportional increase in resources or expertise.
“CISOs have a significant role to play in securing AI adoption, but they can’t own the risk alone,” Patrick Joyce, global resident CISO at Proofpoint, told Cybersecurity Dive. “AI is being adopted across the business, often faster than traditional governance models can keep up.”
Cyber risk posture
The global survey of 1,600 CISOs highlights important changes in overall risk and the CISO relationship with the C-suite. The survey, conducted by Censuswide, included 100 CISOs at major companies in 16 countries across the globe, from the U.S., the U.K., India, Japan and other countries.
CISOs overall have gained confidence in their organization’s risk posture, however. About six out of 10 CISOs expressed concerns about a material cyberattack, compared to about three-quarters in the 2025 survey. Still, more than half of CISOs fear their organization would be unable to manage a targeted cyberattack.
About 85% of CISOs said they are largely aligned with their corporate boards on security issues, a significant increase from a year ago, where less than two-thirds of CISOs were aligned. Despite that improvement, nearly 8 of every 10 CISOs said they are facing excessive pressure from their boards on issues ranging from operational disruption and data loss to reputational risk.
“The CISO is increasingly expected to protect the business, enable AI, safeguard data, manage regulatory risk, support business continuity and explain all of that in commercial terms to the board,” Joyce said.
AI exposure
Among the biggest worries for CISOs is employee use of generative AI. A total of 78% of CISOs now consider GenAI a major security risk, representing an 18% increase from the prior year.
About 86% of CISOs believe their internal security controls provide adequate security protection over risks presented by AI, software-as-a-service and modern work patterns. Despite that confidence, more than 75% of CISOs fear that employees are using AI in a way that could expose sensitive company data.
In addition to the concerns about AI, CISOs have larger concerns regarding employee behavior. About 8 of every 10 CISOs consider human behavior as the biggest cyber vulnerability within their organization, up from 66% a year ago. Among organizations that experienced a material data loss over the past year, about 46% said the loss was related to a malicious or criminal insider.
Filed Under:Threats,Leadership & Careers
