Brian Sims
Editor
Brian Sims
Editor
PROOFPOINT HAS published its 2026 Voice of the CISO Report, duly revealing signs of greater cyber resilience even as the nature of enterprise risk increases in complexity. The percentage of UK Chief Information Security Officers (CISOs) who believe their organisation is at risk of a material cyber attack in the next 12 months has risen to 74% (up from 63% in 2025), while reported material data loss shows a decline from 74% to 62%.
That said, progress has not made the CISO’s job simpler. The global study of 1,600 CISOs operating across 16 countries finds risk increasingly concentrated in the people, data, applications and Artificial Intelligence (AI) systems embedded in everyday work.
Human risk is rising, with 69% of CISOs now identifying it as their organisation’s biggest cyber vulnerability (up from 60% in 2025). With that, the consequences of data loss are becoming more severe.
CISOs are assuming greater responsibility for enabling AI securely, with 72% of them expected to manage AI-related risks without a proportional increase in resources or expertise in the next two years.
“AI is fundamentally changing the CISO mandate,” affirmed Patrick Joyce, global resident CISO at Proofpoint. “Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation, while preventing sensitive data, privileged access and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role.”
Key findings
Key UK findings from the 2026 Voice of the CISO Report include the following:
CISOs are now expected to secure and champion AI
UK GenAI security concerns jumped 13 percentage points year-over-year, with 71% of UK CISOs now viewing it as a security risk. At the same time, 80% state that enabling the safe use of AI assistants, copilots and automation is a top priority over the next two years, while 72% are expected to manage AI-related risks without a proportional increase in resources or expertise.
Cyber resilience improves, but the risk model is changing
Expectations of a material cyber attack among UK CISOs rose from 63% in 2025 to 74% in 2026, while material data loss declined from 74% to 62%. Yet 61% of UK CISOs still say their organisation is unprepared to cope with a targeted cyber attack.
Concern is increasingly centred on technologies embedded in everyday work, including SaaS applications and third party integrations (33%), collaboration platforms (32%), Active Directory/identity infrastructure (32%), perimeter network devices (32%) and AI assistants, copilots, or autonomous agents (30%).
The biggest risk is employee behaviour
69% of UK CISOs identify human risk as their organisation’s biggest cyber vulnerability. That’s up from 60% in 2025. Among organisations that experienced material data loss, compromised insiders were the leading cause (48%), while malicious or criminal insiders were cited by 44% and careless insiders by 37%. Notably, 95% of UK CISOs at organisations experiencing material data loss confirm that departing employees played a role.
Data loss declines, but the consequences grow
While the proportion of UK organisations experiencing material data loss declined year-over-year (from 74% in 2025 to 62% in 2026), the business impact for those that did suffer data loss became more severe.
Regulatory sanctions rose from 30% to 35%, while financial losses increased from 24% to 40%. Post-attack recovery costs rose from 26% to 36% and reputational damage increased from 36% to 45%.
CISOs trust their defences, but not their own employees’ AI habits
While 87% of UK CISOs believe their controls effectively mitigate the risks introduced by AI, SaaS and modern work patterns, 66% believe employees are likely to use AI in ways that could expose sensitive data. 71% are concerned about customer data loss through public GenAI tools. 72% block or otherwise restrict employee GenAI use.
Boards are listening to CISOs more and expecting more in return
87% of UK CISOs see eye-to-eye with their Boards of Directors on cyber security, which is up significantly from 57% last year, but greater alignment is not reducing pressure on security leaders.
Boards of Directors are evaluating cyber risk through a commercial lens, with enterprise value, downtime, reputational damage, operational disruption and sensitive data loss among their top concerns. 74% of UK CISOs note that excessive expectations are placed on them. 85% believe cyber security expertise should be required at the Board-director level. That’s up from 63% in 2025.
“Improving resilience is an encouraging sign, but it doesn’t mean the risk environment is becoming less complex,” concluded Patrick Joyce. “Risk is increasingly tied to how people, data, applications and AI interact every day, while CISOs are being asked to manage that exposure in business terms. The findings of this study make it clear that continued progress will depend on security strategies evolving alongside where both work and risk are headed.”
*Download the 2026 Voice of the CISO Report by visiting www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report
**Learn more about the study’s findings by registering for the 2026 Voice of the CISO webinar, which is taking place on 14 October at 10.00 am BST/11.00 am CEST: https://www.proofpoint.com/uk/resources/webinars/2026-voice-ciso
Western Business Media Limited
Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM