VMTech
Discuss a project →

Proofpoint data tracks cyber risk’s shift into enterprise workflows

Proofpoint data tracks cyber risk’s shift into enterprise workflows

Proofpoint’s 2026 Voice of the CISO findings point to a change in where cyber risk is concentrated. The report says 78% of CISOs regard generative AI as a security risk, 79% name human risk or error as their largest cyber vulnerability, and 79% are expected to manage AI-related risks without a proportional rise in resources or expertise.

The five-year series does not describe a simple worsening or improvement in security. Fewer CISOs expected a material cyberattack in the next 12 months in 2026 than in 2025, and fewer reported material loss of sensitive information year on year. Yet more than half still reported such loss, while preparedness changed little.

AI governance becomes a workflow issue

Generative AI has moved rapidly from an emerging concern to a central security mandate. The share of CISOs calling it a risk rose from 54% in 2024 to 60% in 2025 and 78% in 2026. At the same time, 78% say their organisations block or restrict employee use of GenAI tools, up from 59% a year earlier.

Proofpoint argues that an allow-or-block approach is not sufficient once assistants, copilots, automations and agentic workflows are embedded in productivity suites, collaboration platforms and SaaS applications. The operational questions concern which data a user can reach, what an AI tool may summarise, generate or act upon, and what controls apply when a system influences a decision or triggers an action.

That shifts the discussion beyond prompts and models. In the report’s framing, AI risk involves sensitive information, identity, permissions, intent and control. It therefore links AI governance directly to data security and the capacity of security teams to oversee how work is performed.

Human risk remains persistent

Human risk or error was identified as the biggest vulnerability by 56% of respondents in 2022, 60% in 2023, 74% in 2024, 66% in 2025 and 79% in 2026. Among organisations that experienced material data loss, 93% said departing employees played a role.

The listed causes of material data loss include malicious or criminal insiders, careless insiders, compromised insiders, misuse or misconfiguration of AI tools, external attacks and third-party compromise. These findings place behaviour alongside identity, access, permissions, tooling and changing employment status rather than treating it solely as an awareness-training issue.

Boards are more aligned, while expectations increase

Board alignment also changed sharply across the period. The proportion of CISOs who said their board saw eye to eye with them on cybersecurity reached 85% in 2026, compared with 64% in 2025. But 77% also said excessive expectations were placed on the CISO or CSO, up from 66% in 2025 and 49% in 2022.

Boards are perceived to focus on business valuation, major downtime, reputational damage, sensitive-data loss, operational disruption, customer loss and revenue loss. For businesses, the practical implication is to measure and govern controls where work happens: across identities, collaboration services, SaaS, cloud repositories, endpoints, APIs, automation and AI systems. Security reporting can then connect exposure to operational and commercial consequences rather than treating these environments as separate control domains.

#cybersecurity#datasecurity#aigovernance#cisoleadership
Open analytics
On the site 0 views
min read 4 07.10.2026
Instagram

Proofpoint data tracks cyber risk’s shift into enterprise workflows

Open the post on Instagram ↗