Cyberattack concerns rise while CISO tasks broaden – report

The percentage of UK CISOs who believe their organisation is at risk of a material cyberattack in the next 12 months rose to 74%, up from 63% in 2025, while reported material data loss declined from 74% to 62%, according to a report by cybersecurity firm Proofpoint.

The global study of 1,600 CISOs across 16 countries found that risk is increasingly concentrated in the people, data, applications, and AI systems embedded in everyday work. Human risk is rising, with 69% of CISOs now identifying it as their organisation’s biggest cyber vulnerability, up from 60% in 2025. With that, the consequences of data loss are becoming more severe, and CISOs are assuming greater responsibility for enabling AI securely, with 72% expected to manage AI-related risks without a proportional increase in resources or expertise in the next two years.

Patrick Joyce, global resident CISO at Proofpoint, said: “AI is fundamentally changing the CISO mandate. Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly.

“As AI assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role.”

Among the key UK findings from the 2026 Voice of the CISO report, were rising concerns about UK GenAI security, with 71% of UK CISOs now viewing it as a security risk. At the same time, 80% say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years, while 72% are expected to manage AI-related risks without a proportional increase in resources or expertise.

Joyce added: “Improving resilience is an encouraging sign, but it doesn’t mean the risk environment is becoming less complex. Risk is increasingly tied to how people, data, applications, and AI interact every day, while CISOs are being asked to manage that exposure in business terms. The findings make clear that continued progress will depend on security strategies evolving alongside where both work and risk are headed.”



Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.