Getty Images

CISOs more confident -- and more stressed -- than ever

Security leaders are growing more confident in their abilities to withstand cyberattacks, yet the pressure on them continues to build. Proofpoint's latest survey of CISOs explains why.

With increasing concerns about AI and other emerging threats, you might assume more chief information security officers expect their organizations to face a major cyberattack this year.

You would be wrong.

According to Proofpoint's "2026 Voice of the CISO" report, the proportion of CISOs who believe their company is at significant risk of an attack dropped to 61%, down from 76% in 2025. Reports of consequential data loss also fell from 66% to 53%.

But that doesn't mean a CISO's job is getting any easier.

Organizations are asking security leaders to support the widespread adoption of AI while keeping it secure. As Patrick Joyce, global resident CISO at Proofpoint says: "AI is fundamentally changing the CISO mandate."

AI: A double-edged priority

Proofpoint's survey found that CISO anxiety over generative AI jumped by 18 percentage points to 78%. At the same time, 85% of respondents cited enabling employees to use AI assistants and automation as a top priority.

"Most CISOs are seeing their organizations actively trying to increase the use of AI across both internal systems and in the productions or solutions they deliver," Alyssa Miller, CISO advisor and board member, Epiphany Solutions Group, told TechTarget Cybersecurity.

Miller, formerly the CISO at Epiq and a security leader at CDW, EY and Optiv, added that the public's increasing interest in AI is adding extra pressure on security teams.

"We've all seen the ever-increasing attention that AI is receiving in the media and in particular around some of the large breakout events that have been disclosed," she said. "We're just starting to see some of the real-world implications of threats that up to this point were discussed in more ethereal terms -- and that has gotten the attention of CISOs more than ever."

Preparation gaps and internal vulnerabilities

Despite growing confidence in cyber resilience, more than half (56%) of CISOs surveyed said their companies are still unprepared to handle an attack.

Beyond AI assistants, security leaders cited risks in everyday work tools, including collaboration platforms, SaaS applications and cloud storage.

However, according to David Sowder, a former IT operations and leader and current senior solutions architect at Adaptiva, the bigger problem comes when defenses fail.

"The biggest disconnect I see is that organizations can put tremendous effort into security controls while under-engineering the response plan for when those controls don't work," Sowder said. "No security control is perfect, and as attacks become faster and more sophisticated, organizations have to assume something will eventually get through."

The biggest cybersecurity challenge might be coming from inside the company. Nearly four in five (79%) CISOs identified employees as their organization's biggest vulnerability, up from 66% a year ago. That makes collaboration a critical strategy for security and IT teams to embrace.

"Effective cooperation starts with shared prioritization," Sowder said. "Security needs to identify which vulnerabilities pose the greatest risk and communicate that context to IT operations, while IT brings operational understanding of how and when to remediate those vulnerabilities without unnecessary disruption."

Among the report's other findings:

  • Escalating financial and regulatory impacts. While reported data loss declined, CISOs noted sharper impacts from regulatory sanctions (rising to 40% from 34%) and direct financial losses (rising to 38% from 27%). Post-attack recovery costs and brand reputation damage also increased.
  • Fading trust in the workforce. More than three in four CISOs (76%) said they believe employees are likely to use AI tools in ways that expose sensitive corporate data.
  • Board alignment vs. burnout. Boardroom relationship dynamics are improving, with 85% of CISOs feeling aligned with company leadership, up from 64% in 2025. However, 77% reported that expectations placed on them have become unsustainable.

Adapting to resource constraints

Compounding these challenges, 79% of CISOs said they are expected to handle AI-related risks without a significant increase in resources or expertise.

To manage the strain, Miller said security leaders must find a way to adapt and use automated workflows internally.

"With all the focus on the threats surrounding AI, I think far less attention has been paid to how our SOCs, our GRC teams and even our security engineering teams can improve their own efficiency and efficacy," she said. "We absolutely can minimize the impact to our teams if we can create and expand our own agentic capabilities to handle the more tedious, repetitive and often low-value activities that our teams are working on each day."

Craig Galbraith is the founder and owner of Galbraith Multimedia, an independent journalism company that provides writing, editing, video hosting, podcasting, onstage presentation and consulting services to the technology industry.

Dig Deeper on Enterprise Risk Management