CISOs are feeling the security burden of accelerated AI use

LowCybersecurity Dive · David Jones·

Chief information security officers are largely expected to ensure the security of AI across the enterprise, but many say they are not receiving adequate support, according to findings from Proofpoint. 

About 85% of CISOs said ensuring the safe use of AI assistants, copilots and automation is a top priority over the next two years, according to Proofpoint’s annual Voice of the CISO report. Eight of every 10 CISOs said they are expected to manage AI-related security risks without receiving a proportional increase in resources or expertise. 

“CISOs have a significant role to play in securing AI adoption, but they can’t own the risk alone,” Patrick Joyce, global resident CISO at Proofpoint, told Cybersecurity Dive. “AI is being adopted across the business, often faster than traditional governance models can keep up.”

Cyber risk posture

The global survey of 1,600 CISOs highlights important changes in overall risk and the CISO relationship with the C-suite. The survey, conducted by Censuswide, included 100 CISOs at major companies in 16 countries across the globe, from the U.S., the U.K., India, Japan and other countries.

CISOs overall have gained confidence in their organization’s risk posture, however. About six out of 10 CISOs expressed concerns about a material cyberattack, compared to about three-quarters in the 2025 survey. Still, more than half of CISOs fear their organization would be unable to manage a targeted cyberattack. 

About 85% of CISOs said they are largely aligned with their corporate boards on security issues, a significant increase from a year ago, where less than two-thirds of CISOs were aligned. Despite that improvement, nearly 8 of every 10 CISOs said they are facing excessive pressure from their boards on issues ranging from operational disruption and data loss to reputational risk.

“The CISO is increasingly expected to protect the business, enable AI, safeguard data, manage regulatory risk, support business continuity and explain all of that in commercial terms to the board,” Joyce said.

AI exposure

Among the biggest worries for CISOs is employee use of generative AI. A total of 78% of CISOs now consider GenAI a major security risk, representing an 18% increase from the prior year. 

About 86% of CISOs believe their internal security controls provide adequate security protection over risks presented by AI, software-as-a-service and modern work patterns. Despite that confidence, more than 75% of CISOs fear that employees are using AI in a way that could expose sensitive company data. 

In addition to the concerns about AI, CISOs have larger concerns regarding employee behavior. About 8 of every 10 CISOs consider human behavior as the biggest cyber vulnerability within their organization, up from 66% a year ago. Among organizations that experienced a material data loss over the past year, about 46% said the loss was related to a malicious or criminal insider. 

Reproduced in full under licence from Cybersecurity Dive. © Cybersecurity Dive. Written by David Jones.

At a glance

Severity
Lowfrom category and source signals; no CVSS referenced
Exploitation
No vulnerabilities referenced
Vulnerabilities
None referenced
Vendors & products
None named
Threat actors & malware
None named
Industries
Not industry-specific
Coverage
1 outlet· first seen 2026-09-09 15:36 UTC
Priority
30/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Coverage

One outlet has carried this so far.

  1. Cybersecurity DiveEstablished SourceFirst reported

    2026-09-09 15:36 UTC

Related stories