CISOs are feeling the security burden of accelerated AI use
Chief information security officers are largely expected to ensure the security of AI across the enterprise, but many say they are not receiving adequate support, according to findings from Proofpoint.
About 85% of CISOs said ensuring the safe use of AI assistants, copilots and automation is a top priority over the next two years, according to Proofpoint’s annual Voice of the CISO report. Eight of every 10 CISOs said they are expected to manage AI-related security risks without receiving a proportional increase in resources or expertise.
“CISOs have a significant role to play in securing AI adoption, but they can’t own the risk alone,” Patrick Joyce, global resident CISO at Proofpoint, told Cybersecurity Dive. “AI is being adopted across the business, often faster than traditional governance models can keep up.”
Cyber risk posture
The global survey of 1,600 CISOs highlights important changes in overall risk and the CISO relationship with the C-suite. The survey, conducted by Censuswide, included 100 CISOs at major companies in 16 countries across the globe, from the U.S., the U.K., India, Japan and other countries.
CISOs overall have gained confidence in their organization’s risk posture, however. About six out of 10 CISOs expressed concerns about a material cyberattack, compared to about three-quarters in the 2025 survey. Still, more than half of CISOs fear their organization would be unable to manage a targeted cyberattack.
About 85% of CISOs said they are largely aligned with their corporate boards on security issues, a significant increase from a year ago, where less than two-thirds of CISOs were aligned. Despite that improvement, nearly 8 of every 10 CISOs said they are facing excessive pressure from their boards on issues ranging from operational disruption and data loss to reputational risk.
“The CISO is increasingly expected to protect the business, enable AI, safeguard data, manage regulatory risk, support business continuity and explain all of that in commercial terms to the board,” Joyce said.
AI exposure
Among the biggest worries for CISOs is employee use of generative AI. A total of 78% of CISOs now consider GenAI a major security risk, representing an 18% increase from the prior year.
About 86% of CISOs believe their internal security controls provide adequate security protection over risks presented by AI, software-as-a-service and modern work patterns. Despite that confidence, more than 75% of CISOs fear that employees are using AI in a way that could expose sensitive company data.
In addition to the concerns about AI, CISOs have larger concerns regarding employee behavior. About 8 of every 10 CISOs consider human behavior as the biggest cyber vulnerability within their organization, up from 66% a year ago. Among organizations that experienced a material data loss over the past year, about 46% said the loss was related to a malicious or criminal insider.
Reproduced in full under licence from Cybersecurity Dive. © Cybersecurity Dive. Written by David Jones.
At a glance
- Severity
- Lowfrom category and source signals; no CVSS referenced
- Exploitation
- No vulnerabilities referenced
- Vulnerabilities
- None referenced
- Vendors & products
- None named
- Threat actors & malware
- None named
- Industries
- Not industry-specific
- Coverage
- 1 outlet· first seen 2026-09-09 15:36 UTC
- Priority
- 30/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.
Coverage
One outlet has carried this so far.
2026-09-09 15:36 UTC
Related stories
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · 2026-11-12
- [Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · 2026-10-08
- When the Whole Company Adopts AI: What It Does to Your SOC
The Hacker News · 2026-09-12
- Phishing Research Challenges Conventional Security Awareness Testing
SecurityWeek · 2026-09-11
- AI Governance Can't Wait
Dark Reading · 2026-09-11