ZeroHour
Proofpoint Threat Insightpublished ()ingested

CISOs are feeling the security burden of accelerated AI use

infoIndustryimportance 28
AI summary · glm-5.3-flash

Proofpoint's Voice of the CISO survey finds 85% of CISOs prioritizing AI security, with 80% managing AI risks without proportional resources.

Proofpoint's annual Voice of the CISO report, a Censuswide survey of 1,600 CISOs across 16 countries, found 85% rank securing AI assistants, copilots and automation among top priorities for the next two years. Eight in ten say they must manage AI-related security risk without a proportional increase in resources or expertise, and 78% now consider generative AI a major security risk, up 18% year over year. Board alignment improved to 85%, though nearly 80% still report excessive board pressure; 80% cite human behavior as the biggest cyber vulnerability.

  • 85% of CISOs rank securing AI assistants and automation a top two-year priority.
  • 80% report managing AI-related risk without proportional resources or expertise.
  • 78% consider generative AI a major security risk, up 18% from the prior year.
  • Survey covered 1,600 CISOs in 16 countries, conducted by Censuswide.
VendorsProofpoint
OrganizationsCensuswide
Full article463 words · extracted from proofpoint.com · click to collapse

Chief information security officers are largely expected to ensure the security of AI across the enterprise, but many say they are not receiving adequate support, according to findings from Proofpoint. 

About 85% of CISOs said ensuring the safe use of AI assistants, copilots and automation is a top priority over the next two years, according to Proofpoint’s annual Voice of the CISO report. Eight of every 10 CISOs said they are expected to manage AI-related security risks without receiving a proportional increase in resources or expertise. 

“CISOs have a significant role to play in securing AI adoption, but they can’t own the risk alone,” Patrick Joyce, global resident CISO at Proofpoint, told Cybersecurity Dive. “AI is being adopted across the business, often faster than traditional governance models can keep up.”

Cyber risk posture

The global survey of 1,600 CISOs highlights important changes in overall risk and the CISO relationship with the C-suite. The survey, conducted by Censuswide, included 100 CISOs at major companies in 16 countries across the globe, from the U.S., the U.K., India, Japan and other countries.

CISOs overall have gained confidence in their organization’s risk posture, however. About six out of 10 CISOs expressed concerns about a material cyberattack, compared to about three-quarters in the 2025 survey. Still, more than half of CISOs fear their organization would be unable to manage a targeted cyberattack. 

About 85% of CISOs said they are largely aligned with their corporate boards on security issues, a significant increase from a year ago, where less than two-thirds of CISOs were aligned. Despite that improvement, nearly 8 of every 10 CISOs said they are facing excessive pressure from their boards on issues ranging from operational disruption and data loss to reputational risk.

“The CISO is increasingly expected to protect the business, enable AI, safeguard data, manage regulatory risk, support business continuity and explain all of that in commercial terms to the board,” Joyce said.

AI exposure

Among the biggest worries for CISOs is employee use of generative AI. A total of 78% of CISOs now consider GenAI a major security risk, representing an 18% increase from the prior year. 

About 86% of CISOs believe their internal security controls provide adequate security protection over risks presented by AI, software-as-a-service and modern work patterns. Despite that confidence, more than 75% of CISOs fear that employees are using AI in a way that could expose sensitive company data. 

In addition to the concerns about AI, CISOs have larger concerns regarding employee behavior. About 8 of every 10 CISOs consider human behavior as the biggest cyber vulnerability within their organization, up from 66% a year ago. Among organizations that experienced a material data loss over the past year, about 46% said the loss was related to a malicious or criminal insider. 

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.proofpoint.com/us/newsroom/news/cisos-are-feeling-security-burden-accelerated-ai-use