AI Risks Surge as CISOs Report Growing Responsibility, Yet Cyber Resilience Improves
What Happened — Proofpoint’s 2026 Voice of the CISO survey of 1,600 security leaders across 16 countries shows a paradox: perceived likelihood of a material cyber‑attack fell to 61 % and reported data‑loss incidents dropped to 53 %, yet 78 % of respondents now flag generative‑AI (GenAI) as a top security risk. At the same time, 79 % say human error remains the biggest vulnerability, and 85 % list securing AI assistants, copilots and automation as a priority for the next two years—without a proportional increase in resources or expertise.
Why It Matters for Trust & Control Assurance
- The gap between expanding AI responsibilities and static security staffing creates a control‑assurance blind spot that continuous security‑awareness programs are designed to surface and remediate.
- Demonstrating that your organization has documented AI‑risk policies, regular training, and auditable evidence of compliance satisfies a single VCF control objective (AI governance) that maps to many frameworks (e.g., NIST AI RMF, ISO 42001).
- Continuous monitoring of AI‑related controls provides the defensible audit trail needed when regulators or partners request proof of due‑diligence.
Who Is Affected
- Technology‑focused enterprises (SaaS, cloud platforms) that embed GenAI assistants in daily workflows.
- Any organization that relies on third‑party AI services or internal AI models, across finance, healthcare, manufacturing, and professional services.
Recommended Actions
- Conduct an AI‑risk assessment that inventories all generative‑AI tools, data flows, and privileged‑access points.
- Integrate AI‑specific modules into your security‑awareness curriculum and measure completion rates.
- Formalize AI governance policies (model lifecycle, data handling, access controls) and capture evidence in a continuous‑monitoring repository.
- Align the new AI controls with the VCF “AI governance” objective to generate cross‑framework audit evidence.
Source: Proofpoint 2026 Voice of the CISO Report
Technical Notes
- Survey indicates a 18‑point jump in GenAI security concerns (78 % of CISOs) year‑over‑year.
- Human error cited by 79 % of respondents as the primary vulnerability, up from 66 % in 2025.
- Key risk vectors: collaboration platforms, AI assistants/copilots, SaaS integrations, public GenAI tools.
Source: same as above