Breaking
SecurityDeveloping Story

CISO Data: Cyber Risk Moves Into Workflow

Five years of Voice of the CISO research show risk shifting from the perimeter to the flow of daily work, with AI governance and human risk at the center.

··1 hour ago·7 min read
people sitting at the table
Photo by Memento Media on Unsplash

For years the enterprise security story has been told as a straight line: more attacks, more data loss, more pressure. But a review of five years of Voice of the CISO research suggests a different reading. The role has not simply become harder because every metric is rising. It has become harder because the center of risk has moved closer to the way work now gets done.

That shift is the through-line in the 2026 findings, which look at how resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens.

Five years, not one

The year-over-year movement from 2025 to 2026 matters, but it does not tell the whole story. The latest 2026 findings show signs of progress: fewer CISOs expect a material cyberattack in the next 12 months, and fewer report material loss of sensitive information than in 2025.

Those improvements sit inside a longer trend line that is far less settled. Over five years, attack expectations have risen, fallen, and risen again. Board alignment has swung sharply. Human risk has stayed stubbornly central. AI has moved from an emerging concern to a defining mandate.

The result is not a simple story of improvement or decline. It is a story of risk changing location, and that distinction changes what security leaders should be optimizing for. The question is no longer only what threat will hit next. It is becoming where critical work happens, who or what has access to it, and whether the organization can protect sensitive data as it moves across people, cloud platforms, collaboration tools, SaaS applications, and AI-enabled workflows.

AI turns agenda to governance

AI is the clearest example of how quickly the operating environment has changed. In 2024, 54% of CISOs said GenAI was a security risk. That rose to 60% in 2025 and 78% in 2026. Over the same period, the business conversation around AI moved from experimentation to embedded use, with assistants, copilots, automation, and agentic workflows becoming part of daily work.

The instinct to restrict access is understandable, and many organizations are doing exactly that. In 2026, 78% of CISOs say their organization blocks or restricts employee use of GenAI tools, up from 59% in 2025. But restriction is not governance. As AI becomes embedded in productivity suites, collaboration platforms, SaaS tools, and business workflows, a simple allow-or-block model becomes too blunt for how work actually happens.

The more durable question is whether organizations can govern AI in context. What data can a user access? What is the AI tool allowed to summarize, generate, or act on? What happens when an assistant, agent, or automation moves from answering a question to influencing a decision or triggering an action?

This is where the AI conversation becomes a data security conversation. AI risk is not only about prompts, models, or hallucinations. It is about sensitive information, identity, permissions, intent, and control. That makes the resource signal in the 2026 report especially important: 79% of CISOs say they are expected to manage AI-related risks without a proportional increase in resources or expertise. The gap is no longer awareness. It is operational capacity.

Human risk stays central

Across the five-year trend set, human risk remains one of the most persistent signals. The wording has evolved over time, from human error to human risk, but the direction is clear: 56% in 2022, 60% in 2023, 74% in 2024, 66% in 2025, and 79% in 2026 identified human risk or error as the biggest cyber vulnerability.

That should change how organizations discuss the topic. Human risk is often treated as a training problem, but the 2026 findings show it is much more than that. Among organizations that experienced material data loss, 93% say departing employees played a role.

The leading root causes of material data loss were malicious or criminal insiders, careless insiders, compromised insiders, misuse or misconfiguration of AI tools, external attacks, and third-party compromise. Data loss increasingly sits at the intersection of behavior, identity, access, permissions, tooling, and intent.

This is why human risk should be viewed as a systems problem with a human interface. A user may be malicious, careless, compromised, over-permissioned, under-governed, or simply working inside a process that gives them more access than the business can justify. Awareness training still has a role, but it cannot carry the burden alone. Organizations need to understand behavior in context: who the user is, what data they are touching, whether access is appropriate, whether the action is unusual, and whether a change in role, employment status, or intent has altered the risk.

Board alignment swings sharply

The board trend is one of the most revealing five-year signals because it has not moved in a straight line. In 2022, 51% of CISOs said their board saw eye to eye with them on cybersecurity. That rose to 62% in 2023 and 84% in 2024, fell to 64% in 2025, and rebounded to 85% in 2026.

That volatility matters. It suggests cybersecurity has a firmer place on the board agenda, but alignment still depends on how effectively CISOs can communicate and translate technical risk into commercial risk, operational resilience, regulatory exposure, and customer trust.

The issues boards are perceived to care about reinforce that commercial framing. CISOs say their boards are concerned about business valuation, significant downtime, reputational damage, loss of sensitive information, disruption to operations, loss of current customers, and loss in revenue. That list reads less like a security operations dashboard and more like an enterprise risk agenda.

That creates an opportunity for CISOs, but it also raises expectations. In 2026, 77% of CISOs say excessive expectations are placed on the CISO or CSO, up from 66% in 2025 and from 49% in 2022. Better board alignment has not made the role lighter. It has made the role more visible, more commercial, and more accountable for risk that now spans people, data, identity, AI, regulation, and business continuity.

Reading the five-year arc

The latest findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens.

Attack expectations cooled in 2026 after a 2025 high, but they remain above 2022. Reported data loss fell year over year, but more than half of CISOs still report material loss, and preparedness barely moved. Board alignment rebounded to its highest level in the series, but excessive expectations rose concurrently.

Where resilience gets decided

The practical takeaway from five years of CISO data is not that the threat landscape has become less dangerous. It is that danger has become more operationally embedded. Security strategy needs to reflect where work now happens, which means treating identity, collaboration platforms, SaaS applications, cloud repositories, endpoints, APIs, automation, and AI systems as part of the same risk fabric rather than as separate control domains.

For CISOs, several priorities follow. AI governance should be treated as a data security and decision-control issue, not only as an acceptable-use policy. Human risk should be managed across the employee lifecycle, especially during role changes, privilege expansion, contractor access, and employee departures. Board reporting should move from threat volume to business consequence, helping directors understand how cyber exposure maps to valuation, downtime, customer trust, regulatory impact, and resilience. Control effectiveness should be measured where work actually happens, not only where traditional security tools have historically been deployed.

The conclusion the report points to is that cybersecurity's center of gravity has shifted from the perimeter to the workflow. The modern enterprise is not secured only by stopping attacks at the edge. It is secured by understanding how people, data, identity, applications, and intelligent systems interact every day.

That is the CISO mandate now: not just to prevent the next incident, but to help the business work safely in the places where risk and productivity have become inseparable.

By the numbers

  • 78% of CISOs in 2026 named GenAI a security risk, up from 60% in 2025 and 54% in 2024.
  • 78% of CISOs say their organization blocks or restricts employee GenAI use, up from 59% in 2025.
  • 79% of CISOs are expected to manage AI-related risks without a proportional increase in resources or expertise.
  • Human risk as the biggest vulnerability: 56% (2022), 60% (2023), 74% (2024), 66% (2025), 79% (2026).
  • 93% of organizations that suffered material data loss say departing employees played a role.
  • Board alignment with CISOs: 51% (2022), 62% (2023), 84% (2024), 64% (2025), 85% (2026).
  • Excessive expectations on the CISO or CSO: 49% (2022), 66% (2025), 77% (2026).

The figures come from Proofpoint's Voice of the CISO reports and annual findings across 2022, 2023, 2024, 2025, and 2026, including input from 1,600 global CISOs.

Why it matters

For businesses, the data suggests that treating AI governance as an access-control checkbox will leave gaps. If restriction is already at 78% while risk perception keeps climbing, organizations may be relying on blunt controls where context matters more. That could mean sensitive data continues to move through approved tools without the visibility needed to catch misuse or misconfiguration.

For security leaders, the five-year trend implies that the hardest part of the job is no longer a single perimeter to defend. It is the daily interaction of people, permissions, and AI systems inside workflows that generate business value. That is a governance problem as much as a technology one, and the resource gap many CISOs report suggests the operating model has not caught up.

For the industry, the arc points toward a quieter shift: success may be measured less by incidents stopped at the edge and more by whether critical work can proceed safely in systems where risk and productivity are inseparable.

Reporting based on original coverage from The Hacker News.

#ciso#ai governance#human risk#data security#insider threat#risk management

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories