Proofpoint

138 stats5 reports

All Statistics

85% of UK CISOs believe cybersecurity expertise should be required at the board-director level, up from 63% in 2025.

Proofpoint2026 Voice of the CISO·6d ago
Board GovernanceUK

72% of UK CISOs report that their organisations block or restrict employee GenAI use.

Proofpoint2026 Voice of the CISO·6d ago
Generative AIAccess ControlUK

62% of UK organisations experience material data loss, down from 74% in 2025.

Proofpoint2026 Voice of the CISO·6d ago
Data LossUK

48% of organizations in Singapore report user interaction as the reason ransomware bypassed controls.

User BehaviorSingaporeRansomware

65% of global organizations affected by ransomware say AI increased the effectiveness of the attack.

AI SecurityRansomwareAttack Effectiveness

28% of global organizations that experienced a ransomware attack report that AI significantly increases the attack's effectiveness.

RansomwareAI

Resolving a data loss incident can take between one and four weeks for more than one in five organizations (21%).

Proofpoint2025 Data Security Landscape·10mo ago
Data loss

44% of organizations lack sufficient visibility and controls over GenAI tools.

Proofpoint2025 Data Security Landscape·10mo ago
GenAIVisibility

Over a third of organizations worry about sensitive data being used in AI training.

Proofpoint2025 Data Security Landscape·10mo ago
Data lossGenAI

67% percent of healthcare organizations say ransomware attacks had a negative impact on patient care.

HealthcareRansomwareCyber attack consequences

45% of attacked tools in healthcare organizations are email.

HealthcareEmail

52% of healthcare organizations use secure email gateways to protect against email-based attacks, which is a 7-point increase from 2024.

HealthcareSEGEmail

92% of organisations attribute at least some data loss to departing employees. This is up from 73% last year.

Proofpoint2025 Voice of the CISO·1y ago
CISOsData lossCyber riskInsider threat

In the U.S., 80% of CISOs express concern over potential customer data loss via public GenAI platforms.

Proofpoint2025 Voice of the CISO·1y ago
CISOsGen AIData lossUS

Despite this, 68% of CISOs believe employees understand cybersecurity best practices.

Proofpoint2025 Voice of the CISO·1y ago
CISOsEmployees

69% of UK CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 60% in 2025.

Proofpoint2026 Voice of the CISO·6d ago
Employee BehaviorInsider ThreatUK

61% of UK CISOs say their organisation is unprepared to cope with a targeted cyberattack.

Proofpoint2026 Voice of the CISO·6d ago
Incident ResponseCyber ResilienceUK

Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.

Proofpoint2026 Voice of the CISO·6d ago
Insider ThreatData LossUK

95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.

Proofpoint2026 Voice of the CISO·6d ago
Insider ThreatData LossUK

Among UK organisations that experienced material data loss, regulatory sanctions rose to 35% from 30% in 2025.

Proofpoint2026 Voice of the CISO·6d ago
Regulatory ComplianceData LossUK

Among UK organisations that experienced material data loss, financial losses increased to 40% from 24% in 2025.

Proofpoint2026 Voice of the CISO·6d ago
Financial LossData LossUK

Among UK organisations that experienced material data loss, post-attack recovery costs rose to 36% from 26% in 2025.

Proofpoint2026 Voice of the CISO·6d ago
Incident ResponseData LossUK

Among UK organisations that experienced material data loss, reputational damage increased to 45% from 36% in 2025.

Proofpoint2026 Voice of the CISO·6d ago
ReputationData LossUK

87% of UK CISOs believe their controls effectively mitigate risks introduced by AI, SaaS, and modern work patterns.

Proofpoint2026 Voice of the CISO·6d ago
Security ControlsAI SecurityUK

66% of UK CISOs believe employees are likely to use AI in ways that could expose sensitive data.

Proofpoint2026 Voice of the CISO·6d ago
AI SecurityEmployee BehaviorUK

71% of UK CISOs are concerned about customer data loss through public GenAI tools.

Proofpoint2026 Voice of the CISO·6d ago
Customer DataGen AIUK

71% of UK CISOs view GenAI as a security risk, a 13 percentage-point increase year-over-year.

Proofpoint2026 Voice of the CISO·6d ago
Gen AIAI SecurityUK

74% of UK CISOs say excessive expectations are placed on them.

Proofpoint2026 Voice of the CISO·6d ago
Board GovernanceLeadership PressureUK

87% of UK CISOs say they see eye-to-eye with their boards on cybersecurity, up from 57% in 2025.

Proofpoint2026 Voice of the CISO·6d ago
Board GovernanceUK

74% of UK CISOs believe their organisation is at risk of a material cyberattack in the next 12 months, up from 63% in 2025.

Proofpoint2026 Voice of the CISO·6d ago
Risk AssessmentUK

72% of UK CISOs expect to manage AI-related risks without a proportional increase in resources or expertise in the next two years.

Proofpoint2026 Voice of the CISO·6d ago
AI SecurityRisk ManagementUK

UK CISOs identify the following technologies as top concerns: SaaS applications and third-party integrations (33%), Collaboration platforms (32%), Active Directory/Identity infrastructure (32%), Perimeter network devices (32%), and AI assistants/copilots/autonomous agents (30%).

Proofpoint2026 Voice of the CISO·6d ago
Cloud SecurityIdentity ManagementUK

80% of UK CISOs say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years.

Proofpoint2026 Voice of the CISO·6d ago
AI SecurityOperational PrioritiesUK

37% of global organizations that experienced a ransomware attack report that AI somewhat increases the attack's effectiveness.

RansomwareAI

Only 9% of global organizations affected by ransomware report no evidence of AI use in the attack.

RansomwareAI

54% of organizations affected by ransomware pay a ransom.

Ransom PaymentsRansomwareExtortion

37% of organizations that pay a ransom face a second extortion demand.

RansomwareExtortion

60% of US organizations confirm sensitive data theft during ransomware incidents.

Data TheftUSer BehaviorRansomware

40% of organizations say employees did not suspect the attack because it appeared authentic.

Social EngineeringRansomwareHuman Factors

Credential harvesting is identified as the initial threat in 36% of ransomware incidents.

Credential TheftRansomwareThreat Vectors

93% of US organizations affected by ransomware pay a ransom.

Ransom PaymentsRansomwareUS

Phishing emails and other email-based social engineering are the initial entry vector in 34% of ransomware incidents.

PhishingRansomwareEmail Security

US organizations report AI-enhanced attack effectiveness at 81%.

AI SecurityRansomwareUS

User interaction as a bypass factor is highest in Japan (49%), India (49%), and Singapore (48%).

User InteractionRansomwareRegional Comparison

Malicious links are identified as the initial threat in 47% of ransomware incidents.

RansomwareMalicious LinksThreat Vectors

40% of organizations report that employees trust AI-powered attacks.

Social EngineeringAI Threats

38% of organizations report that employees interact with malicious content.

Malicious ContentUser Behavior

34% of ransomware incidents begin with phishing emails or other email-based social engineering.

PhishingSocial EngineeringRansomware

65% of global organizations affected by ransomware report that AI increases the attack's effectiveness.

RansomwareAI

Malicious links are identified as the initial threat in 47% of incidents, malicious attachments in 46%, credential harvesting in 36%, and Business Email Compromise in 35%.

RansomwareCredential TheftBECMalicious AttachmentsCredential Harvesting