Proofpoint
Reports
All Statistics
85% of UK CISOs believe cybersecurity expertise should be required at the board-director level, up from 63% in 2025.
72% of UK CISOs report that their organisations block or restrict employee GenAI use.
62% of UK organisations experience material data loss, down from 74% in 2025.
48% of organizations in Singapore report user interaction as the reason ransomware bypassed controls.
65% of global organizations affected by ransomware say AI increased the effectiveness of the attack.
28% of global organizations that experienced a ransomware attack report that AI significantly increases the attack's effectiveness.
Resolving a data loss incident can take between one and four weeks for more than one in five organizations (21%).
44% of organizations lack sufficient visibility and controls over GenAI tools.
Over a third of organizations worry about sensitive data being used in AI training.
67% percent of healthcare organizations say ransomware attacks had a negative impact on patient care.
45% of attacked tools in healthcare organizations are email.
52% of healthcare organizations use secure email gateways to protect against email-based attacks, which is a 7-point increase from 2024.
92% of organisations attribute at least some data loss to departing employees. This is up from 73% last year.
In the U.S., 80% of CISOs express concern over potential customer data loss via public GenAI platforms.
Despite this, 68% of CISOs believe employees understand cybersecurity best practices.
69% of UK CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 60% in 2025.
61% of UK CISOs say their organisation is unprepared to cope with a targeted cyberattack.
Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.
95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.
Among UK organisations that experienced material data loss, regulatory sanctions rose to 35% from 30% in 2025.
Among UK organisations that experienced material data loss, financial losses increased to 40% from 24% in 2025.
Among UK organisations that experienced material data loss, post-attack recovery costs rose to 36% from 26% in 2025.
Among UK organisations that experienced material data loss, reputational damage increased to 45% from 36% in 2025.
87% of UK CISOs believe their controls effectively mitigate risks introduced by AI, SaaS, and modern work patterns.
66% of UK CISOs believe employees are likely to use AI in ways that could expose sensitive data.
71% of UK CISOs are concerned about customer data loss through public GenAI tools.
71% of UK CISOs view GenAI as a security risk, a 13 percentage-point increase year-over-year.
74% of UK CISOs say excessive expectations are placed on them.
87% of UK CISOs say they see eye-to-eye with their boards on cybersecurity, up from 57% in 2025.
74% of UK CISOs believe their organisation is at risk of a material cyberattack in the next 12 months, up from 63% in 2025.
72% of UK CISOs expect to manage AI-related risks without a proportional increase in resources or expertise in the next two years.
UK CISOs identify the following technologies as top concerns: SaaS applications and third-party integrations (33%), Collaboration platforms (32%), Active Directory/Identity infrastructure (32%), Perimeter network devices (32%), and AI assistants/copilots/autonomous agents (30%).
80% of UK CISOs say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years.
37% of global organizations that experienced a ransomware attack report that AI somewhat increases the attack's effectiveness.
Only 9% of global organizations affected by ransomware report no evidence of AI use in the attack.
54% of organizations affected by ransomware pay a ransom.
37% of organizations that pay a ransom face a second extortion demand.
60% of US organizations confirm sensitive data theft during ransomware incidents.
40% of organizations say employees did not suspect the attack because it appeared authentic.
Credential harvesting is identified as the initial threat in 36% of ransomware incidents.
93% of US organizations affected by ransomware pay a ransom.
Phishing emails and other email-based social engineering are the initial entry vector in 34% of ransomware incidents.
US organizations report AI-enhanced attack effectiveness at 81%.
User interaction as a bypass factor is highest in Japan (49%), India (49%), and Singapore (48%).
Malicious links are identified as the initial threat in 47% of ransomware incidents.
40% of organizations report that employees trust AI-powered attacks.
38% of organizations report that employees interact with malicious content.
34% of ransomware incidents begin with phishing emails or other email-based social engineering.
65% of global organizations affected by ransomware report that AI increases the attack's effectiveness.
Malicious links are identified as the initial threat in 47% of incidents, malicious attachments in 46%, credential harvesting in 36%, and Business Email Compromise in 35%.