Report by Proofpoint

2026 Voice of the CISO

21 FINDINGSPublished Sep 9, 2026
View Original Report →

Key Findings

85% of UK CISOs believe cybersecurity expertise should be required at the board-director level, up from 63% in 2025.

Proofpoint2026 Voice of the CISO·5d ago
Board GovernanceUK

72% of UK CISOs report that their organisations block or restrict employee GenAI use.

Proofpoint2026 Voice of the CISO·5d ago
Generative AIAccess ControlUK

62% of UK organisations experience material data loss, down from 74% in 2025.

Proofpoint2026 Voice of the CISO·5d ago
Data LossUK

69% of UK CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 60% in 2025.

Proofpoint2026 Voice of the CISO·5d ago
Employee BehaviorInsider ThreatUK

61% of UK CISOs say their organisation is unprepared to cope with a targeted cyberattack.

Proofpoint2026 Voice of the CISO·5d ago
Incident ResponseCyber ResilienceUK

Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.

Proofpoint2026 Voice of the CISO·5d ago
Insider ThreatData LossUK

95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.

Proofpoint2026 Voice of the CISO·5d ago
Insider ThreatData LossUK

Among UK organisations that experienced material data loss, regulatory sanctions rose to 35% from 30% in 2025.

Proofpoint2026 Voice of the CISO·5d ago
Regulatory ComplianceData LossUK

Among UK organisations that experienced material data loss, financial losses increased to 40% from 24% in 2025.

Proofpoint2026 Voice of the CISO·5d ago
Financial LossData LossUK

Among UK organisations that experienced material data loss, post-attack recovery costs rose to 36% from 26% in 2025.

Proofpoint2026 Voice of the CISO·5d ago
Incident ResponseData LossUK

Among UK organisations that experienced material data loss, reputational damage increased to 45% from 36% in 2025.

Proofpoint2026 Voice of the CISO·5d ago
ReputationData LossUK

87% of UK CISOs believe their controls effectively mitigate risks introduced by AI, SaaS, and modern work patterns.

Proofpoint2026 Voice of the CISO·5d ago
Security ControlsAI SecurityUK

66% of UK CISOs believe employees are likely to use AI in ways that could expose sensitive data.

Proofpoint2026 Voice of the CISO·5d ago
AI SecurityEmployee BehaviorUK

71% of UK CISOs are concerned about customer data loss through public GenAI tools.

Proofpoint2026 Voice of the CISO·5d ago
Customer DataGen AIUK

71% of UK CISOs view GenAI as a security risk, a 13 percentage-point increase year-over-year.

Proofpoint2026 Voice of the CISO·5d ago
Gen AIAI SecurityUK

74% of UK CISOs say excessive expectations are placed on them.

Proofpoint2026 Voice of the CISO·5d ago
Board GovernanceLeadership PressureUK

87% of UK CISOs say they see eye-to-eye with their boards on cybersecurity, up from 57% in 2025.

Proofpoint2026 Voice of the CISO·5d ago
Board GovernanceUK

74% of UK CISOs believe their organisation is at risk of a material cyberattack in the next 12 months, up from 63% in 2025.

Proofpoint2026 Voice of the CISO·5d ago
Risk AssessmentUK

72% of UK CISOs expect to manage AI-related risks without a proportional increase in resources or expertise in the next two years.

Proofpoint2026 Voice of the CISO·5d ago
AI SecurityRisk ManagementUK

UK CISOs identify the following technologies as top concerns: SaaS applications and third-party integrations (33%), Collaboration platforms (32%), Active Directory/Identity infrastructure (32%), Perimeter network devices (32%), and AI assistants/copilots/autonomous agents (30%).

Proofpoint2026 Voice of the CISO·5d ago
Cloud SecurityIdentity ManagementUK

80% of UK CISOs say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years.

Proofpoint2026 Voice of the CISO·5d ago
AI SecurityOperational PrioritiesUK