“78% of CISOs say their organization blocks or restricts employee use of GenAI tools.”
AI governance has become a data-security problem
Proofpoint’s Voice of the CISO series shows GenAI moving from an emerging risk to a governance mandate. The share of CISOs who identified GenAI as a security risk rose from 54% in 2024 to 60% in 2025 and to 78% in 2026. At the same time, 78% of organizations report blocking or restricting employee use of GenAI tools in 2026, up from 59% in 2025. Yet restriction alone is inadequate: as AI features embed into assistants, copilots, collaboration suites and SaaS workflows, the report argues governance must answer contextual questions — what data a user can access, what an AI is allowed to summarize or act upon, and how assistants change decision flows.
That shift is sharpened by a resource mismatch: 79% of CISOs say they are expected to manage AI-related risks without a proportional increase in resources or expertise, turning awareness into an operational capacity problem rather than a policy debate.
Human risk: persistent, systemic, and often tied to departures
Across five years, human risk has been consistently central to loss. The proportion of CISOs naming human risk or error as the biggest cyber vulnerability climbed from 56% in 2022 to 79% in 2026, with intermediate values of 60% (2023), 74% (2024) and 66% (2025). Among organizations that reported material data loss, 93% say departing employees played a role.
Proofpoint’s analysis lists the leading root causes of material data loss as malicious or criminal insiders, careless insiders, compromised insiders, misuse or misconfiguration of AI tools, external attacks, and third‑party compromise. The report frames human risk as a systems problem — identity, permissions, tooling, intent and lifecycle events (role changes, privilege expansion, contractor access, departures) interact to create exposure that training alone cannot fix.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleBoardroom attention is higher — and expectations have grown
Board alignment has been volatile but stronger overall: 51% of CISOs reported board alignment in 2022, 62% in 2023, 84% in 2024, 64% in 2025 and 85% in 2026. Boards are seen as focused on commercial consequences — business valuation, significant downtime, reputational damage, loss of sensitive information, operational disruption, customer loss, and revenue impact — reframing cybersecurity as enterprise risk.
That visibility brings pressure: the share of CISOs reporting excessive expectations rose to 77% in 2026 from 66% in 2025 and 49% in 2022. Greater board interest has not eased the mandate; it has amplified accountability across people, data, identity, AI, regulation and continuity.
The center of risk has moved into the workflow
The five‑year trend is not a straight line of escalation but a relocation of risk. The report’s central claim is that cyber risk has shifted from perimeter defenses toward the places where work actually happens: identity systems, collaboration platforms, SaaS applications, cloud repositories, endpoints, APIs, automation and AI-enabled workflows. Control effectiveness, the report says, must be measured where users touch data and make decisions, not only where traditional security tools have historically been deployed.
As AI, automation and integrated SaaS proliferate, the allow‑or‑block paradigm becomes blunt; protecting sensitive information requires governance that can reason about identity, permissions, intent and the point at which assistance becomes influence or action.
What this means for technologists, boards, and procurement leaders
- Technologists and security teams: Expect to shift investments from edge defenses to contextual controls that map identity and data flows inside collaboration and AI‑enabled workflows. The resource gap for AI risk (79% of CISOs) highlights a near‑term operational capacity shortfall.
- Boards and directors: Directors are focused on valuation, downtime, reputation, data loss and revenue impact; better alignment has increased expectations and accountability rather than reducing them. Reporting should translate technical exposure into those business consequences.
- Procurement and enterprise leaders: Because data loss increasingly reflects interactions between people, tools and third parties (including misuse or misconfiguration of AI), control effectiveness must be evaluated where chosen SaaS, automation and AI services operate — not only by vendor security posture on paper.
Proofpoint’s Voice of the CISO findings across 2022–2026 show a security profession adapting to a relocated center of gravity: risk no longer lives only at the edge but inside the workflows that power the business. The CISO mandate, the report concludes, is now to enable the business to work safely where productivity and risk have become inseparable — by governing AI in context, treating human risk as a systems problem, and measuring control effectiveness where work actually happens.
Read the original Proofpoint Voice of the CISO summary at The Hacker News




