The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens.

For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That narrative is still familiar, but comparing the five most recent years of Voice of the CISO research suggests a more useful reading. The CISO role has not simply become harder because every metric is rising at once. It has become harder because the center of risk has shifted and moved closer to the way work now gets done.

The latest 2026 findings show signs of progress. Fewer CISOs expect a material cyberattack in the next 12 months, and fewer report material loss of sensitive information than in 2025. But those improvements sit within a longer trend line that is much less settled. Over five years, attack expectations have risen, fallen, and risen again. Board alignment has swung sharply. Human risk has remained stubbornly central. AI has moved from an emerging concern to defining mandate. The result is not a simple story of improvement or decline. It is a story of risk changing location.

That distinction matters because it changes what security leaders should be optimizing for. The question for CISOs is no longer only, “What threat will hit us next?” It is becoming, “Where does critical work happen, who or what has access to it, and can the organization protect sensitive data as it moves across people, cloud platforms, collaboration tools, SaaS applications, and AI-enabled workflows?”

The five-year trend is not linear

The year-over-year (YoY) movement from 2025 to 2026 is important, but it doesn’t tell the whole story. The five-year view shows a profession that has been forced to absorb and manage wave after wave of change rather than follow a smooth maturity curve.

The value of the five-year view is that it resists easy conclusions. Attack expectations cooled in 2026 after a 2025 high, but they remain above 2022. Reported data loss fell YoY, but more than half of CISOs still report material loss and preparedness barely moved. Board alignment rebounded to its highest level in the series, but excessive expectations also rose concurrently. Taken together, the data trends across the years point to a security function that is gaining visibility and support while also being asked to govern a much wider operating environment.

AI turned the CISO agenda from protection to governance

AI is the clearest example of how quickly that operating environment has changed. In 2024, 54% of CISOs said GenAI was a security risk. That rose to 60% in 2025 and 78% in 2026. Over the same period, the business conversation around AI has moved from experimentation to embedded use, with assistants, copilots, automation, and agentic workflows becoming part of daily work.

The instinct to restrict access is understandable, and many organizations are doing exactly that. In 2026, 78% of CISOs say their organization blocks or restricts employee use of GenAI tools, up from 59% in 2025. But restriction is not the same as governance. As AI becomes embedded in productivity suites, collaboration platforms, SaaS tools, and business workflows, a simple allow-or-block model becomes too blunt for how work actually happens.

The more durable question is whether organizations can govern AI in context. What data can a user access? What is the AI tool allowed to summarize, generate, or act on? What happens when an assistant, agent, or automation moves from answering a question to influencing a decision or triggering an action?

This is where the AI conversation becomes a data security conversation. AI risk is not only about prompts, models, or hallucinations. It is about sensitive information, identity, permissions, intent, and control. That makes the resource signal in the 2026 report especially important: 79% of CISOs say they are expected to manage AI-related risks without a proportional increase in resources or expertise. The gap is no longer awareness. It is operational capacity.

Human risk is no longer a soft problem

Across the five-year trend set, human risk remains one of the most persistent signals. The wording has evolved over time, from human error to human risk, but the direction is clear enough to matter: 56% in 2022, 60% in 2023, 74% in 2024, 66% in 2025, and 79% in 2026 identified human risk or error as the biggest cyber vulnerability.

That should change how organizations discuss the topic. Human risk is often treated as a training problem, but the 2026 findings show it is much more than that. Among organizations that experienced material data loss, 93% say departing employees played a role. The leading root causes of material data loss were malicious or criminal insiders, careless insiders, compromised insiders, misuse or misconfiguration of AI tools, external attacks, and third-party compromise. In other words, data loss increasingly sits at the intersection of behavior, identity, access, permissions, tooling, and intent.

This is why human risk should be viewed as a systems problem with a human interface. A user may be malicious, careless, compromised, over-permissioned, under-governed, or simply working inside a process that gives them more access than the business can justify. Awareness training still has a role, but it cannot carry the burden alone. Organizations need to understand behavior in context: who the user is, what data they are touching, whether access is appropriate, whether the action is unusual, and whether a change in role, employment status, or intent has altered the risk.

The boardroom is closer to the problem, but not necessarily closer to resolution

The board trend is one of the most revealing five-year signals because it has not moved in a straight line. In 2022, 51% of CISOs said their board saw eye to eye with them on cybersecurity. That rose to 62% in 2023 and 84% in 2024, fell to 64% in 2025, and rebounded to 85% in 2026. That volatility is important. It suggests that cybersecurity has a firmer place on the board agenda, but alignment still depends on how effectively CISOs can communicate and translate technical risk into commercial risk, operational resilience, regulatory exposure, and customer trust.

The issues boards are perceived to care about reinforce this commercial framing. CISOs say their boards are concerned about business valuation, significant downtime, reputational damage, loss of sensitive information, disruption to operations, loss of current customers, and loss in revenue. That list reads less like a security operations dashboard and more like an enterprise risk agenda.

That creates an opportunity for CISOs, but it also raises expectations. In 2026, 77% of CISOs say excessive expectations are placed on the CISO or CSO, up from 66% in 2025 and from 49% in 2022. Better board alignment has not made the role lighter. It has made the role more visible, more commercial, and more accountable for risk that now spans people, data, identity, AI, regulation, and business continuity.

The next phase of resilience will be decided inside the flow of work

The practical takeaway from five years of CISO data is not that the threat landscape has become less dangerous. It is that danger has become more operationally embedded. Security strategy needs to reflect where work now happens, which means treating identity, collaboration platforms, SaaS applications, cloud repositories, endpoints, APIs, automation, and AI systems as part of the same risk fabric rather than as separate control domains.

For CISOs, several priorities follow. AI governance should be treated as a data security and decision-control issue, not only as an acceptable-use policy. Human risk should be managed across the employee lifecycle, especially during role changes, privilege expansion, contractor access, and employee departures. Board reporting should move from threat volume to business consequence, helping directors understand how cyber exposure maps to the business concerns of valuation, downtime, customer trust, regulatory impact, and resilience. Control effectiveness should be measured where work actually happens, not only where traditional security tools have historically been deployed.

The more thought-provoking conclusion is that cybersecurity’s center of gravity has shifted from the perimeter to the workflow. The modern enterprise is not secured only by stopping attacks at the edge. It is secured by understanding how people, data, identity, applications, and intelligent systems interact every day.

That is the CISO mandate now. Not just to prevent the next incident, but to help the business work safely in the places where risk and productivity have become inseparable.

See what 1,600 global CISOs revealed about AI, human risk, and cyber resilience in the 2026 Voice of the CISO report. Download the report.

Source: Proofpoint Voice of the CISO reports and annual findings, 2022, 2023, 2024, 2025, 2026.

Note: This article has been expertly written and contributed by Patrick Joyce, Global Resident CISO, Proofpoint.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.