Site navigation

76% of CISOs Expect ‘Material Cyber-attack’ in the Next Year

Tom Quinn

,

CISO
“As genAI adoption accelerates both opportunity and threat, CISOs are being asked to do more with less, navigate unprecedented complexity, and still safeguard what matters most,” said Patrick Joyce, Proofpoint.

As cyber threats become more frequent and multifaceted, CISOs are becoming increasingly concerned about their organisation’s ability to withstand a material attack, according to new research from Proofpoint.

The cybersecurity and compliance firm’s latest Voice of the CISO report found a culture of heightened anxiety among security leaders, fostered by the rapid rise of genAI, concerns around data exposure, and mounting business pressures.

Polling 1,600 CISOs across sixteen countries, two-thirds admitted to a material data loss in the past year, while 76% said they felt at risk of experiencing a material cyberattack over the next twelve months, but despite that, more than half (58%) are still unprepared to respond.  

Keeping up with the threat landscape is a major part of the problem, with AI becoming both a top priority and a top concern for CISOs.

Almost two-thirds (64%) said that enabling genAI is a strategic priority over the next two years, but 80% of CISOs expressed serious concern over the potential for customer data loss via public genAI platforms. 

CISOs report that in response, their organisations are shifting from restriction to governance, with 67% implementing usage guidelines and 68% exploring AI-powered defences, though enthusiasm has dipped from last year’s high of 87%.  

However, while the prevalence of AI on both sides of the cyber divide is undeniably a growing problem, human behaviour remains a more critical vulnerability.

Almost all (92%) of security leaders attributed at least some data loss to departing employees, according to the survey, up from 73% last year. Meanwhile, human error remains the top cybersecurity vulnerability in 2025, with 66% of CISOs citing people as their greatest risk, despite 68% believing their employees understand cybersecurity best practices.

Proofpoint said this shows awareness alone is not enough, and that dedicated insider risk resources are needed to bridge the gap between knowledge and behaviour, something nearly a third of organisations still lack.

Rather than receiving more support to face this fragmented threat landscape, most CISOs are being pressured by expectations from above.


Recommended reading


Proofpoint found that boardroom alignment with CISOs has declined from a high of 84% in 2024 to 64% this year, with two-thirds (66%) facing excessive expectations, and 63% either experiencing or witnessing burnout in the past year.

One bright spot Proofpoint identified was that business valuation has emerged as boards’ top concern following a cyberattack, up from the bottom of the list last year, signalling that cyber risk is gaining traction as a strategic priority, and could lead to more resources for CISOs.

“While many security leaders express optimism about their organisation’s cyber posture, the reality tells a different story – rising data loss, readiness gaps, and persistent human risk continue to undermine resilience,” said Patrick Joyce, global resident CISO at Proofpoint.

“As genAI adoption accelerates both opportunity and threat, CISOs are being asked to do more with less, navigate unprecedented complexity, and still safeguard what matters most. It’s clear that the role of the CISO has never been more pivotal, or more pressured.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data