For years, the overarching narrative of enterprise cybersecurity has been told as a straight line of relentless escalation. Industry reports, conference keynotes, and executive briefings have routinely painted a picture defined by a simple, compounding equation: more attacks, more data loss, more operational pressure, and ever-increasing urgency. While that familiar narrative still holds elements of truth, a retrospective look at five consecutive years of research tells a much more nuanced story. Comparing the findings from half a decade of the "Voice of the CISO" research reveals that the Chief Information Security Officer role has not merely grown more difficult because every single metric is heading upward at once. Instead, the profession has fundamentally transformed because the epicenter of cyber risk has shifted inward, moving much closer to the daily workflows where modern business actually gets done. Read Also: CISA Adds Microsoft SharePoint and MikroTik RouterOS Flaws to Known Exploited Vulnerabilities Catalog Apple Issues Urgent Security Updates for Older Devices Following Targeted Zero-Day Exploitation The latest findings from the 2026 Voice of the CISO report, authored by Patrick Joyce, Global Resident CISO at Proofpoint, offer a striking look into this evolving landscape. On the surface, the 2026 data contains notable glimmers of operational progress. Fewer security leaders expect to experience a material cyberattack within the next 12 months, and fewer report suffering a material loss of sensitive corporate information compared to the previous year. Yet, these short-term improvements exist within a much longer, highly volatile trend line. Over the past five years, expectations surrounding attack frequencies have repeatedly risen, fallen, and climbed right back up. Levels of board alignment have swung dramatically from year to year. Human risk has stubbornly remained at the core of enterprise vulnerabilities, while artificial intelligence has rapidly transitioned from an emerging peripheral concern to a defining operational mandate. The resulting reality is neither a simple story of sweeping improvement nor one of steady decline. Rather, it is a complex narrative of risk changing its physical location within the enterprise. Recognizing this distinction is critical, as it fundamentally alters what modern security leaders must optimize for. The defining question for a CISO is no longer just a defensive calculation of what threat might strike next. Instead, security executives must ask where critical work happens, who or what holds access to vital assets, and whether the organization can adequately protect sensitive data as it flows seamlessly across people, cloud platforms, collaboration tools, SaaS applications, and AI-enabled workflows. The Five-Year Trend Is Not Linear While the year-over-year movement between 2025 and 2026 provides a useful snapshot, it fails to capture the turbulent journey security executives have navigated. Looking across a five-year horizon exposes a profession that has been forced to constantly absorb and manage wave after wave of systemic change, rather than following a smooth, predictable curve of institutional maturity. The true value of this multi-year perspective is that it aggressively resists easy conclusions and oversimplified narratives. Attack expectations may have cooled slightly in 2026 following a notable peak in 2025, but they stubbornly remain well above the baseline levels recorded in 2022. Similarly, while reported instances of data loss fell year-over-year, more than half of all surveyed CISOs still grapple with material information loss, and overall organizational preparedness has barely budged. Meanwhile, board alignment rebounded in 2026 to reach its highest point across the entire five-year study, yet excessive stakeholder expectations rose concurrently. Taken together, these longitudinal data points paint a vivid picture of a security function that is successfully gaining visibility and executive support, while simultaneously being asked to govern an exponentially wider and more complex operating environment. AI Turned the CISO Agenda from Protection to Governance Nothing illustrates the rapid transformation of the modern enterprise operating environment quite like the advent and adoption of artificial intelligence. In 2024, roughly 54 percent of CISOs identified generative AI as a legitimate security risk. That figure climbed to 60 percent in 2025, before surging to a commanding 78 percent in 2026. Over that exact same timeframe, the corporate conversation surrounding AI shifted decisively from cautious experimentation to embedded daily use. Automated assistants, productivity copilots, machine learning models, and complex agentic workflows have become standard fixtures of daily operations. The instinct to restrict employee access to these potent new tools is entirely understandable, and a vast number of organizations have moved aggressively in that direction. In the 2026 findings, 78 percent of CISOs reported that their organizations actively block or restrict employee use of generative AI tools, a sharp jump from 59 percent just a year prior. However, institutional restriction is not the same thing as true governance. As AI becomes deeply embedded within corporate productivity suites, collaboration platforms, SaaS applications, and backend business workflows, a rudimentary allow-or-block model becomes far too blunt an instrument for the realities of modern work. The more durable and pressing question is whether modern enterprises can successfully govern artificial intelligence in proper context. Security leaders must grapple with complex questions: What specific data can an individual user access? What is the AI tool authorized to summarize, generate, or execute? And crucially, what happens when an automated assistant, agent, or workflow transcends answering simple questions to actively influencing commercial decisions or triggering automated enterprise actions? This operational reality transforms the AI conversation into an inherently data security conversation. AI-related risk is no longer solely about abstract prompts, foundational models, or algorithmic hallucinations. Instead, it centers on sensitive information, digital identity, granular permissions, user intent, and absolute control. This brings the resource allocation signal in the 2026 report into sharp focus. Fully 79 percent of CISOs report that they are expected to successfully manage complex AI-related risks without receiving a proportional increase in financial resources or specialized expertise. The primary gap is no longer mere awareness of the threat; it is an acute deficit in operational capacity. Human Risk Is No Longer a Soft Problem Across the entire five-year span of the research, human risk has consistently emerged as one of the most stubborn and prominent signals in enterprise cybersecurity. While the professional terminology has evolved over time—shifting gradually from traditional human error to the broader concept of human risk—the trajectory is unmistakable. The percentage of CISOs identifying human risk or error as their organization’s single biggest cyber vulnerability stood at 56 percent in 2022, climbed to 60 percent in 2023, jumped to 74 percent in 2024, registered at 66 percent in 2025, and reached a staggering 79 percent in 2026. This persistent trend demands a fundamental shift in how organizations discuss and approach the human element of security. Human risk is frequently relegated to the status of a routine training problem, easily remedied by annual awareness modules. Yet the 2026 data proves it is a much deeper systemic challenge. Among organizations that suffered material data loss, an overwhelming 93 percent reported that departing employees played a direct role in the incident. The leading root causes of material data loss span a multifaceted spectrum: malicious or criminal insiders, careless insiders, compromised accounts, the misuse or misconfiguration of AI tools, external cyber attacks, and third-party vendor compromises. In short, enterprise data loss increasingly occurs at the complex intersection of human behavior, digital identity, access privileges, modern tooling, and personal intent. This is precisely why human risk must be viewed as a systems problem that merely features a human interface. An individual user may be acting maliciously, operating carelessly, suffering a credential compromise, holding excessive permissions, working under poor governance, or simply operating inside a business process that grants them far more access than the organization can justify. While security awareness training retains a foundational role, it cannot possibly carry the burden of defense alone. Organizations must understand user behavior within its proper context: determining who the user is, what sensitive data they are touching, whether their access rights are appropriate, whether a specific action is anomalous, and whether a recent shift in role, employment status, or intent has fundamentally altered their risk profile. The Boardroom Is Closer to the Problem, But Not Necessarily Closer to Resolution The boardroom trend represents one of the most revealing signals in the five-year dataset, largely because its trajectory has been remarkably volatile rather than linear. In 2022, 51 percent of CISOs stated that their board of directors saw eye-to-eye with them on cybersecurity matters. That alignment rose to 62 percent in 2023 and climbed sharply to 84 percent in 2024, before dipping to 64 percent in 2025 and rebounding to 85 percent in 2026. This volatility is deeply significant. It indicates that while cybersecurity has firmly secured a permanent place on the board agenda, true alignment remains contingent upon how effectively security leaders can communicate and translate technical vulnerability into tangible commercial risk, operational resilience, regulatory exposure, and customer trust. The specific issues that corporate boards are perceived to care about reinforce this commercial framing. According to CISOs, their boards are intensely concerned with enterprise business valuation, significant operational downtime, reputational damage, the loss of sensitive information, business disruption, customer churn, and revenue contraction. That priority list reads much less like a traditional security operations dashboard and far more like a comprehensive enterprise risk agenda. This dynamic creates a profound opportunity for CISOs, but it simultaneously ratchets up expectations. In 2026, 77 percent of CISOs reported that excessive expectations are placed on their role, up from 66 percent in 2025 and a mere 49 percent in 2022. Achieving better board alignment has not made the CISO’s job lighter; instead, it has made the role vastly more visible, commercially integrated, and directly accountable for enterprise-wide risk spanning people, data, digital identity, artificial intelligence, regulation, and business continuity. The Next Phase of Resilience Will Be Decided Inside the Flow of Work The overarching practical takeaway from five years of comprehensive CISO data is not that the global threat landscape has somehow become less dangerous. Rather, it is that danger has become deeply and operationally embedded into everyday business functions. Modern security strategy must accurately reflect where work actually takes place. This requires treating digital identity, collaboration platforms, SaaS applications, cloud repositories, endpoints, APIs, automation engines, and AI systems as integral components of a single, unified risk fabric rather than as isolated control domains. For contemporary security leaders, several distinct operational priorities emerge. AI governance must be treated as a core data security and decision-control issue, extending well beyond basic acceptable-use policies. Human risk must be actively managed across the entire lifecycle of the employee, with particular attention paid to periods involving role changes, privilege expansion, contractor onboarding, and employee departures. Furthermore, board reporting must evolve away from tracking raw threat volumes toward articulating clear business consequences, helping directors understand precisely how cyber exposure maps directly to commercial valuation, operational uptime, customer trust, and regulatory impact. Finally, control effectiveness must be measured precisely where work happens, rather than solely relying on traditional security tools deployed at historical enterprise boundaries. Ultimately, cybersecurity’s center of gravity has fundamentally shifted away from the network perimeter and deep into the workflow. The modern enterprise is no longer secured solely by stopping malicious attacks at the edge. True security is achieved by understanding how people, data, identity, applications, and intelligent systems interact with one another every single day. That is the definitive CISO mandate for the years ahead: not simply to prevent the next isolated incident, but to actively help the business operate safely in the exact environments where risk and productivity have become permanently intertwined. Post navigation Sophisticated "Human-Operated Phishing Platform" Weaponizes AI Ad Tools to Hijack Enterprise Accounts Attackers Compromise Three ccTLDs to Obtain Unauthorized HTTPS Certificates for Google Domains