Proofpoint report flags resourcing gap as Australian CISOs take on AI risk

Australian chief information security officers are increasingly being asked to manage artificial intelligence-related cyber risks without additional resources, according to findings from Proofpoint’s 2026 Voice of the CISO

Proofpoint report flags resourcing gap as Australian CISOs take on AI risk

Proofpoint report flags resourcing gap as Australian CISOs take on AI risk


Australian chief information security officers are increasingly being asked to manage artificial intelligence-related cyber risks without additional resources, according to findings from Proofpoint’s 2026 Voice of the CISO report.

The report, based on a global survey of 1,600 CISOs across 16 countries including 100 in Australia, found 79% of Australian CISOs are expected to manage expanding AI risks without a proportional increase in resources or expertise. Proofpoint said the research was conducted by Censuswide in May 2026 and surveyed CISOs at organisations with 1,000 employees or more.

Proofpoint’s data also suggests anxiety about major incidents remains high. The report said 78% of Australian CISOs believe their organisation is at risk of a material cyberattack in the next 12 months, while 68% said they are unprepared to cope with a targeted attack.

Alongside the broader threat environment, the report points to rising consequences when breaches occur. Proofpoint said the proportion of Australian organisations experiencing material data loss fell year-on-year from 76% to 68%, but those that suffered breaches reported larger impacts. Direct financial losses increased from 18% to 49%, regulatory sanctions rose from 29% to 46%, post-attack recovery costs increased from 26% to 43%, and reputational damage rose from 21% to 37%.

Proofpoint’s survey found AI adoption is contributing to a widening CISO mandate. The report said 85% of Australian CISOs view generative AI as a security risk, and 89% said enabling safe AI use—such as AI assistants, copilots and automation—is a top priority over the next two years.

“AI is fundamentally changing the CISO mandate,” said Patrick Joyce, global resident CISO at Proofpoint. “Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role.”

The report also highlights the role of human behaviour in cyber risk, with 83% of Australian CISOs identifying human risk as their organisation’s biggest cyber vulnerability, up from 72% in 2025. Among organisations that experienced material data loss, Proofpoint said compromised insiders were cited as the leading cause (50%), followed by careless insiders (47%) and malicious or criminal insiders (44%). The report added that 90% of CISOs at organisations experiencing material data loss said departing employees played a role.

Adrian Covich, vice president, systems engineering, Asia-Pacific and Japan for Proofpoint, said the rise of AI changes how organisations need to understand user behaviour. “The human element remains the biggest cyber vulnerability for Australian organisations, but AI is changing what that risk looks like, which is increasingly about how people interact with AI, data and the applications they use every day,” Covich said. “For Australian organisations, this shift requires a different approach to cybersecurity, which need to understand behaviour and intent, rather than relying solely on policies or perimeter-based controls. As AI becomes embedded in our workspace, protecting data means securing the decisions and actions of both human and AI across the data lifecycle.”

Proofpoint’s report suggests boards are taking a closer interest in cyber risk, but that alignment does not necessarily reduce expectations on security leaders. The survey found 91% of Australian CISOs said they see eye-to-eye with their boards on cybersecurity, up from 82% in 2025, while 83% said excessive expectations are placed on them. It also found 90% believe cybersecurity expertise should be required at the board-director level, up from 77% in 2025.

The full 2026 Voice of the CISO report is available via Proofpoint’s website.

You can read the full report here.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.