thehackernews.com 7 Oct 2026, 11:57 UTC

79% of CISOs Must Manage AI Risk Without More Resources or Expertise

THE Hacker News article discusses Proofpoint’s 2026 Voice of the CISO findings, which show cyber risk is moving inside the organisation’s actual workflows rather than just up at the perimeter. Over five years, the centre of gravity has shifted: AI governance has moved from a creeping concern to a defined mandate, while the work itself—across people, cloud platforms, collaboration tools, SaaS, and AI-enabled workflows—has become the primary battleground.

The 2026 results indicate progress in some areas (fewer CISOs expect a material attack in the next 12 months and fewer report material data loss than in 2025), but the longer view reveals a more complex picture: attack expectations have fluctuated above 2022 levels, and human risk remains central. A striking figure is that 79% of CISOs say they are expected to manage AI-related risks without a proportional increase in resources or expertise, underscoring an enduring capacity gap.

The piece highlights several practical implications for security leadership. AI risk is framed as a data security and decision-control issue—questions of who can access data, what an AI tool can summarise or act on, and what happens when automation influences decisions. Human risk is treated as a systems problem tied to the employee lifecycle, with 93% of organisations experiencing material data loss citing departing employees as a factor.

Board engagement remains volatile but has grown overall, with alignment rising to 85% in 2026, while excessive expectations on CISOs have also increased to 77%. The article concludes that resilience now hinges on protecting data and productivity where work occurs, not just on defending the perimeter.

View full article

Article by CyberSIXT