www.proofpoint.com CISOs Report Shifting Cyber Risk Landscape in 2026
Article Content
- •74% of CISOs identify human error as the top cybersecurity risk.
- •87% of CISOs are leveraging AI technologies to combat human-centric threats.
- •Over half of CISOs still report material loss of sensitive information.
The 2026 Voice of the CISO report reveals a significant shift in cybersecurity risks, with fewer CISOs expecting material cyberattacks compared to 2025. However, human error remains a critical vulnerability, identified by 74% of CISOs. The report highlights a growing reliance on AI technologies, with 87% of CISOs using AI to mitigate human error. Despite improvements in confidence, over half of CISOs still report material loss of sensitive information. The evolving nature of work, including cloud platforms and AI workflows, has changed the focus of cybersecurity from merely preventing attacks to governance and data protection. The findings indicate that while there are signs of progress, the overall landscape remains complex and challenging for security leaders.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Common questions
What are the main findings of the 2026 report?
How are CISOs addressing human error?
What trends are emerging in cybersecurity risk?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…