AI Policy & Regulation

Proofpoint report flags resourcing gap as Australian CISOs take on AI risk

Proofpoint's 2026 Voice of the CISO report finds 79% of Australian security chiefs are managing expanding AI risks without proportional increases in resources.

Proofpoint report flags resourcing gap as Australian CISOs take on AI risk

Key takeaways

  • Proofpoint's 2026 Voice of the CISO report, drawn from a survey of 100 Australian CISOs, found 79% are expected to manage expanding AI risks without a proportional increase in resources or expertise.
  • 85% of Australian CISOs view generative AI as a security risk, while 89% said enabling safe AI use is a top priority over the next two years.
  • The proportion of Australian organisations experiencing material data loss fell from 76% to 68% year-on-year, but direct financial losses among those affected jumped from 18% to 49%.
  • 83% of Australian CISOs now identify human risk as their organisation's biggest cyber vulnerability, up from 72% in 2025.
  • 78% of Australian CISOs believe their organisation faces a material cyberattack within 12 months; 68% said they are unprepared for a targeted attack.

What Happened

In-body image for: Proofpoint report flags resourcing gap as Australian CISOs take on AI risk
Illustrative AI-generated image by Mindiam (Flux 1.1 Pro Ultra)

Proofpoint published its 2026 Voice of the CISO report on 10 September 2026, drawing on a global survey of 1,600 CISOs across 16 countries. One hundred of those respondents were based in Australia. The research was conducted by Censuswide in May 2026 and covered organisations with 1,000 employees or more.

The headline finding for Australia: 79% of local CISOs are being asked to manage expanding AI-related risks without a proportional increase in resources or expertise. That sits alongside a broader anxiety about major incidents. The report found 78% of Australian CISOs believe their organisation is at risk of a material cyberattack in the next 12 months. Of those, 68% said they are unprepared to cope with a targeted attack.

Patrick Joyce, global resident CISO at Proofpoint, said the technology shift is redefining the role itself. "AI is fundamentally changing the CISO mandate," Joyce said. "Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed."

The report found 85% of Australian CISOs view generative AI as a security risk. At the same time, 89% said enabling safe AI use, covering AI assistants, copilots and automation, is a top priority over the next two years.


Why It Matters

The resourcing gap documented in the report has direct consequences for how Australian organisations handle breaches when they occur. Proofpoint found the proportion of Australian organisations experiencing material data loss fell year-on-year from 76% to 68%. Among those that did suffer breaches, though, the reported impacts grew sharply. Direct financial losses increased from 18% to 49%. Regulatory sanctions rose from 29% to 46%. Post-attack recovery costs increased from 26% to 43%, and reputational damage rose from 21% to 37%.

Those figures sit within a regulatory environment where the Office of the Australian Information Commissioner (OAIC) oversees mandatory data breach notification obligations under the Privacy Act 1988. The rising rate of regulatory sanctions in Proofpoint's data reflects a pattern consistent with increased enforcement activity across the sector.


Key Details

Human behaviour remains central to the risk picture. The report found 83% of Australian CISOs identify human risk as their organisation's biggest cyber vulnerability, up from 72% in 2025.

Among organisations that experienced material data loss, compromised insiders were cited as the leading cause at 50%, followed by careless insiders at 47% and malicious or criminal insiders at 44%. Separately, 90% of CISOs at organisations experiencing material data loss said departing employees played a role.

Proofpoint's commentary on the findings noted that AI is changing the nature of that human risk. "The human element remains the biggest cyber vulnerability for Australian organisations, but AI is changing what that risk looks like, which is increasingly about how people interact with AI, data and the applications they use every day," the report stated.

The report added: "For Australian organisations, this shift requires a different approach to cybersecurity, which need to understand behaviour and intent, rather than relying solely on policies or perimeter-based controls. As AI becomes embedded in our workspace, protecting data means securing the decisions and actions of both human and AI across the data lifecycle."


Background and Context

The Voice of the CISO report is an annual publication from Proofpoint. The 2026 edition marks the first year the survey has placed AI risk management at the centre of its findings for Australian respondents. Previous editions tracked metrics including attack preparedness and data loss, but the explicit framing around AI resourcing is new to this cycle.

The survey methodology, conducted by Censuswide in May 2026, covered organisations with at least 1,000 employees across 16 countries. The Australian cohort of 100 CISOs represents a consistent sample size with prior years, allowing year-on-year comparisons on metrics such as human risk perception and data loss rates.


What Comes Next

The report does not set out specific timelines or commitments from Proofpoint or the surveyed organisations. Joyce's comments indicate Proofpoint expects the dual mandate, securing the business while enabling AI adoption, to define the CISO role for the foreseeable future. The 89% of Australian CISOs who identified safe AI enablement as a top priority over the next two years suggests the resourcing question will remain a live issue through at least 2027.

Sources & citations

  1. Australian Cyber Security Magazine, "Proofpoint report flags resourcing gap as Australian CISOs take on AI risk," 10 September 2026
  2. Security Brief Australia, "Australian CISOs face rising AI risk duties at Proofpoint," 2026
JUST THE WEEKLY ROUNDUP

One Friday email. The five things AU operators actually need to know.

Operator-tested, primary-source linked, citation-first. Written by an operator, not a marketing team. Or, for a personalised view first, take our 90-second quiz.

Unsubscribe anytime. No spam. See our privacy policy.