UK CISOs tighten AI controls as board pressure rises
Tue, 15th Sep 2026 (Today)
Proofpoint has published research showing that UK Chief Information Security Officers are tightening controls on employees' use of generative AI tools. The findings also point to rising pressure on security leaders as boards demand more from them.
Its 2026 Voice of the CISO report found that 72% of UK CISOs now block or restrict employee use of generative AI, while 66% expect staff to use AI in ways that could expose sensitive data. The survey suggests concern about internal behaviour now sits alongside the more familiar threat of external attacks.
Proofpoint surveyed more than 1,600 CISOs at organisations with at least 1,000 employees across 16 countries, including 100 in the UK. In Britain, 74% of respondents said their organisation is at risk of a material cyberattack in the next 12 months, up from 63% a year earlier.
That rising sense of threat comes despite signs that organisations are getting better at preparing for incidents. Even so, 61% of UK CISOs said their organisation remains unprepared to cope with a targeted cyberattack.
Board pressure
The data points to a shift in the relationship between CISOs and company boards. Some 87% of UK respondents said they see eye-to-eye with their boards on cybersecurity, up from 57% in the previous survey, suggesting security discussions have moved closer to the centre of corporate oversight.
That improved alignment has not eased the pressure on security chiefs. Nearly three-quarters, or 74%, said excessive expectations are placed on them, while 85% said cybersecurity expertise should be required at board-director level, up from 63% a year earlier.
The report also indicates that AI has widened the remit of the CISO role. Four in five UK respondents said enabling the safe use of AI assistants, copilots and automation will be a top priority over the next two years. Yet 72% said they are expected to manage AI-related risks without a matching increase in resources or expertise.
Patrick Joyce, Global Resident CISO at Proofpoint, said the job is changing as AI tools move into daily business use.
"AI is fundamentally changing the CISO mandate.
"Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role."
Human risk
The study found that 69% of UK CISOs now identify human risk as their organisation's biggest cyber vulnerability, up from 60% a year earlier. That concern extends beyond current employees using AI tools inappropriately.
Departing staff emerged as a major source of data loss. Among UK CISOs whose organisations had experienced material data loss, 95% said departing employees played a role.
The report suggests internal risk is becoming more complex as work increasingly depends on connected platforms and identities. UK respondents highlighted software-as-a-service applications and third-party integrations, collaboration platforms, Active Directory and identity infrastructure, perimeter network devices, and AI assistants, copilots or autonomous agents among the main areas of concern.
Cost of breaches
While the proportion of organisations suffering data loss appears to have declined, the impact on those that did experience incidents has grown. Financial losses were cited by 40% of affected UK respondents, up from 24% a year earlier.
Regulatory sanctions rose from 30% to 35%, post-attack recovery costs increased from 26% to 36%, and reputational damage climbed from 36% to 45%. The figures suggest that when incidents do occur, they are becoming more expensive and more visible for companies.
Joyce said the overall picture is one of progress mixed with growing complexity.
"Improving resilience is an encouraging sign, but it doesn't mean the risk environment is becoming less complex.
"Risk is increasingly tied to how people, data, applications and AI interact every day, while CISOs are being asked to manage that exposure in business terms. The findings make clear that continued progress will depend on security strategies evolving alongside where both work and risk are headed."