ChannelLife Australia - Industry insider news for technology resellers
Australia
Australian CISOs face rising AI risk duties at Proofpoint

Australian CISOs face rising AI risk duties at Proofpoint

Thu, 10th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Proofpoint has released research showing Australian Chief Information Security Officers are taking on expanding artificial intelligence risk management duties without matching increases in resources or expertise. The findings point to rising pressure on security leaders as breach costs intensify.

Its 2026 Voice of the CISO study found 79% of Australian CISOs were expected to manage AI-related risks without a proportional increase in support, while 85% said generative AI posed a security risk. At the same time, 89% said enabling the safe use of AI assistants, copilots and automation would be a top priority over the next two years.

The results suggest the CISO role is widening as businesses adopt AI tools across routine work. Security leaders are being asked not only to defend their organisations against cyber threats, but also to oversee how staff use AI systems that can expose sensitive information through everyday tasks.

Threat expectations remain high. Some 78% of Australian CISOs believed their organisation was at risk of a material cyberattack in the next 12 months, while 68% said it remained unprepared to cope with a targeted attack.

The survey also showed that although the share of organisations suffering material data loss fell to 68% from 76% a year earlier, the consequences for those affected had become more severe. Direct financial losses rose to 49% from 18%, regulatory sanctions increased to 46% from 29%, post-attack recovery costs climbed to 43% from 26%, and reputational damage reached 37% from 21%.

Human risk

Employee behaviour remained the dominant concern in the Australian findings. More than four in five respondents, or 83%, identified human risk as their organisation's biggest cyber vulnerability, up from 72% the previous year.

Among organisations that experienced material data loss, compromised insiders were cited as the leading cause by 50% of CISOs. Careless insiders were named by 47%, while 44% pointed to malicious or criminal insiders. Among CISOs at organisations that experienced material data loss, 90% believed departing employees had played a role.

Concern over staff use of AI was also prominent. The report found 83% of Australian CISOs believed employees were likely to use AI in ways that could expose sensitive data, 78% were concerned about customer data loss through public generative AI tools, and 84% said their organisations blocked or restricted employee use of generative AI.

Areas of concern are no longer limited to conventional network defences. CISOs increasingly pointed to technologies embedded in daily work, including public generative AI tools, software-as-a-service applications and third-party integrations, collaboration platforms, AI assistants and cloud storage services.

Patrick Joyce, Global Resident CISO at Proofpoint, said the job now involves balancing defensive work with business demands to adopt AI. "AI is fundamentally changing the CISO mandate," said Patrick Joyce, Global Resident CISO at Proofpoint. "Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role."

Board pressure

The findings also showed a shift in board-level engagement with cyber risk. Some 91% of Australian CISOs now felt they saw eye-to-eye with their boards on cybersecurity, compared with 82% a year earlier.

That stronger alignment has not reduced the strain on security leaders. The survey found 83% said excessive expectations were placed on them, while 90% believed cybersecurity expertise should be required at board-director level, up from 77% the year before.

Boards were described as viewing cyber risk increasingly through a commercial lens, with concern centred on enterprise value, downtime, reputational damage, operational disruption and the loss of sensitive data. That may help explain why the rise in financial and regulatory consequences from breaches has become a more prominent issue for security leaders.

Proofpoint's Australian results formed part of a wider study of more than 1,600 CISOs at organisations with at least 1,000 employees across 16 countries. The research covered 100 CISOs in each market.

Adrian Covich, Vice President, Systems Engineering, Asia-Pacific & Japan, at Proofpoint, said the spread of AI into standard business software had altered the nature of cyber risk. "The human element remains the biggest cyber vulnerability for Australian organisations, but AI is changing what that risk looks like, which is increasingly about how people interact with AI, data and the applications they use every day," said Adrian Covich, Vice President, Systems Engineering, Asia-Pacific & Japan, at Proofpoint. "For Australian organisations, this shift requires a different approach to cybersecurity, which needs to understand behaviour and intent rather than rely solely on policies or perimeter-based controls. As AI becomes embedded in the workspace, protecting data means securing the decisions and actions of both human and AI across the data lifecycle."