The Proofpoint Voice of the CISO report returned on September 10, 2026 with a stark headline for India. 93 percent of Indian CISOs now identify human risk as their organization’s biggest cyber vulnerability, up from 67 percent in 2025. It also found that 92 percent of Indian CISOs prioritize enabling safe use of AI assistants, copilots, and automation over the next two years. That same proportion expects to manage the risks without additional resources or expertise.
Censuswide conducted the global study in May 2026, polling 1,600 CISOs across 16 countries with 100 respondents per market. All surveyed organizations have 1,000 or more employees. Patrick Joyce, global resident CISO at Proofpoint, framed the findings around a dual mandate. CISOs must protect the business from technology risk while helping it embrace transformative technology safely.
The numbers point to a role under strain. Expectations of a material cyberattack within 12 months rose from 90 percent in 2025 to 94 percent in 2026. Reported material data loss declined from 99 percent to 76 percent. Yet 77 percent of Indian CISOs still say their organization is unprepared to cope with a targeted attack.
What the Proofpoint Voice of the CISO Report Says About India
The findings cluster around three themes. First, human risk has become the dominant concern. Malicious or criminal insiders led the causes of material data loss at 47 percent. Careless insiders followed at 41 percent, with compromised insiders at 38 percent. Notably, 82 percent of Indian CISOs at organizations experiencing material data loss say departing employees played a role.
Second, AI has expanded the CISO mandate. Indian GenAI security concerns jumped 17 percentage points year-over-year to 92 percent. The same share says enabling safe AI use is a top priority, while also being expected to manage the risks without additional resources.
Concern increasingly centers on technologies embedded in everyday work. AI assistants, copilots, and autonomous agents lead at 42 percent. Collaboration platforms and Active Directory each rank at 34 percent, followed by SaaS applications at 31 percent and public generative AI tools at 30 percent.
Third, the consequences of data loss are getting worse even as incidence declines. Among organizations that suffered material data loss, regulatory sanctions rose from 34 percent to 45 percent, and financial losses climbed from 29 percent to 43 percent. Post-attack recovery costs surged from 28 percent to 45 percent, while reputational damage grew from 33 percent to 39 percent.
Board dynamics have also shifted. 93 percent of Indian CISOs say they see eye-to-eye with their boards, up from 72 percent in 2025. But alignment has not reduced pressure. Fully 87 percent report excessive expectations. Another 94 percent believe boards should require cybersecurity expertise at the director level, up from 64 percent in 2025.
The Vendor Commissioned the Survey, and Sells the Cure
The report’s most important context sits in its About section. Proofpoint describes itself as a global leader in human and agent cybersecurity. Its platform secures how people, data, and AI agents connect across email, cloud, and collaboration tools.
Every headline finding maps to a product Proofpoint sells. Human risk as the top vulnerability maps to ZenGuide, the company’s security awareness training product. Departing-employee data loss maps to its insider threat management suite. Employee misuse of AI tools maps to Acuvity, an AI security acquisition completed in February 2026.
This does not make the findings false. It makes them a demand-generation instrument. The framing of CISOs as overburdened leaders who must “do more with less” is also a sales argument. The implied solution is automation, which vendors like Proofpoint sell.
Proofpoint has a significant commercial stake in this narrative succeeding. Thoma Bravo took the company private in 2021 in a $12.3 billion deal, the largest software take-private at the time. Its annual recurring revenue reached $2.45 billion exiting 2025. CEO Sumit Dhawan has repositioned the company around the exact themes this report elevates: people, data, and AI agents.
In July 2026, reports emerged that AI concerns affected the pricing of Proofpoint’s $5 billion debt refinancing. That raises the commercial stakes on its AI-security narrative even further.
The Sample Size Problem: 100 CISOs
The India findings rest on 100 CISO interviews. At that sample size, the margin of error is roughly plus or minus 10 percentage points at 95 percent confidence. Year-over-year comparisons at this scale are inherently noisy. A jump from 67 percent to 93 percent is large enough to be directionally meaningful. Smaller shifts, like the move from 72 to 93 percent board alignment, deserve more skepticism.
The report also does not define what qualifies as “material” data loss. This omission matters when reading the headline decline from 99 percent to 76 percent. The 2025 figure meant essentially every surveyed Indian organization had lost sensitive data. That was the highest rate globally and far above the 66 percent global average.
A figure that extreme invites questions about question framing and how respondents interpreted the threshold. This year’s decline may reflect genuine improvement, changing interpretation, or both.
The sample is also limited to organizations with 1,000 or more employees. That threshold excludes most Indian businesses. It leaves out the mid-market and SME segment that employs most of the country’s workforce. The report describes Indian CISO sentiment, not Indian organizational sentiment.
The Contradictions CISOs Are Living With
The report contains internal tensions that deserve attention. 94 percent of Indian CISOs believe their controls effectively mitigate risks from AI, SaaS, and modern work patterns. Yet 77 percent say their organization is unprepared for a targeted cyberattack. Both cannot be fully true simultaneously.
Similarly, 92 percent say enabling safe AI use is a top priority. Meanwhile, 91 percent block or restrict employee GenAI use, up from 74 percent in 2025. Blocking and enabling are opposing strategies. The coexistence of both figures suggests organizations are running parallel tracks: restricting access today while building governance for tomorrow. That tension is precisely the gap vendors pitch their products into.
What Independent Data Shows
External evidence supports parts of the report. IBM’s 2026 Cost of a Data Breach Report, using a separate methodology, found that India’s average breach cost hit a record Rs 25.5 crore. That represents a 15.9 percent year-over-year increase. It independently corroborates the Proofpoint finding that data loss consequences are growing more severe.
IBM also found that shadow AI, meaning employee use of unsanctioned AI tools, added an average of Rs 1.79 crore to breach costs where present. Shadow AI ranked among India’s top three breach cost amplifiers. 26 percent of malicious breaches in India were AI-generated. These figures align with a report finding: 79 percent of Indian CISOs expect employees to expose sensitive data through AI use.
The regulatory sanction finding also has structural support. India notified its Digital Personal Data Protection Rules in November 2025. Substantive obligations and penalties of up to Rs 250 crore take effect in May 2027. The Data Protection Board is being constituted through 2026. Rising regulatory consequences for data loss are not just CISO perception; they are written into law with a compliance deadline.
The Competitive Context: Everyone Is Selling Human Risk
Proofpoint is not the only vendor telling this story. KnowBe4, owned by Vista Equity Partners, is the most widely deployed security awareness platform. It positions itself as a human risk management suite. Mimecast, owned by Permira, has built a Human Risk Management platform on top of its email security base. Abnormal Security raised $250 million in 2026 at a $5.1 billion valuation on the strength of AI-driven email security.
Microsoft bundles Attack Simulation Training into Defender for Office 365 at effectively no incremental cost.
Every one of these companies benefits from the same narrative. Humans are the biggest vulnerability, AI is making it worse, and the answer is a platform purchase. The Proofpoint Voice of the CISO report is the most visible annual expression of that shared commercial thesis. Buyers reading it should weigh it accordingly, alongside independent sources such as the IBM report and India’s regulatory calendar.

What to Watch
Three signals will determine whether the 2026 findings hold. First, whether the 93 percent human-risk figure stabilizes or reverses in the 2027 edition. That would indicate whether the jump was a trend or a measurement artifact. Second, whether Indian organizations move from restriction to governance on AI, shifting the 91 percent blocking figure downward. Third, whether the DPDPA’s May 2027 compliance deadline turns the rising sanction figures into actual penalties.
The report’s core message is credible but commercially convenient. Human risk is real, AI is expanding the attack surface, and Indian CISOs are under-resourced. The evidence from independent sources supports the direction. The precise percentages, drawn from 100 respondents and framed by a vendor selling the remedy, deserve a more skeptical reading.
Editor’s Note
This article was produced using the TechRecast editorial framework, which applies a six-layer analytical process to press releases. Sources include the Proofpoint 2026 Voice of the CISO press release dated September 10, 2026; Proofpoint’s 2025 Voice of the CISO report India findings from August 2025; Proofpoint corporate disclosures including its February 2026 fiscal 2025 results blog post by CEO Sumit Dhawan; the Thoma Bravo acquisition announcement from August 2021; IBM’s 2026 Cost of a Data Breach Report India findings from August 2026; India’s Digital Personal Data Protection Rules 2025 as notified on November 13, 2025; Revelio Labs workforce data on Proofpoint; Private Equity Wire reporting on Proofpoint’s July 2026 debt refinancing; and industry analysis of the security awareness and human risk management market including KnowBe4, Mimecast, Abnormal Security, and Microsoft competitor positioning.
All survey statistics cited, including the 93 percent human risk figure, the 92 percent AI priority and resource gap figures, the 94 percent attack expectation, the 76 percent material data loss figure, the 91 percent GenAI restriction figure, the insider cause breakdown, the consequence escalation figures, and the board alignment figures, are from the Proofpoint-commissioned Censuswide survey of 1,600 CISOs conducted in May 2026. India results are based on 100 respondents at organizations of 1,000 or more employees. These are company-commissioned survey findings, not independently audited measurements.
Independently verified data includes Proofpoint’s $12.3 billion Thoma Bravo take-private in August 2021; Proofpoint’s $2.45 billion ARR exiting 2025; the Acuvity acquisition announced February 2026; IBM’s Rs 25.5 crore average India breach cost figure; the DPDPA penalty framework of up to Rs 250 crore with the May 13, 2027 compliance deadline; and the November 13, 2026 Consent Manager phase-in date.
Uncertain or unverified items include Proofpoint’s precise current headcount, with estimates ranging from roughly 3,800 to 6,580 depending on the source, and the sampling methodology and panel composition of the Censuswide survey beyond what the press release discloses. The margin of error calculation of approximately plus or minus 10 percentage points is our analytical estimate for a sample of 100 respondents, not a figure disclosed by Proofpoint.
Contact: techrecasteditor@gmail.com

