A newly compiled five-year analysis of global CISO survey data — covering 2022 through 2026 and drawing on roughly 1,600 security leaders worldwide — points to a profession whose center of gravity has shifted. The threat hasn't disappeared from the network perimeter; it has moved inside the daily flow of work, following identity, data, and AI tools wherever employees now operate.
What the data shows
The year-over-year numbers for 2026 look like modest good news: fewer CISOs expect a material cyberattack in the next 12 months compared with 2025, and fewer report a material loss of sensitive data. But the five-year arc tells a less settled story. Attack expectations cooled in 2026 after peaking in 2025, yet remain above 2022 levels. More than half of CISOs still report material data loss, and organizational preparedness has barely moved.
Three trends stand out.
AI governance has overtaken AI restriction. The share of CISOs who see generative AI as a security risk climbed from 54% in 2024 to 60% in 2025 and 78% in 2026. Many organizations responded by locking the tools down — 78% now block or restrict employee use of GenAI, up from 59% a year earlier. But as AI becomes embedded in everyday productivity, collaboration, and SaaS tools, a blanket block-or-allow policy is losing its usefulness. 79% of CISOs say they're expected to manage AI-related risk without a matching increase in resources or expertise.
Human risk keeps climbing. The share of CISOs naming human error or human risk as the single biggest vulnerability rose from 56% in 2022 to 79% in 2026. Among organizations that experienced material data loss, 93% said departing employees played a role — pointing to insider behavior, access mismanagement, and misuse of AI tools as recurring factors, alongside external attacks and third-party compromise.
Boards are paying more attention — and expecting more in return. CISOs reporting that their board is fully aligned with them on cybersecurity swung from 51% in 2022 up to 84% in 2024, dipped to 64% in 2025, then rebounded to 85% in 2026. Over the same period, the share who say excessive expectations are placed on the CISO role rose from 49% to 77%. Better board alignment hasn't made the job lighter — it's made it more visible, more commercial, and more accountable.
Why it matters
The underlying shift is that cyber risk no longer lives mainly at the network edge. It lives wherever people, data, identity, and AI-enabled workflows intersect — in SaaS apps, collaboration platforms, and automated processes that barely featured in risk models a few years ago. Treating human risk as a one-off training issue, or AI governance as a simple access toggle, is no longer enough to keep pace with how risk is actually distributed across a modern organization.
What to do
- Govern AI tools in context rather than with blanket block/allow rules — track what data a tool can access, what it's permitted to generate or act on, and what happens when it moves from answering questions to triggering actions.
- Treat human risk as a continuous, identity-driven signal rather than a training checkbox — pay particular attention to access and behavior changes around role changes, privilege expansion, contractor access, and employee departures.
- Reframe board reporting around business consequence — valuation, downtime, customer trust, and regulatory exposure — rather than raw threat counts, to keep alignment durable as expectations rise.
