The Proofpoint 2026 Voice of the CISO report highlights a significant improvement in UAE cyber resilience, with expected material attacks dropping to 49%. Despite this progress, human risk is at an all-time high, and CISOs face mounting pressure to secure AI systems without additional resources. The study also notes better board alignment, though expectations for security leaders remain exceptionally high.
Yet progress has not made the CISO’s job simpler. The global study of 1,600 CISOs across 16 countries, including the UAE, finds risk increasingly concentrated in the people, data, applications, and AI systems embedded in everyday work. Human risk is rising, with 73% of CISOs in the UAE now identifying it as their organization’s biggest cyber vulnerability, up from 57% in 2025. With that, the consequences of data loss are becoming more severe, and CISOs in the country are assuming greater responsibility for enabling AI securely—with 75% expected to manage AI-related risks without a proportional increase in resources or expertise in the next two years.
“AI is fundamentally changing the CISO mandate,” said Patrick Joyce, global resident CISO at Proofpoint. “Security leaders are being asked to do two things at once: protect the business from technology risk and help it embrace transformative technology safely and rapidly. As AI assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed. That dual responsibility is quickly becoming one of the defining challenges of the role.”
Key findings in the UAE from the 2026 Voice of the CISO report include:
- CISOs are now expected to secure and champion AI. GenAI security concerns in the UAE jumped 19 percentage points year over year, with 73% of CISOs now viewing it as a security risk. At the same time, 86% say enabling the safe use of AI assistants, copilots, and automation is a top priority over the next two years, while 75% are expected to manage AI-related risks without a proportional increase in resources or expertise.
- Cyber resilience improves, but the risk model is changing. Expectations of a material cyberattack in the UAE fell from 69% in 2025 to 49% in 2026, while material data loss declined from 77% to 50%. Yet 40% of CISOs in the UAE still say their organization is unprepared to cope with a targeted cyberattack. Concern is increasingly centered on technologies embedded in everyday work, including Public generative AI tools (36%), Microsoft 365 (36%), Active Directory / Identity infrastructure (35%), SaaS applications and third-party integrations (34%), and APIs and automation tools (34%).
- The biggest risk is employee behavior. 73% of CISOs in the UAE identify human risk as their organization’s biggest cyber vulnerability, up from 57% in 2025. Among organizations that experienced material data loss, malicious or criminal insiders and careless insiders were the leading causes, each cited at 52%, while compromised insiders were cited at 32%. Notably, 90% of CISOs at organizations experiencing material data loss in the UAE say departing employees played a role.
- Data loss declines, but the consequences grow. While the proportion of organizations experiencing material data loss in the UAE declined year over year—from 77% in 2025 to 50% in 2026—the business impact for those that did suffer data loss became more severe. Regulatory sanctions rose from 36% to 46%, while financial losses increased from 22% to 46%. Post-attack recovery costs fell from 47% to 34%, and reputational damage increased from 18% to 50%.
- CISOs trust their defenses, but not their own employees’ AI habits. While 83% of CISOs in the UAE believe their controls effectively mitigate risks introduced by AI, SaaS, and modern work patterns, 70% believe employees are likely to use AI in ways that could expose sensitive data. 75% are concerned about customer data loss through public GenAI tools, and 69% block or restrict employee GenAI use.
- Boards are listening to CISOs more and expecting more in return. 81% of CISOs in the UAE say they see eye-to-eye with their boards on cybersecurity, up significantly from 57% in 2025. But greater alignment is not reducing pressure on security leaders. Boards are evaluating cyber risk through a commercial lens, with enterprise value, downtime, reputational damage, operational disruption, and sensitive data loss among their top concerns. 75% of CISOs in the UAE say excessive expectations are placed on them. 84% believe cybersecurity expertise should be required at the board-director level, up from 61% in 2025.
“Improving resilience is an encouraging sign, but it doesn’t mean the risk environment is becoming less complex,” said Patrick Joyce. “Risk is increasingly tied to how people, data, applications, and AI interact every day, while CISOs are being asked to manage that exposure in business terms. The findings make clear that continued progress will depend on security strategies evolving alongside where both work and risk are headed.”




