Security News

Australian CISOs Told to Manage AI Risk Without Extra Resources, Report Finds

Key Takeaway Small businesses adopting AI tools should pair that adoption with clear data handling and access rules, since under-resourced oversight increases the risk and cost of a breach.

A new global survey from Proofpoint has found that 79% of Australian chief information security officers are expected to manage expanding AI-related risks without a matching increase in resources or expertise. The 2026 Voice of the CISO report surveyed 1,600 CISOs across 16 countries, including 100 in Australia, at organisations with 1,000 or more employees.

The report also found continued unease about major incidents, with 78% of Australian CISOs believing their organisation is at risk of a material cyberattack in the next 12 months, and 68% saying they are unprepared for a targeted attack. While the share of Australian organisations reporting material data loss fell from 76% to 68% year-on-year, the consequences of breaches that did occur grew sharply: direct financial losses rose from 18% to 49%, regulatory sanctions from 29% to 46%, recovery costs from 26% to 43%, and reputational damage from 21% to 37%.

AI adoption is adding to the pressure on security leaders. The report found 85% of Australian CISOs view generative AI as a security risk, while 89% said enabling safe use of AI tools such as assistants, copilots and automation is a top priority over the next two years. Proofpoint's Patrick Joyce said CISOs are increasingly expected to both protect the business from technology risk and help it adopt AI safely, calling this dual responsibility one of the defining challenges of the role.

AI security CISO report data breach costs Proofpoint Australian businesses
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Australian Cyber Security Magazine. We link back to every original so you can read it yourself.