Cyber resilience appears to be improving among organisations in the UAE, but cybersecurity leaders are facing a more complex risk environment as artificial intelligence becomes increasingly embedded in business operations, according to Proofpoint’s 2026 Voice of the CISO report.
The report found that the proportion of UAE chief information security officers (CISOs) who believe their organisations are at risk of a material cyberattack in the next 12 months fell to 49% in 2026, compared with 69% in 2025. The percentage reporting material data loss also declined, from 77% to 50%.
However, the findings indicate that declining incident expectations have not reduced pressure on CISOs. Risks are increasingly concentrated around employees, sensitive data, applications and AI systems used in day-to-day business operations.
The global study surveyed 1,600 CISOs across 16 countries, including the UAE.
AI becomes a growing responsibility for CISOs
GenAI security concerns among UAE CISOs increased by 19 percentage points year on year, with 73% now identifying generative AI as a security risk.
At the same time, 86% of CISOs said enabling the safe use of AI assistants, copilots and automation will be a top priority over the next two years. Yet 75% expect to manage AI-related risks without a proportional increase in resources or expertise.
Patrick Joyce, global resident CISO at Proofpoint, said AI is changing the responsibilities of security leaders as organisations seek to adopt new technologies while managing associated risks.
“As AI assistants, copilots, automation, and public GenAI tools become embedded in everyday business processes, CISOs are relied on to enable innovation while preventing sensitive data, privileged access, and critical workflows from being exposed,” Joyce said.
Human behaviour remains a major cyber vulnerability
The report found that 73% of UAE CISOs identify human risk as their organisation’s biggest cyber vulnerability, up from 57% in 2025.
Among organisations that experienced material data loss, malicious or criminal insiders and careless insiders were each cited as leading causes by 52% of CISOs, while compromised insiders were identified by 32%.
Departing employees were also a significant concern. Among organisations that experienced material data loss, 90% of UAE CISOs said departing employees played a role.
The findings suggest that employee behaviour remains a key factor in an increasingly complex cybersecurity environment, particularly as workers gain access to AI tools and cloud-based applications.
Cyber resilience improves but risks are shifting
Despite the improvement in perceived cyber resilience, 40% of UAE CISOs said their organisations remain unprepared to cope with a targeted cyberattack.
The technologies and systems generating the greatest concern include public generative AI tools and Microsoft 365, each cited by 36% of respondents. Active Directory and identity infrastructure followed at 35%, while SaaS applications and third-party integrations, as well as APIs and automation tools, were each cited by 34%.
The report indicates that cybersecurity risks are increasingly connected to technologies that have become integral to everyday work rather than being confined to traditional IT infrastructure.
Data loss incidents decline but impact becomes more severe
While the proportion of organisations experiencing material data loss dropped from 77% in 2025 to 50% in 2026, the consequences reported by affected organisations became more severe in several areas.
Regulatory sanctions increased from 36% to 46%, while financial losses doubled from 22% to 46%. Reputational damage also rose sharply, from 18% to 50%.
Meanwhile, post-attack recovery costs declined from 47% to 34%.
CISOs concerned about employee use of AI
UAE CISOs generally expressed confidence in their existing cybersecurity controls, with 83% saying their controls effectively mitigate risks associated with AI, SaaS and modern working practices.
However, 70% believe employees are likely to use AI in ways that could expose sensitive information. Customer data loss through public GenAI tools is a concern for 75% of CISOs, while 69% said their organisations block or restrict employee use of GenAI.
The figures highlight a gap between confidence in technical controls and concerns about how employees may use emerging AI tools.
Board-level cybersecurity expectations increase
The report also found stronger alignment between CISOs and corporate boards. 81% of UAE CISOs said they see eye-to-eye with their boards on cybersecurity, up from 57% in 2025.
At the same time, security leaders continue to face growing expectations. Three-quarters of UAE CISOs said excessive expectations are placed on them.
Boards are increasingly assessing cyber risk in commercial terms, including enterprise value, downtime, reputational damage, operational disruption and the loss of sensitive data.
Meanwhile, 84% of UAE CISOs believe cybersecurity expertise should be required at the board-director level, compared with 61% in 2025.
Joyce said improving resilience was encouraging, but warned that the changing nature of risk requires cybersecurity strategies to evolve alongside new ways of working.
“Risk is increasingly tied to how people, data, applications, and AI interact every day, while CISOs are being asked to manage that exposure in business terms,” he said.

Comments
0 commentsNo comments yet. Be the first to share your thoughts!