58% of organizations are unprepared for cyberattacks

Written on Sep 11, 2025

Proofpoint has released its most recent Voice of the CISO report, surveying 1,600 CISOs across 16 countries to better understand their challenges, expectations and priorities for the next two years. The report found two notable trends: increases in cyberattacks are raising anxiety among CISOs and genAI is causing cyber leaders to balance innovation and risk.  

As cyberattacks become more sophisticated and frequent, CISOs express concern about their organization’s defensive abilities, with 76% feeling at risk of a cyberattack in the next 12 months. CISOs concerns about experiencing a cyberattack are not unfounded, as two-thirds faced material data loss this past year. Insider concerns were the most prominent data loss risk, with 92% citing at least some data loss to departing employees. 

GenAI is both a priority and a risk factor for CISOs, according to the report. Over the next two years, establishing genAI tool usage will be a strategic priority for 64% of global CISOs; yet, in the United States, 80% express concern over possible customer data loss through public genAI platforms.  

Despite these concerns, most organizations are not ready to secure against these evolving threats. More than half (58%) report they are unprepared to respond to potential attacks. In the event that a malicious actor ransoms organizational data, 66% of CISOs claim they would consider paying it if it meant restoring systems or preventing data leaks.