Proofpoint’s latest Voice of the CISO report highlights how UAE CISOs are grappling with insider threats, AI governance and mounting cyber risks. With 100% linking data loss to departing employees and 55% concerned about customer data exposure via public GenAI tools, the pressure on security leaders has never been greater.
Proofpoint’s 2025 Voice of the CISO report has AI governance and insider threats emerging as top priorities for UAE security leaders.
The fifth annual report reveals 100% of UAE CISOs linking data loss to departing employees, making insider risk a critical vulnerability.
Fifty-five per cent of UAE CISOs worry customer data is at risk via public GenAI tools and 60% are shown as prioritising safe GenAI use – with 59% enforcing guidelines and 58% exploring AI defences.
The 2025 edition of the report explores the perspectives of 1,600 CISOs across 16 countries, including the UAE, shedding light on the evolving pressures, priorities and realities of defending organisations against today’s most advanced cyber threats.
The 2025 report underscores two interconnected themes: the growing impact of artificial intelligence – both as a driver of innovation and as an amplifier of risk – and the unrelenting challenge of insider-driven data loss. For CISOs in the UAE, these issues have become central to their cybersecurity strategies, influencing investment priorities, boardroom discussions and day-to-day defence decisions.
Rising cyber threats: confidence vs capability
Across the UAE, security leaders are contending with a volatile threat landscape where cyberattacks are no longer a matter of if but when. According to Proofpoint’s 2025 data, 69% of CISOs in the UAE believe their organisations are likely to face a material cyberattack within the next year. This level of perceived risk is consistent with last year’s figures, reflecting the sustained pressure CISOs feel amid escalating digital threats.
Yet confidence in readiness tells a different story. 56% of UAE CISOs admit they are unprepared to respond to such an attack, exposing a troubling disconnect between security aspirations and operational capability. This readiness gap is particularly concerning given the 77% of organisations that experienced material data loss in the past 12 months – a sharp increase from 45% reported in 2024.
This mismatch between perception and preparedness is a recurring theme globally. Many CISOs express optimism in surveys about the maturity of their cybersecurity programmes, yet actual incident data reveals persistent weaknesses. The situation in the UAE mirrors this trend, illustrating the immense complexity security leaders must navigate as they balance rising threats, constrained resources and heightened expectations from both boards and regulators.
Insider threats: data doesn’t walk out the door alone
One of the starkest findings in the 2025 report relates to insider risk. Every single CISO surveyed in the UAE (100%) confirmed that departing employees contributed to data loss incidents in the past year, up dramatically from 64% in 2024. This makes insider-driven risk one of the most critical vulnerabilities facing organisations in the region.
Despite widespread adoption of data loss prevention (DLP) solutions, 42% of UAE CISOs still believe their sensitive data is inadequately protected. Departing employees, whether through negligence or malice, remain a consistent weak point—often walking away with intellectual property, customer records or sensitive financial information that can damage reputation and competitiveness.
The insider threat problem is compounded by human error, which continues to top the list of vulnerabilities with 57% of CISOs in the UAE identifying people as their organisation’s greatest cybersecurity risk, despite 59% believing employees have a strong understanding of security best practices. This highlights a critical paradox: awareness is not translating into consistent secure behaviour.
A lack of dedicated insider risk management resources worsens the issue. Nearly one in four UAE organisations still do not have specialised teams or programmes focused on insider threats, underscoring the gap between recognising the problem and investing in meaningful solutions.
The AI balancing act: opportunity and risk
Few topics have dominated boardroom and security discussions in 2025 as much as artificial intelligence—particularly generative AI (GenAI). For CISOs, AI presents a double-edged sword: a transformative technology that can supercharge productivity and defences but also a potential backdoor for new sophisticated threats.
In the UAE, 60% of CISOs say enabling the safe use of GenAI tools is a strategic priority over the next two years. However, enthusiasm is tempered by real security concerns: 55% of CISOs worry about customer data loss via public GenAI platforms, particularly when employees input sensitive information into unsecured chatbots and collaboration tools.
Organisations are shifting from blanket restrictions to structured governance with 59% of UAE CISOs have implemented usage guidelines and 58% are actively exploring AI-powered security solutions to defend against AI-driven attacks. Yet, compared to last year’s figure of 89% expressing excitement about AI’s potential, enthusiasm has cooled – suggesting that real-world challenges are beginning to outweigh initial optimism.
The security implications are not just theoretical. Attackers are increasingly leveraging AI to craft convincing phishing emails, automate reconnaissance and bypass detection mechanisms. Simultaneously, AI-powered defences – ranging from anomaly detection to real-time threat modelling – are emerging as critical tools for defenders. CISOs find themselves at the centre of this technological arms race, tasked with maximising AI’s benefits while mitigating its risks.
Ransomware pressures: to pay or not to pay
Ransomware continues to loom large as one of the most pressing threats for CISOs in the UAE. With the potential for devastating financial and reputational damage, organisations are grappling with difficult decisions when faced with extortion demands.
Proofpoint’s 2025 survey reveals that 55% of CISOs in the UAE would consider paying a ransom to restore systems or prevent data leaks. This figure, while significant, is lower than the staggering 84% reported in Canada and Mexico, but it still underscores the desperation that many organisations feel in the aftermath of an attack.
This willingness to pay reflects the high stakes involved – whether to safeguard customer trust, protect intellectual property or simply resume business operations quickly. However, it also highlights a troubling cycle: the more organisations pay, the more they incentivise attackers to continue their campaigns.
Boardroom dynamics: shifting priorities, declining alignment
Another revealing finding in this year’s report is the decline in boardroom alignment with CISOs in the UAE – from 90% in 2024 to just 57% in 2025. This drop suggests that while cybersecurity remains a strategic priority, the relationship between security leaders and executive boards is under strain.
Interestingly, boards are increasingly viewing cyber risk through the lens of business valuation. Concerns about financial impact and shareholder confidence now rank higher than operational disruptions, reflecting a broader understanding of how deeply cybersecurity influences corporate resilience and market trust.
Yet, for CISOs, this shifting focus also brings added pressure. They must not only secure systems but also articulate the business consequences of security investments, often in financial terms that resonate with directors and investors.
The human toll: burnout and excessive expectations
The human element of cybersecurity extends beyond employee mistakes – it also affects the wellbeing of security leaders themselves. The 2025 Voice of the CISO report highlights the mounting personal and professional pressures faced by CISOs in the UAE:
- 62% report facing excessive expectations from their organisations
- 52% say they have experienced or witnessed burnout in the past year
- 40% feel they lack the resources necessary to achieve their cybersecurity goals despite rising stakes
While more organisations are beginning to implement protections – 54% of UAE companies now say they have taken steps to shield CISOs from personal liability – the role remains one of the most high-pressure positions in the corporate world.
Global perspective: key trends beyond the UAE
Though this report highlights UAE-specific insights, many of the challenges faced by CISOs in the region mirror global trends:
- Fragmented threat landscape: from email fraud to cloud account takeovers, no single threat dominates but most lead to the same result—data loss
- AI’s double-edged nature: globally, CISOs are both embracing and fearing GenAI, with adoption strategies shifting from blanket bans to governance and monitoring
- Persistent human vulnerability: employees remain the weakest link worldwide even as organisations invest heavily in training and awareness
- Growing ransom dilemma: across multiple countries, a significant percentage of CISOs admit they would pay to contain or recover from an attack, reflecting global desperation in the face of ransomware
Expert perspectives
Patrick Joyce, Global Resident CISO at Proofpoint, emphasised the contradictions revealed by the survey:
“This year’s findings reveal a growing disconnect between confidence and capability among CISOs. While many security leaders express optimism about their organisation’s cyber posture, the reality tells a different story – rising data loss, readiness gaps and persistent human risk continue to undermine resilience. As GenAI adoption accelerates both opportunity and threat, CISOs are being asked to do more with less, navigate unprecedented complexity and still safeguard what matters most. It’s clear that the role of the CISO has never been more pivotal – or more pressured.”
Ryan Kalember, Chief Strategy Officer at Proofpoint, highlighted the transformative impact of AI:
“Artificial intelligence has moved from concept to core, transforming how both defenders and adversaries operate. CISOs now face a dual responsibility: harnessing AI to strengthen their security posture while ensuring its ethical and responsible use. This balancing act places them at the centre of strategic decision-making. But AI is just one of many forces reshaping the CISO role. As threats intensify and environments grow more complex, organisations are reevaluating what cybersecurity leadership really looks like in today’s enterprise.”
Conclusion: the CISO role redefined
The 2025 Voice of the CISO report paints a vivid picture of a profession at a crossroads. For CISOs in the UAE, insider-driven data loss and AI governance are not abstract concerns – they are immediate, pressing challenges that demand urgent attention. At the same time, boardroom expectations, ransomware pressures and the mental health toll of the role add layers of complexity to an already demanding job.
The report makes clear that success in this environment requires more than technology. It requires cultural change, executive alignment, resilient processes and a recognition that people – whether insiders, employees or leaders themselves – are both the greatest risk and the greatest asset in the fight for cybersecurity resilience.
As organisations across the UAE and the wider world adapt to these realities, one truth stands out: the CISO role is not just about defending networks, it is about safeguarding trust, reputation and the very future of the enterprise.


