The CISO Report 2026, published by Splunk and released by Cisco on March 1, 2026, surveyed 650 Chief Information Security Officers globally and found that agentic AI is fundamentally changing how security leaders manage risk, talent, and cybersecurity operations.

Oxford Economics researchers conducted the survey in July and August 2025. Respondents represented nine industry sectors across nine countries, including Australia, France, Germany, India, Japan, New Zealand, Singapore, the United Kingdom, and the United States.

CISO Report 2026: The AI Imperative in Security Operations

The CISO Report 2026 shows that 95% of CISOs cite the growing sophistication of threat actor capabilities as their greatest risk. Moreover, 92% say improving threat detection and response is a top priority, followed by strengthening identity and access management at 78%, and investing in artificial intelligence cybersecurity capabilities at 68%.

Additionally, 92% of CISOs say AI enables their teams to review more security events. Furthermore, 89% report improved data correlation through AI tools.

Agentic AI Adoption and Concerns

Among CISOs who have partially or fully adopted agentic AI, 39% strongly agree it has more than doubled their teams’ reporting speed. In contrast, only 18% of those still exploring the technology report similar gains.

However, concerns accompany adoption. Specifically, 86% of CISOs fear agentic AI will increase the sophistication of social engineering attacks. Meanwhile, 82% worry it will accelerate the deployment speed and complexity of persistence mechanisms used by threat actors.

Despite these concerns, 82% of CISOs believe agentic AI will increase the volume of data reviewed, and 82% say it will improve correlation and response speeds across their security operations.

“CISOs operate in the eye of the storm, at the center of constant transformation. Role responsibilities expand, threats evolve, and AI accelerates everything. This expanded mandate brings an exceptional level of pressure and personal accountability. We are not just managing technology. We are managing risk, talent, and the digital resilience that drives critical business outcomes.”

Michael Fanning, CISO, Splunk

Expanded Roles and Personal Liability

Nearly four out of five CISOs report their role has become significantly more complex. More than three quarters now express concern about personal liability for security incidents, a sharp increase from just over half who held similar concerns the previous year.

Nearly all respondents report that CISO responsibilities now include AI governance and risk management. In addition, more than four out of five oversee secure software development, commonly referred to as DevSecOps.

Workforce Burnout and Talent Strategy

The report identifies a significant workforce retention challenge, with nearly two-thirds of cybersecurity teams experiencing moderate to significant burnout. The leading stressors are high alert volumes at 98%, false alerts at 94%, and tool fatigue at 79%.

Despite the rise of AI, CISOs continue to prioritize human capital. Their primary strategies include upskilling existing staff, hiring full-time employees, and engaging contractors. The report notes that human intelligence and creativity remain central to nuanced tasks such as threat hunting.

Challenges to cross-departmental data sharing persist, including data privacy concerns cited by 91%, high storage costs at 76%, and a lack of shared data views at 70%. Consequently, CISOs are consolidating security data into unified views and using data-driven narratives to communicate technical issues to non-technical leadership.

Shared Accountability and Business Alignment

The report finds that joint accountability across the C-suite drives the most value for key security initiatives, cited by 62% of respondents. Security budget and funding collaboration follows at 55%, while access to security-relevant data ranks third at 49%.

CISOs are also focusing on translating cybersecurity value into measurable business outcomes. Incident reduction, Mean Time to Detect (MTTD), and Mean Time to Respond (MTTR) are the top metrics used to communicate return on investment to organizational leadership.