Survey: over 60% of 1,400 CISOs in 14 countries expect a damaging cyberattack in the next 12 months, due to massive shift to remote work since the pandemic
Proofpoint surveyed 1,400 CISOs across the globe about the current cybersecurity landscape. — More than 1,000 CISOs around …
Context & Ripple Effects
Proofpoint's survey lands mid-arc in a run of security sentiment data. Two years earlier, enterprise cyber insurance adoption had climbed from 34% to 47% as executive worry built; Proofpoint now puts numbers on that anxiety at the CISO level — over 60% of 1,400 respondents in 14 countries expecting a damaging attack within a year, with the pandemic-driven move to remote work named as the driver.
The firm also pairs the survey with its claim of high confidence that hackers are collaborating with organized crime groups, framing attacker capability — not just exposed perimeters — as what CISOs are pricing in.
First-order effects
- CISOs holding this expectation are pushed to redirect budget toward securing distributed workforces rather than office perimeters, since remote work is the stated cause of their pessimism.
- Proofpoint gains both a sales narrative and survey-derived intelligence for its own email-security and threat-research positioning against rival vendors courting the same buyers.
Second-order effects
- Cyber insurers can treat majority-expected-loss sentiment as an input for premium pricing, extending the coverage growth path that had already taken enterprise policies from 34% to 47% of firms.
- Competing security vendors face pressure to answer Proofpoint's survey-led marketing with their own research — the pattern Barracuda followed a year later when its OT survey found 94% of industrial security officers attacked.
Third-order effects
- If the survey series holds, security procurement structurally shifts toward protecting endpoints and identities outside the corporate network — a trajectory the UK government's later finding that 43% of businesses suffered a breach in a year suggests was borne out in practice.
- Persistent breach expectations normalize ransomware response planning at board level, consistent with later evidence that firms were losing more money to holiday and weekend ransomware attacks than they had been.
The trend: Security budgets and insurance markets are re-pricing around a permanently distributed workforce, with vendor surveys becoming the recurring barometer of expected loss.