The Gaps CISOs Keep Losing Sleep Over — And Why They're Getting Harder to Close

Proofpoint's 2025 survey found 58% of organizations unprepared to respond to a cyberattack. The reasons why are structural, not just technical.

ThreatVectr Newsdesk· 3 min read
The Gaps CISOs Keep Losing Sleep Over — And Why They're Getting Harder to Close
Share

One-third of CISOs say the data inside their own organizations isn't adequately protected. That figure, drawn from Proofpoint's 2025 Voice of the CISO Report, sits alongside another uncomfortable number: 58% of respondents said their organizations were unprepared to handle a cyberattack. Only 67% felt they had sufficient budget, headcount, and tooling to meet their goals.

These aren't edge cases. They're the baseline.

The perception problem

Errol Weiss, CSO at Health-ISAC, frames the first gap plainly: too many CISOs still treat security as an IT discipline rather than a business-continuity function. "They need to shift from protecting systems at all costs to instead building resilience and thinking about the downstream impacts when something fails," he says. The Change Healthcare attack in 2024 made the case for that shift at industry scale — consequences rippled well beyond any single IT environment.

Business continuity has historically belonged to someone else's org chart. Weiss argues that's no longer viable.

Execution velocity

Cisco Talos' 2025 Year in Review observed adversaries weaponizing new vulnerabilities — including flaws tracked as React2Shell and ToolShell — almost immediately after disclosure. Security teams aren't matching that tempo. Buck Bell, director of security strategy at CDW, calls the result "execution gaps": static defenses, monthly pen tests, and patch-Tuesday cadences built for a slower era.

Leading programs are moving toward continuous threat exposure management, AI-assisted triage, and automation. The ones that aren't are falling further behind.

Business outpacing security

Chirag Shah, global information security officer at Model N, is direct about the dynamic: "Business wants to run faster, and if they're wanting to run faster, that means we at security and compliance have to run with them." PwC's 2026 CISO Outlook frames it similarly — AI, quantum, and hyperconnectivity are reshaping risk faster than most security programs adapt.

Some CISOs are upskilling teams on AI specifically to stay in stride with business-unit priorities rather than chasing them retroactively.

Skills, not just headcount

The SANS 2026 Cybersecurity Workforce Research Report documents a shift in how the gap manifests: 60% of security leaders now identify skills gaps as their primary workforce challenge, up from 52% last year, while only 40% cite raw headcount shortages. AI is disrupting traditional entry points; specialists in new roles are in demand at nearly double the rate year-over-year.

Beth Miller, global field CISO at Mimecast, extends the problem outward. A fully skilled security team still fails if security literacy doesn't exist across the broader organization. "You can have a fully skilled security team, but if you don't have security skills in the business, too, you still will have a gap."

Shadow AI

The AI deployment gap may be the most immediate. Leadership announces adoption initiatives; business units start building within weeks, often connecting AI tooling to live data before security knows the project exists. Shah calls it plainly: "Shadow AI is happening industry wide."

Discovering those deployments after the fact doesn't close the exposure. And the controls needed to secure AI are themselves a moving target — governance frameworks that fit today's models may not map cleanly to what ships next quarter.

Capability and intent are distinct problems. Organizations can acquire the tools. Closing these gaps requires something harder to procure: institutional intention.

© 2026 Threat Vectr