HomeRisk ManagementsAI Incident Response Readiness Trails Behind AI Adoption, ISACA Reports

AI Incident Response Readiness Trails Behind AI Adoption, ISACA Reports

Published on

spot_img

Organizations Struggle with AI Security Preparedness Despite Rising Implementation

Most organizations are currently underprepared to tackle AI-related security incidents, despite the increasing integration of AI technologies into their operational frameworks. Recent research conducted by ISACA has highlighted a significant gap in readiness among security teams. According to the findings in ISACA’s 2026 State of Cyber report, a striking 71% of organizations have yet to conduct any AI incident response exercises. Alarmingly, only 3% of surveyed entities possess mature, formal runbooks specifically designed for handling AI-related incidents, while an additional 30% have not even begun to formulate a response strategy.

The report indicates that the various scenarios which could trigger an incident response include sensitive data being exposed through AI systems, AI-driven phishing attacks, and the misuse of generative AI by internal employees or other insiders. The lack of readiness presents a concerning oversight, especially given the rapid adoption of AI technologies across various sectors.

AI Adoption Outpaces Security Preparedness

The findings in ISACA’s report reveal a rapid acceleration of AI adoption that is outpacing the corresponding preparedness measures. Approximately 37% of organizations are employing AI technologies to automate threat detection and response, which is an increase of eight percentage points compared to 2025. Additionally, 35% of organizations utilize AI for routine security tasks, and 29% have implemented AI solutions for endpoint security.

Security professionals are at the forefront of this AI rollout, with 54% indicating that they or their teams have played a critical role in developing, onboarding, or implementing AI solutions within their organizations. Furthermore, around 60% of cybersecurity personnel have contributed to the formulation of AI policies, reflecting a proactive approach within certain sectors.

However, the report also cautions that AI has empowered attackers to operate at unprecedented speeds. ISACA observed that the automation capabilities of AI allow cybercriminals to execute attacks that once took days or even weeks in a matter of moments.

Chris Dimitriadis, ISACA’s global chief strategy officer, emphasized that while organizations can leverage AI to prevent and detect cyber threats effectively, robust governance protocols are essential. "Governance must be considered non-negotiable," Dimitriadis asserted. He highlighted the importance of established guidelines to ensure the safe use of AI among employees while simultaneously protecting organizations from AI-generated threats. To substantiate this need for governance, he pointed to the CMMI’s AI Maturity Model as a valuable benchmark for organizations striving to enhance their readiness.

Rising Cyberattacks Amid Workforce Strain

The report further sheds light on the alarming increase in cyberattacks, with 38% of European IT and cybersecurity professionals reporting that their organizations have experienced a greater number of cyber threats compared to the previous year. Furthermore, 54% anticipate that their organization will face a cyberattack within the next 12 months. Among the various threat vectors, social engineering has emerged as the most common type of attack, identified by 46% of respondents, with ISACA noting that the sophistication and prevalence of these attacks are increasingly bolstered by AI technologies.

The cybersecurity workforce is bearing the brunt of this escalating threat landscape. A staggering 72% of professionals reported that their jobs have become more stressful compared to five years ago, attributing this rise in stress primarily to the increased complexity of threats. Additionally, 56% of respondents indicated that their teams are understaffed and 55% reported underfunding for essential security measures.

Beyond external threats, challenges within organizations complicate matters further. Approximately 57% of surveyed professionals cited unrealistic expectations and excessive workloads as contributing factors to their stress levels, while 35% noted that their teams lack sufficient training or skills to effectively handle the evolving threat environment. Alarmingly, one-fifth of companies reported taking no action to address employee burnout, with those that do tend to offer measures such as flexible hours (55%) and encouraging breaks or vacations (46%).

Dimitriadis concluded by pointing out a crucial misallocation of resources: budgets are frequently "sunk into crisis response" rather than being strategically invested in workforce development and training initiatives required to prevent future attacks. "Better funding and a clear action plan for improving cyber resilience should be a top priority for C-suite executives," he urged, highlighting the necessity for a strategic overhaul in cybersecurity practices as organizations continue to grapple with the dual challenges of rapid AI adoption and rising cyber threats.

Source link

Latest articles

Critical Linux KVM Vulnerability Allows Guest-to-Host Escape on ARM64 Systems

A serious vulnerability has been identified in the Linux Kernel-based Virtual Machine (KVM) specifically...

Gemini Exceeds Expectations in Cybersecurity Test

Google's Gemini AI Incident Highlights Cybersecurity Challenges In a striking development for the tech industry,...

CISOs Must Address the Nation-State Threat

Rise of AI in Cyber Threats: Nation-States and Cybercriminals at the Forefront In the evolving...

More like this

Critical Linux KVM Vulnerability Allows Guest-to-Host Escape on ARM64 Systems

A serious vulnerability has been identified in the Linux Kernel-based Virtual Machine (KVM) specifically...

Gemini Exceeds Expectations in Cybersecurity Test

Google's Gemini AI Incident Highlights Cybersecurity Challenges In a striking development for the tech industry,...