-

Only 8 Percent of Organizations Conduct Regular AI-Specific Response Exercises, ISACA Research Finds

According to ISACA’s 2026 State of Cybersecurity survey report, the increasingly complex threat landscape has become an even bigger stressor this year

SCHAUMBURG, Ill.--(BUSINESS WIRE)--With rogue AI model behavior in the news recently, new research from ISACA finds concerning news about AI security. While AI is being heavily leveraged within cybersecurity teams, only eight percent of organizations indicate they conduct AI-specific response exercises regularly, according to ISACA’s 2026 State of Cybersecurity report, which surveyed more than 1,800 cybersecurity professionals across the globe.

According to ISACA’s 2026 State of Cybersecurity survey report, the increasingly complex threat landscape has become an even bigger stressor this year.

Share

AI incident response planning lags, even as AI transforms cybersecurity roles

ISACA’s 12th annual survey report, sponsored by Wolters Kluwer TeamMate, also found that 64 percent of enterprises have not conducted any AI-related incident response exercises. Seventeen percent say that AI incident response is included in broader cyber incident response exercises and 16 percent plan to conduct exercises in the future.

The gaps in planning also extend to AI incident playbooks—48 percent of respondents either don’t know whether their organization has established them or say their organization does not have them.

This comes as more cybersecurity professionals are using AI—only 13 percent do not use AI in their security operations. Among those who do, top uses include automating threat detection/response (41 percent, up from 32 percent in 2025), automating routine security tasks (40 percent, up from 28 percent last year), and endpoint security (33 percent).

Increasingly, AI is also impacting required cybersecurity skills. Forty-five percent of respondents report that LLM SecOps is a skill gap they see among cybersecurity professionals, a 12-point increase from 2025 and 21-point increase from 2024.

Cybersecurity professionals are also now even more hands-on with AI implementation and governance, with more than half (51 percent) now involved in developing, onboarding or implementing AI solutions, up from 40 percent in 2025 and 29 percent in 2024. Additionally, 56 percent of respondents say that they or someone from their team were involved in the development of a policy governing the use of AI in their organization.

“AI is quickly becoming embedded in cybersecurity operations, but this research shows that many organizations have not yet matched that adoption with the response planning and workforce readiness required to manage AI-related risk,” says Jon Brandt, ISACA senior director, professional practices and innovation. “As cybersecurity professionals take on a larger role in implementing and governing AI, enterprises need to prioritize AI-specific incident exercises, clear playbooks and upskilling in areas such as LLM SecOps to help their teams use AI securely and effectively.”

Stress growing amid staffing challenges, evolving threats

With increased AI use also comes shifting cyber threats to mitigate—and with it, increased stress. Sixty-eight percent report that their roles have become more stressful over the past five years. Respondents cite the main cause of this stress as the increasingly complex threat landscape (71 percent, up from 63 percent in 2025), a change from the 18 percentage-point drop for this stress driver from 2024 (81 percent) to 2025 (63 percent).

This comes as 45 percent of respondents say they expect a cyber-attack on their organization in the next year, and 35 percent indicate they are experiencing an increase in these attacks compared to a year ago. Less than half (42 percent) have high confidence in their organization’s cybersecurity team’s ability to detect and respond to cyber threats. These top attack types that enterprises are facing include social engineering (45 percent), vulnerabilities (39 percent), and remote access (24 percent) (an increase of five percent from 2025).

Additionally, staffing struggles continue to impact cybersecurity teams. Fifty-eight percent of organizations believe their cybersecurity team is understaffed, up slightly from 55 percent last year, and 49 percent report having open cybersecurity positions. Retention also remains a challenge, with more than half (55 percent) reporting difficulties retaining qualified cybersecurity professionals. High work stress is now the leading reason people leave their roles, cited by 52 percent, up from 47 percent in 2025.

To address technical cybersecurity skills gaps, over a third (35 percent) of cybersecurity teams are increasing their reliance on AI or automation, a 12-point increase from last year. They are also turning to training non-security staff for security roles (27 percent) and increased usage of contract employees or outside consultants (26 percent).

“Despite a majority of organizations struggling with retention and security professionals identifying high workload as a critical factor in job stress, we see a year-over-year increase in organizations with no open cybersecurity positions,” Sandy Buchanan, Lead Product Manager, Wolters Kluwer TeamMate. “It’s no surprise that we also see many organizations embracing the use of AI to augment their teams’ capabilities across their security operations. This highlights how critical it is for security and compliance platforms to provide AI-powered integrations and automation support to reduce the workload on these teams.”

Providing professional support, industry insights

In addition to thought leadership and resources, ISACA offers cybersecurity professionals with credentialing and training for every career stage—including Certified Information Security Manager (CISM), Advanced in AI Security Management (AAISM), and the upcoming Certified Cybersecurity Specialist (CCS) certification for early-career professionals.

Delve further into the topic in the complimentary upcoming 20 October webinar, “State of Cyber 2026: Global Update on Workforce Efforts, Resources, and Cybersecurity Operations.”

Access the complimentary 2026 State of Cybersecurity survey report and related resources at www.isaca.org/state-of-cybersecurity. For more cybersecurity resources, visit www.isaca.org/resources/cybersecurity.

About ISACA

For more than 55 years, ISACA® (www.isaca.org) has empowered its community of 195,000+ members with the knowledge, credentials, training and network they need to thrive in fields like information security, governance, assurance, risk management, data privacy and emerging tech. With a presence in more than 190 countries and with more than 230 chapters worldwide, ISACA offers resources tailored to every stage of members’ careers. Through the ISACA Foundation, ISACA also expands IT and education career pathways, fostering opportunities to grow the next generation of technology professionals.

Contacts

communications@isaca.org
Emily Ayala, +1.847.385.7223
Bridget Drufke, +1.847.660.5554

ISACA


Release Versions
Hashtags

Contacts

communications@isaca.org
Emily Ayala, +1.847.385.7223
Bridget Drufke, +1.847.660.5554

Social Media Profiles
More News From ISACA

Cyber Teams Stretched Too Thin as Attacks Intensify and Budgets Shrink, ISACA Research Finds

LONDON--(BUSINESS WIRE)--Cyberattacks are rising, but the teams defending against them are not growing to keep pace. Four in ten (38%) European IT and cybersecurity professionals say their organisation faced more attacks this year than last, yet more than half remain understaffed (56%) and underfunded (55%), according to new research from ISACA. According to ISACA's 2026 State of Cyber report, attacks are expected to rise further, with half of cyber professionals (54%) saying it’s likely their...

ISACA Foundation Scholarship Program Expands Access to Tech and Cybersecurity Education

SCHAUMBURG, Ill.--(BUSINESS WIRE)--New ISACA Foundation scholarship applications are open now for undergraduate and graduate students seeking opportunities in IT and cybersecurity...

AI Governance, Cyber Resilience and Digital Trust to Take Centre Stage at ISACA Europe Conference 2026 in Munich

MUNICH--(BUSINESS WIRE)--As artificial intelligence transforms organisations faster than governance frameworks can keep pace, professionals across Europe are under growing pressure to ensure AI is not only adopted, but governed, secured and managed responsibly. Against that backdrop, ISACA Europe Conference 2026 will bring more than 50 international speakers to Munich from 7–9 October to examine how organisations can strengthen oversight, manage risk and build resilience in an increasingly comp...
Back to Newsroom