-

Cyber Teams Stretched Too Thin as Attacks Intensify and Budgets Shrink, ISACA Research Finds

  • 38% of European IT professionals say their organisations are experiencing more cyberattacks than this time last year
  • Cyber teams are struggling to keep pace with an increasingly complex threat landscape, with 72% reporting that their job is more stressful now than 5 years ago

LONDON--(BUSINESS WIRE)--Cyberattacks are rising, but the teams defending against them are not growing to keep pace. Four in ten (38%) European IT and cybersecurity professionals say their organisation faced more attacks this year than last, yet more than half remain understaffed (56%) and underfunded (55%), according to new research from ISACA.

Cyber teams are struggling to keep pace with an increasingly complex threat landscape, with 72% reporting that their job is more stressful now than 5 years ago.

Share

According to ISACA's 2026 State of Cyber report, attacks are expected to rise further, with half of cyber professionals (54%) saying it’s likely their organisation will experience a cyberattack within the next year.

Cyber teams are also grappling with new threats. Cybercriminals and hackers are now behind 39% of incidents, and social engineering (manipulating people rather than breaking through systems) is the most common kind of attack, cited by 46%. Social engineering attacks are increasingly supported by AI, overtaking conventional hacking methods.

Compounding this, 72% report that their role is more stressful now than five years ago. The increasingly complex threat landscape is overwhelmingly cited (72%) as the direct cause of this. Other reasons cited are unrealistic expectations and too much work (57%), and staff not being sufficiently trained or skilled (35%). Despite this, a fifth (21%) of companies still take no action to mitigate burnout, not addressing these challenges even as cyber teams are pushed to their limits. Others are taking steps to ease the pressure, with 55% offering flexible working hours and 46% encouraging employees to take breaks and vacation time to mitigate burnout.

Chris Dimitriadis, Global Chief Strategy Officer at ISACA, said, “The growing gap between rising threats and under-resourcing for cybersecurity is taking a toll on the people tasked with managing it. Too often we are seeing budgets being sunk into crisis response, but there’s still a distinct lack of investment in the workforce, training, and resources needed to prevent attacks and protect organisations in the first place. Preparedness is key to resilience, and we must see this reflected in the way businesses approach cybersecurity investment. Better funding and a clear plan for improving cyber resilience should be a C-suite priority.”

AI’s exponential growth has proved to be an aid for cybersecurity teams, with AI's footprint in cyber operations expanding dramatically over the past year. Almost four in ten (37%) organisations now use AI to automate threat detection and response, a rise from eight percentage points on 2025 figures. AI is also being used for endpoint security by 29% and to automate routine security tasks by 35%.

Cyber professionals are increasingly shaping how AI is adopted more broadly. 54% said themselves or their team had been involved in the development, onboarding, or implementation of AI solutions, and 60% have had a hand in developing policies governing AI use within their organisation.

However, AI also presents difficult and serious challenges for cyber teams. AI-enabled cyberattacks mean bad actors can operate at the speed of intent, automating attacks that once took days or weeks.

Yet preparedness for when AI itself goes wrong is lagging well behind adoption. Almost three-quarters (71%) of organisations have not conducted any AI-related incident response exercises. Such exercises can prepare organisations for scenarios including sensitive data exposure through AI systems, AI-enabled phishing, fraud or social engineering, and misuse of generative AI by employees or insiders. Just 3% have mature, formal runbooks for AI-specific incidents, and close to a third (30%) have not even begun to address their response to AI-related incidents.

Dimitriadis concludes:Organisations can effectively use AI for preventing and detecting cyber threats. However, its governance should be non-negotiable. AI governance is critical to ensuring employees are using AI safely in the workplace - but also for ensuring that businesses understand and can protect themselves from AI generated threats. Implementing checks and balances such as CMMI’s AI Maturity Model (AIM) can give teams a structured way to benchmark AI governance maturity – rather than relying on ad hoc controls as adoption accelerates.”

As AI transforms cyber threats and the tools available to defend against it, ISACA warns that governance, readiness, and funding must keep pace with adoption.

Diving into the research

To delve further into the topic, ISACA is hosting a complimentary webinar, “State of Cyber 2026: Global Update on Workforce Efforts, Resources, and Cybersecurity Operations” on 20th October.

You can access the 2026 State of Cybersecurity survey report and related resources at https://www.isaca.org/state-of-cybersecurity. For more cybersecurity resources, visit www.isaca.org/resources/cybersecurity.

Notes to Editors

About ISACA

ISACA® (www.isaca.org) champions the global workforce advancing trust in technology. For more than 55 years, ISACA has empowered its community of 195,000+ members with the knowledge, credentials, training and network they need to thrive in fields like information security, governance, assurance, risk management, data privacy and emerging tech. With a presence in more than 190 countries and with nearly 230 chapters worldwide, ISACA offers resources tailored to every stage of members’ careers—helping them to thrive in a rapidly changing digital landscape, drive trusted innovation and ensure a more secure digital world. Through the ISACA Foundation, ISACA also expands IT and education career pathways, fostering opportunities to grow the next generation of technology professionals.

ISACA security resources

In addition to thought leadership and resources such as this report, ISACA offers cybersecurity professionals with credentialing and training that meets their needs at every stage of their careers—including CISM, AAISM, and the upcoming Certified Cybersecurity Specialist (CCS) certification for early-career professionals, slated to release in December.

Methodology

All figures are based on fieldwork conducted by ISACA in May 2026 amongst 1,888 global respondents working in cybersecurity, of which 494 are located in Europe.

Contacts

firstlight group
Layla Angell, +44 7960 079 643, 020 3617 7240, isacateam@firstlightgroup.io

ISACA
Esther Almendros, +34 692 669 772, ealmendros@isaca.org

ISACA


Release Versions
Hashtags

Contacts

firstlight group
Layla Angell, +44 7960 079 643, 020 3617 7240, isacateam@firstlightgroup.io

ISACA
Esther Almendros, +34 692 669 772, ealmendros@isaca.org

Social Media Profiles
More News From ISACA

Only 8 Percent of Organizations Conduct Regular AI-Specific Response Exercises, ISACA Research Finds

SCHAUMBURG, Ill.--(BUSINESS WIRE)--With rogue AI model behavior in the news recently, new research from ISACA finds concerning news about AI security. While AI is being heavily leveraged within cybersecurity teams, only eight percent of organizations indicate they conduct AI-specific response exercises regularly, according to ISACA’s 2026 State of Cybersecurity report, which surveyed more than 1,800 cybersecurity professionals across the globe. AI incident response planning lags, even as AI tra...

ISACA Foundation Scholarship Program Expands Access to Tech and Cybersecurity Education

SCHAUMBURG, Ill.--(BUSINESS WIRE)--New ISACA Foundation scholarship applications are open now for undergraduate and graduate students seeking opportunities in IT and cybersecurity...

AI Governance, Cyber Resilience and Digital Trust to Take Centre Stage at ISACA Europe Conference 2026 in Munich

MUNICH--(BUSINESS WIRE)--As artificial intelligence transforms organisations faster than governance frameworks can keep pace, professionals across Europe are under growing pressure to ensure AI is not only adopted, but governed, secured and managed responsibly. Against that backdrop, ISACA Europe Conference 2026 will bring more than 50 international speakers to Munich from 7–9 October to examine how organisations can strengthen oversight, manage risk and build resilience in an increasingly comp...
Back to Newsroom