Exabeam
Reports
All Statistics
56% of security leaders use behavioral monitoring and baselining to monitor AI agents.
27% of security leaders identify limited behavioral context and correlation as the biggest limitation of their current AI agent monitoring approach.
93% of security and finance leaders say the two functions are aligned on cybersecurity risk tolerance.
87% of security leaders express confidence that their cybersecurity investments are delivering business value.
59% of security leaders report using outcome metrics to measure cybersecurity investments.
AI and automation serve as the primary catalyst for cybersecurity budget expansion for 44% of organizations, followed by cloud infrastructure growth (33%) and mainstream business AI adoption (32%).
Healthcare expects a 53% rise in insider threats.
More than half of executives believe AI tools are fully deployed, contrasting with managers and analysts who report many are still in pilot or evaluation stages
In the Middle East, nearly one-third (30%) of organisations anticipate a decrease in insider threats.
56% of security teams report that AI has improved productivity in threat detection, investigation, and response (TDIR).
Among analysts, only 10% trust in AI autonomy.
Only 22% of analysts agree that AI has significantly improved productivity across their security teams.
48% of security leaders rank AI agents operating with excessive, compromised, or unintended access as the greatest threat to their organization, while 28% rank external threat actors, 12% rank compromised insiders, and 12% rank malicious insiders.
29% of security leaders continue to rely on manual review to monitor AI agents.
60% of security leaders use dedicated AI security or governance tooling to monitor AI agents.
56% of security leaders extend existing SIEM, detection, or monitoring platforms to monitor AI agents.
81% of security leaders say their CFO understands the cybersecurity risks they are working to mitigate.
55% of security leaders delay or scale back a security initiative because they cannot frame the risk in financial terms their CFO will accept.
95% of organizations are increasing cybersecurity budgets in 2026.
74% of organizations are seeing double-digit cybersecurity budget growth in 2026.
30% of security leaders in the Netherlands report that AI is already improving security operations.
30% of security leaders cite a lack of board understanding of the link between cybersecurity investment and business resilience as their biggest challenge in defending spend.
32% of organizations identify AI as the most challenging cybersecurity spend to justify to business stakeholders.
44% of organizations identify AI as the top driver of cybersecurity budget increases.
63% of security leaders report using quantified ROI to measure cybersecurity investments.
75% of security leaders in Saudi Arabia report that AI is already improving security operations.
44% of organizations would cut AI investment first if cybersecurity budgets tightened.
27% of security leaders in Japan report that AI is already improving security operations.
AI-enhanced phishing and social engineering are the most concerning tactics (27%) for insider threats.
In the Middle East, unauthorised GenAI is the top insider concern (31%).
More than three-quarters of organisations (76%) report some level of unapproved Generative AI (GenAI) usage.
Government organisations are bracing for the steepest rise (73%) in insider threats.
The majority (54%) of organisations expect insider threat growth to continue.
Unapproved GenAI usage rates are highest in technology (40%), financial services (32%), and government (38%).
53% of cybersecurity professionals expect insider threats to increase.
Over the past year, more than half of organisations (53%) have seen a measurable increase in insider incidents.
64% of cybersecurity professionals view insiders (whether malicious or compromised) as a greater risk than external actors.
88% of organisations state they have insider threat programmes.
74% of cybersecurity professionals report that AI is making insider threats more effective.
Just 44% of organisations use user and entity behaviour analytics (UEBA) for insider threat detection.
97% of organisations use some form of AI in their insider threat tooling.
Two of the top three current insider threat vectors are now AI-related.
Asia-Pacific and Japan lead in projected insider threat growth (69%).
Manufacturing expects a 60% rise in insider threats.
More than half of surveyed organizations have restructured their teams due to AI implementation.
71% of executives report AI-driven productivity gains.
18% of organizations are expanding hiring for roles focused on AI governance, automation oversight, and data protection.
Only 29% of teams trust AI to act on its own.
37% of organizations report workforce reductions tied to automation.
Organizations in India, Middle East, Turkey, and Africa (IMETA) report the highest productivity gains (81%) after adopting AI.