EY
Reports
All Statistics
52% of senior AI executives say they encountered cybersecurity risks as an AI-related risk in the past year.
14% of organizations that conducted a formal AI assurance review had to modify three-quarters or more of their AI systems.
29% of organizations that conducted a formal AI assurance review paused a quarter or more of their AI systems.
Currently, 9% of organizations dedicate at least 25% of their total cybersecurity budget to AI solutions; this share is expected to rise to 48% in two years.
97% of senior corporate security leaders agree their organization's competitive advantage in the next two years will be directly tied to the maturity of agentic AI cybersecurity defenses.
Currently, 23% of senior corporate security leaders say Identity and Access Management is largely run with agentic AI; this rises to 51% in two years.
81% of healthcare organizations believe that integrating cybersecurity into the core business strategy is effective in improving operational efficiencies to deliver better outcomes.
81% of healthcare executives believe that prioritizing cybersecurity in their business strategy is effective in overcoming challenges.
59% of healthcare organizations faced clinical consequences from cyber incidents, including delayed treatments and compromised patient trust.
Improving cybersecurity is a top priority for 54% of state and local government IT leaders for the current fiscal year. This is seen as a higher priority than modernising legacy systems.
When it comes to challenges faced by government IT leaders in using private sector innovations, cybersecurity concerns are the most often cited barrier, mentioned by 39%.
A significant concern regarding AI is cyberattacks becoming more sophisticated due to AI, noted by 82% of state and local government IT leaders.
Only 43% of cybersecurity functions are meaningfully involved in helping other functions adopt AI.
73% of the study's cohort of "Secure Creators" (organizations with more advanced cybersecurity functions than their peers) believe their ability to add value will grow in the future.
58% of CISOs and cybersecurity executives say it is difficult to articulate their value beyond risk mitigation.
68% of CISOs are more likely than the rest of the C-suite (57%) to express concern about senior leaders at their organisation underestimating the dangers of cybersecurity threats.
Two-thirds (66%) of CISOs say they are worried that the cybersecurity threats their organisation is facing are more advanced than their defences, which is significantly more than their C-suite counterparts (56%).
57% of CISOs are more likely than the rest of the C-suite (47%) to say their organisation has experienced a cybersecurity incident due to cybercriminals in the past three years.
91% of senior AI executives report their organization uses agentic AI through active pilot programs or full enterprise deployment.
49% of senior AI executives whose organization uses agentic AI say their governance framework has not been updated to include agentic AI requirements and risks.
72% of senior AI executives fear the inability to accurately trace or audit the data lineage and inputs that feed critical AI decision models.
81% of senior AI executives express fear of third-party AI-enabled cyber attacks.
9% of organizations that conducted a formal AI assurance review paused three-quarters or more of their AI systems.
85% of senior AI executives whose organization uses agentic AI say at least a handful of those systems execute actions without real-time human involvement.
63% of senior AI executives express concern about a lack of internal expertise to implement AI governance controls.
98% of senior AI executives say their organization conducts a formal AI assurance review at least annually.
47% of senior AI executives say their organization previously did not apply its AI governance process for urgent deployments.
39% of organizations that conducted formal AI assurance reviews identify shadow AI as a common issue.
72% of senior AI executives fear their organization failing to comply with new or emerging AI-specific regulations.
89% of senior AI executives say they encountered AI-related risks in the past year.
36% of senior AI executives report their organization experienced an AI incident or failure that caused a materially negative impact, including data loss, financial damage, brand damage and operational disruptions.
98% of senior AI executives report that their organization has formal AI governance policies in place.
26% of senior AI executives whose organization uses agentic AI report that their organization cannot detect unauthorized AI agents operating internally.
69% of senior AI executives express concern about a lack of internal expertise to effectively evolve AI governance controls.
47% of senior AI executives say they encountered human risk as an AI-related risk in the past year.
46% of senior AI executives say they encountered shadow AI risk as an AI-related risk in the past year.
25% of organizations that conducted a formal AI assurance review fully stopped a quarter or more of their AI systems.
48% of organizations that conducted formal AI assurance reviews identify AI model drift as a common issue.
5% of organizations that conducted a formal AI assurance review fully stopped three-quarters or more of their AI systems.
57% of organizations that conducted formal AI assurance reviews identify data quality problems as a common issue.
75% of senior AI executives fear a high-profile AI failure publicly impacting their organization's reputation.
64% of organizations that conducted a formal AI assurance review significantly modified a quarter or more of their AI systems.
Currently, 25% of senior corporate security leaders say third-party risk management is largely run with agentic AI; this rises to 50% in two years.
26% of organizations report their AI cybersecurity governance framework is fully rolled out and integrated across relevant business units.
Currently, 30% of senior corporate security leaders say Advanced Persistent Threat detection is largely run with agentic AI; this rises to 62% in two years.
Currently, 27% of senior corporate security leaders say data privacy and compliance is largely run with agentic AI; this rises to 48% in two years.
96% of senior corporate security leaders say AI-enabled cybersecurity attacks are a significant threat to their organization.
85% of senior corporate security leaders using AI in cybersecurity say their current cybersecurity budget is insufficient to meet AI-enabled threats.
Currently, 23% of senior corporate security leaders say deep fake and impersonation defense is largely run with agentic AI; this rises to 42% in two years.
48% of senior corporate security leaders estimate at least 25% of their organization's cybersecurity incidents in the past year were enabled by AI.