EY

88 stats6 reports

All Statistics

52% of senior AI executives say they encountered cybersecurity risks as an AI-related risk in the past year.

AI RiskEnterprise Risk

14% of organizations that conducted a formal AI assurance review had to modify three-quarters or more of their AI systems.

AI AssuranceEnterprise Risk

29% of organizations that conducted a formal AI assurance review paused a quarter or more of their AI systems.

AI AssuranceEnterprise Risk

Currently, 9% of organizations dedicate at least 25% of their total cybersecurity budget to AI solutions; this share is expected to rise to 48% in two years.

Cybersecurity BudgetsAI InvestmentAI Solutions

97% of senior corporate security leaders agree their organization's competitive advantage in the next two years will be directly tied to the maturity of agentic AI cybersecurity defenses.

Agentic AICompetitive AdvantageAgentic AI Cybersecurity Defenses

Currently, 23% of senior corporate security leaders say Identity and Access Management is largely run with agentic AI; this rises to 51% in two years.

Identity And Access ManagementAgentic AI

81% of healthcare organizations believe that integrating cybersecurity into the core business strategy is effective in improving operational efficiencies to deliver better outcomes.

CybersecurityHealthcareOperational Efficiency

81% of healthcare executives believe that prioritizing cybersecurity in their business strategy is effective in overcoming challenges.

HealthcareCybersecurityBusiness strategy

59% of healthcare organizations faced clinical consequences from cyber incidents, including delayed treatments and compromised patient trust.

HealthcareCyber incidentCyber incident consequencesClinical Consequences

Improving cybersecurity is a top priority for 54% of state and local government IT leaders for the current fiscal year. This is seen as a higher priority than modernising legacy systems.

GovernmentCybersecurity

When it comes to challenges faced by government IT leaders in using private sector innovations, cybersecurity concerns are the most often cited barrier, mentioned by 39%.

GovernmentCybersecurity

A significant concern regarding AI is cyberattacks becoming more sophisticated due to AI, noted by 82% of state and local government IT leaders.

GovernmentAI

Only 43% of cybersecurity functions are meaningfully involved in helping other functions adopt AI.

AI

73% of the study's cohort of "Secure Creators" (organizations with more advanced cybersecurity functions than their peers) believe their ability to add value will grow in the future.

Cybersecurity benefitsCybersecurity value

58% of CISOs and cybersecurity executives say it is difficult to articulate their value beyond risk mitigation.

CISOCybersecurity benefitsCybersecurity value

68% of CISOs are more likely than the rest of the C-suite (57%) to express concern about senior leaders at their organisation underestimating the dangers of cybersecurity threats.

Cybersecurity threatC-SuiteCISO

Two-thirds (66%) of CISOs say they are worried that the cybersecurity threats their organisation is facing are more advanced than their defences, which is significantly more than their C-suite counterparts (56%).

Cybersecurity threatC-SuiteCISO

57% of CISOs are more likely than the rest of the C-suite (47%) to say their organisation has experienced a cybersecurity incident due to cybercriminals in the past three years.

Security incidentC-SuiteCISO

91% of senior AI executives report their organization uses agentic AI through active pilot programs or full enterprise deployment.

Agentic AIEnterprise Risk

49% of senior AI executives whose organization uses agentic AI say their governance framework has not been updated to include agentic AI requirements and risks.

Agentic AIAI GovernanceEnterprise Risk

72% of senior AI executives fear the inability to accurately trace or audit the data lineage and inputs that feed critical AI decision models.

Agentic AIAI GovernanceEnterprise Risk

81% of senior AI executives express fear of third-party AI-enabled cyber attacks.

AIAI RiskEnterprise Risk

9% of organizations that conducted a formal AI assurance review paused three-quarters or more of their AI systems.

AI AssuranceEnterprise Risk

85% of senior AI executives whose organization uses agentic AI say at least a handful of those systems execute actions without real-time human involvement.

Agentic AIHuman OversightEnterprise Risk

63% of senior AI executives express concern about a lack of internal expertise to implement AI governance controls.

AI GovernanceSkills GapEnterprise Risk

98% of senior AI executives say their organization conducts a formal AI assurance review at least annually.

AI AssuranceComplianceEnterprise Risk

47% of senior AI executives say their organization previously did not apply its AI governance process for urgent deployments.

AI GovernanceEnterprise Risk

39% of organizations that conducted formal AI assurance reviews identify shadow AI as a common issue.

Shadow AIAI AssuranceEnterprise Risk

72% of senior AI executives fear their organization failing to comply with new or emerging AI-specific regulations.

Regulatory RiskComplianceAgentic AIEnterprise Risk

89% of senior AI executives say they encountered AI-related risks in the past year.

AI RiskEnterprise Risk

36% of senior AI executives report their organization experienced an AI incident or failure that caused a materially negative impact, including data loss, financial damage, brand damage and operational disruptions.

AI IncidentsOperational RiskEnterprise Risk

98% of senior AI executives report that their organization has formal AI governance policies in place.

AI GovernanceCorporate PolicyEnterprise Risk

26% of senior AI executives whose organization uses agentic AI report that their organization cannot detect unauthorized AI agents operating internally.

Agentic AIThreat DetectionEnterprise RiskAI Agents

69% of senior AI executives express concern about a lack of internal expertise to effectively evolve AI governance controls.

AI GovernanceSkills GapEnterprise Risk

47% of senior AI executives say they encountered human risk as an AI-related risk in the past year.

Human RiskAI RiskEnterprise Risk

46% of senior AI executives say they encountered shadow AI risk as an AI-related risk in the past year.

Shadow AIAI RiskEnterprise Risk

25% of organizations that conducted a formal AI assurance review fully stopped a quarter or more of their AI systems.

AI AssuranceEnterprise Risk

48% of organizations that conducted formal AI assurance reviews identify AI model drift as a common issue.

Model DriftAI AssuranceEnterprise Risk

5% of organizations that conducted a formal AI assurance review fully stopped three-quarters or more of their AI systems.

AI AssuranceEnterprise Risk

57% of organizations that conducted formal AI assurance reviews identify data quality problems as a common issue.

Data QualityAI AssuranceEnterprise Risk

75% of senior AI executives fear a high-profile AI failure publicly impacting their organization's reputation.

AI FailureEnterprise Risk

64% of organizations that conducted a formal AI assurance review significantly modified a quarter or more of their AI systems.

AI AssuranceEnterprise Risk

Currently, 25% of senior corporate security leaders say third-party risk management is largely run with agentic AI; this rises to 50% in two years.

Third-Party Risk ManagementAgentic AI

26% of organizations report their AI cybersecurity governance framework is fully rolled out and integrated across relevant business units.

AI Cybersecurity GovernanceEnterprise Integration

Currently, 30% of senior corporate security leaders say Advanced Persistent Threat detection is largely run with agentic AI; this rises to 62% in two years.

Advanced Persistent ThreatsAgentic AI

Currently, 27% of senior corporate security leaders say data privacy and compliance is largely run with agentic AI; this rises to 48% in two years.

Data PrivacyComplianceAgentic AI

96% of senior corporate security leaders say AI-enabled cybersecurity attacks are a significant threat to their organization.

AI-Enabled AttacksCybersecurity Threat

85% of senior corporate security leaders using AI in cybersecurity say their current cybersecurity budget is insufficient to meet AI-enabled threats.

Cybersecurity BudgetsResource ConstraintsAI-Enabled Threats

Currently, 23% of senior corporate security leaders say deep fake and impersonation defense is largely run with agentic AI; this rises to 42% in two years.

DeepfakesIdentity ProtectionAgentic AIImpersonation Defense

48% of senior corporate security leaders estimate at least 25% of their organization's cybersecurity incidents in the past year were enabled by AI.

AI-Enabled AttacksCybersecurity Threat