Isaca
Reports
All Statistics
16% of organizations plan to conduct AI-related incident response exercises in the future.
45% of cybersecurity professionals expect a cyber-attack on their organization in the next year.
49% of organizations report having open cybersecurity positions.
45% of digital trust professionals noted that AI risks are an immediate priority.
74% of digital trust professionals cited privacy violations as an AI risk.
60% of digital trust professionals cited social engineering as an AI risk.
28% of digital trust professionals point to their board or executives as having ultimate responsibility for AI.
32% of digital trust professionals believe they could halt an AI system within 60 minutes after a security incident.
36% of digital trust professionals say humans approve most AI-generated actions before execution.
61% of professionals identified AI and machine learning as top technology priorities for 2026.
41% of professionals support statutory cybersecurity guidance for high-risk sectors in 2026.
51% of professionals anticipate difficulty filling digital trust roles with qualified candidates in 2026.
The complex cyber threat landscape is cited as the main reason for stress by 63% of respondents in 2025, down from 81% in 2024.
The top three most important soft skills needed by security professionals are critical thinking (57%), communication (56%), and problem solving (47%).
61% of respondents indicate that adaptability is very important in determining a cybersecurity applicant's qualifications.
Forty-four percent admit they have never heard of the new NIST standards
Sixty-three percent say quantum will increase or shift cybersecurity risks.
Nearly half (48 percent) are very or somewhat optimistic about quantum computing’s impact in their sector/industry.
24 percent of IT tech professionals say limited career opportunities is the biggest career obstacle.
63 percent of IT tech professionals say they would like to have a mentor.
54 percent of IT tech professionals say heavy workloads is a source of stress.
10% of those who always practiced privacy by design experienced a material privacy breach in the past year.
38% of respondents believed their legal/compliance privacy team was understaffed.
51% of respondents believed the demand for legal/compliance privacy roles would increase in the next year.
55% of organizations report difficulties retaining qualified cybersecurity professionals.
48% of cybersecurity professionals say their organization either does not have AI incident playbooks or the playbook status is unknown to them.
Enterprises face social engineering attacks (45%), vulnerabilities (39%), and remote access attacks (24%), with remote access increasing 5 percentage points from 2025.
Only 8% of organizations conduct AI-specific response exercises regularly.
64% of enterprises have not conducted any AI-related incident response exercises.
Only 13% of cybersecurity professionals do not use AI in their security operations.
41% of cybersecurity professionals use AI to automate threat detection and response, up from 32% in 2025.
40% of cybersecurity professionals use AI to automate routine security tasks, up from 28% in 2025.
33% of cybersecurity professionals use AI for endpoint security.
45% of cybersecurity professionals report that LLM SecOps is a skill gap, a 12-point increase from 2025 and a 21-point increase from 2024.
51% of cybersecurity professionals are involved in developing, onboarding, or implementing AI solutions, up from 40% in 2025 and 29 percent in 2024.
56% of cybersecurity professionals say they or someone from their team were involved in developing a policy governing AI use in their organization.
68% of cybersecurity professionals report that their roles have become more stressful over the past five years.
71% of cybersecurity professionals cite the increasingly complex threat landscape as the main cause of increased stress, up from 63% in 2025.
35% of cybersecurity professionals report experiencing an increase in cyber-attacks compared to a year ago.
42% of cybersecurity professionals have high confidence in their organization's cybersecurity team's ability to detect and respond to cyber threats.
58% of organizations believe their cybersecurity team is understaffed, up from 55% in 2025.
52% of cybersecurity professionals cite high work stress as the leading reason people leave their roles, up from 47% in 2025.
35% of cybersecurity teams are increasing their reliance on AI or automation to address technical skills gaps, a 12-point increase from 2025.
27% of cybersecurity teams are training non-security staff for security roles.
26% of cybersecurity teams are increasing use of contract employees or outside consultants.
17% of organizations include AI incident response in broader cyber incident response exercises.
The percentage citing the increasingly complex threat landscape as the main cause of stress drops 18 percentage points from 81% in 2024 to 63% in 2025.
90% believe employees are using artificial intelligence in their organization, but only 22% say AI return on investment (ROI) has met or exceeded their expectations.
Only 38% of digital trust professionals are confident in their board’s understanding of AI risks.
26% of digital trust professionals report that humans review selected AI decisions or patterns after execution.