Isaca
Reports
All Statistics
45% of digital trust professionals noted that AI risks are an immediate priority.
74% of digital trust professionals cited privacy violations as an AI risk.
60% of digital trust professionals cited social engineering as an AI risk.
90% believe employees are using artificial intelligence in their organization, but only 22% say AI return on investment (ROI) has met or exceeded their expectations.
Only 38% of digital trust professionals are confident in their board’s understanding of AI risks.
28% of digital trust professionals point to their board or executives as having ultimate responsibility for AI.
32% of digital trust professionals believe they could halt an AI system within 60 minutes after a security incident.
36% of digital trust professionals say humans approve most AI-generated actions before execution.
26% of digital trust professionals report that humans review selected AI decisions or patterns after execution.
43% of digital trust professionals are completely or fairly confident in their organization’s ability to investigate and explain to leadership or regulators if a serious AI system incident occurred.
18% of digital trust professionals indicate that disclosure is required and enforced when AI has been used to create or substantially assist with work products.
11% of digital trust professionals say humans intervene in AI decision-making only when alerted to potential issues.
20% of digital trust professionals say disclosure of AI use is required but not consistently enforced.
32% of digital trust professionals note that no disclosure requirements exist when AI is used to create or substantially assist with work products.
18% of digital trust professionals believe their CIO or CTO would have ultimate responsibility for AI.
20% of digital trust professionals say they do not know how humans oversee AI decision-making at their organization.
39% of digital trust professionals are completely or fairly confident in their organization’s data governance around AI.
56% of digital trust professionals indicate they do not know how quickly they could halt an AI system due to a security incident if needed.
7% of digital trust professionals say it would take them more than 60 minutes to halt an AI system after a security incident.
13% of digital trust professionals assign ultimate AI responsibility to their CISO.
20% of digital trust professionals do not know where ultimate responsibility for AI would lie in their organization.
51% of professionals anticipate difficulty filling digital trust roles with qualified candidates in 2026.
Only 18% of professionals feel fully ready for new regulations like NIS2 and DORA in 2026.
14% of professionals ranked modernizing legacy systems as a top digital trust priority in 2026.
30% of professionals indicated that workforce upskilling in data security is very important in 2026.
59% of professionals identified AI-driven social engineering as a significant cyber threat for 2026.
64% of professionals ranked regulatory compliance as a very important priority in 2026.
63% of professionals expect to hire for digital trust roles in 2026.
41% of professionals support statutory cybersecurity guidance for high-risk sectors in 2026.
43% of professionals in digital trust fields identified cloud migration and security as very important focus areas in 2026.
32% of professionals expect regulatory complexity and global compliance risks to be major concerns in 2026.
61% of professionals identified AI and machine learning as top technology priorities for 2026.
18% of professionals believe increased government funding for cyber skills and workforce development is the most important factor for enhancing cybersecurity resilience in their country.
Only 14% of professionals reported that their organization is very prepared to manage generative AI risks in 2026.
Only 12% of professionals reported having a strong talent pipeline for digital trust roles.
45% of professionals indicated they will be hiring for more digital trust roles in 2026 than in 2025.
The top three most important soft skills needed by security professionals are critical thinking (57%), communication (56%), and problem solving (47%).
61% of respondents indicate that adaptability is very important in determining a cybersecurity applicant's qualifications.
Soft skills are the largest reported skill gap in cybersecurity, increasing from 51% in 2024 to 59% in 2025.
Half of respondent enterprises have challenges retaining qualified cybersecurity professionals, which is the lowest percentage reported since 2020.
Only 41% of respondents believe their cybersecurity budgets will increase in the next 12 months, compared to 47% last year.
Professional development training is the most common employer benefit at 60%, three percentage points higher than last year.
18% of survey respondents believe their cybersecurity budgets will decrease in the next 12 months, compared to 13% last year.
The percentage of respondent enterprises that provided training to allow nonsecurity staff to move into security roles dropped considerably, from 41% last year to just 29% this year.
The top method to address technical skill gaps is increasing usage of contract employees or outside consultants (30%), which is a decline from 36% last year.
Prior hands-on cybersecurity experience is considered very important by 60% of respondents, marking a decline from 73% last year.
Employer-paid employee certification fees dropped to the second most common benefit, offered by only 54% of respondents, a decrease from 65% in 2024
High work-stress levels, limited promotion and development opportunities, and recruitment by other enterprises are the top reasons cybersecurity professionals leave their current roles.
66% of respondents indicate that their cybersecurity roles are significantly or slightly more stressful now than five years ago.
The complex cyber threat landscape is cited as the main reason for stress by 63% of respondents in 2025, down from 81% in 2024.