PwC
Reports
All Statistics
Half of security leaders identify attacks targeting AI systems as one of their biggest preparedness gaps.
Security and risk leaders rank compromise by autonomous botnets (53%), adversarial attacks (52%), and data poisoning (52%) as the top AI-enabled attacks they are least prepared to address.
Only 21% of organisations are implementing quantum security measures, while 49% have not even begun.
For companies with $5 billion or more in revenue, 41% reported a breach costing $1 million or more.
Security leaders rank threat hunting as the #1 AI security capability they plan to bolster over the next 12 months.
Only 6% of organisations have fully implemented all data risk measures surveyed across the enterprise.
84% of security and finance leaders expect their cyber budget to increase, six percentage points higher than last year.
About half (51%) rank data protection and trust as their top cyber spend priority, 46% rank securing against AI-enabled attacks, and 45% rank securing AI and autonomous agents.
More than half (55%) rank reliability and maturity of AI technology among their top three barriers to increasing AI agent autonomy, while 46% cite accountability and explainability.
To retain employees, organisations place growth opportunities (59%), a strong cyber culture (53%), and AI-enabled tools and training (53%) among their top priorities.
Security leaders rank AI (53%), cloud security (49%), data protection and trust (42%), and threat management (39%) among their top priorities for managed security services over the coming year.
29% of CEOs and security and risk leaders say AI governance accountability sits with the CIO, CTO, or technology function, 26% say it sits with a dedicated AI leader or AI function, and 17% say it sits with the CISO or cyber function.
Only 39% of security, risk, and operations leaders have fully formalised and integrated operational continuity plans that specifically address cyber risks.
58% of security leaders rank AI in their top cyber budget priorities.
Cloud-related threats (40%), third-party breaches (34%), and ransomware (33%) rank after AI as major preparedness gaps.
Half of organisations are making changes to vendor, third-party, and supply chain risk management, while 49% are making changes to cyber insurance, incident response, and crisis management.
On average, companies have implemented only three out of seven key data risk measures across their organisations.
Only 5% of organisations have fully implemented every data risk measure surveyed, down from 7% last year.
About half of organisations have fully implemented data classification policies (49%) and data loss prevention across key egress channels (48%).
50% of security leaders rank threat detection and alerting among their top AI-for-security priorities, followed by fraud detection (43%) and phishing detection and response (42%).
22% of organisations would authorise AI agents to fully execute defensive manoeuvres without human approval, 38% would permit partial autonomy, and 36% prefer human-led execution with AI support.
Organisations are most comfortable authorising autonomous agents for threat intelligence enrichment and correlation (49%), phishing email quarantine or deletion (47%), and malware removal and system remediation (46%).
Nearly half of CISOs (44%) identify workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy.
49% of organisations have not considered or started implementing any quantum-resistant security measures.
Cloud and connected product attacks are the top two cyber threats organisations feel least prepared to address.
48% of organisations that have experienced a major attack are prioritising managed services to fill critical skills deficiencies (compared to 39% overall).
Roughly half of respondents say their organisation is at best only ‘somewhat capable’ of withstanding cyber attacks targeting specific vulnerabilities.
Only 3% of organisations have implemented all leading quantum-resistant security measures surveyed.
The top internal challenges to achieving post-quantum cryptography include gaps in technical expertise to adopt industry standards (37%) and gaps in dedicated quantum computing knowledge and resources (36%).
33% of business and tech leaders ranked cloud-related threats in their top three threats they are least prepared to address.
78% of business and tech leaders expect their cyber budget to increase over the coming year (a figure virtually unchanged from 77% last year).
Most companies (67%) are spending roughly equal amounts on proactive and reactive cybersecurity measures.
The top three investment priorities when allocating cyber budgets are: Artificial intelligence (AI) (36%), Cloud security (34%), and Network security and zero trust (28%).
39% of business and tech leaders prioritise changes in trade and operating policies in response to the current geopolitical landscape.
AI enablement of key cyber capabilities is the #1 cyber investment priority for security leaders.
Over half (53%) of organisations are prioritising AI and machine learning tools in their top three priorities to help close capability gaps in cyber talent.
28% of business and tech leaders ranked attacks on connected products in their top three threats they are least prepared to address.
Regarding Operational Technology (OT) and Industrial Internet of Things (IIoT) systems, 47% of leaders cite a lack of qualified personnel/skillsets and resources as a top three challenge.
Only 16% of organisations are measuring the potential financial impact of cyber risks (risk quantification) to a significant extent.
The Top 2 challenges to implementing AI for cyber defence are knowledge and skills gaps.
41% of business and tech leaders prioritise changes in critical infrastructure location in response to the current geopolitical landscape.
60% of business and tech leaders prioritise cyber risk investment in response to the current geopolitical landscape.
Only 24% of organisations are spending significantly more on proactive measures (e.g., monitoring, testing, controls) than reactive measures (e.g., incident response, fines, recovery)—which is considered the ideal spend ratio.
AI (38%) and Cloud security (32%) are the top two areas where organisations are prioritising the use of managed services
Only 8% of security leaders include quantum readiness in their top three budget priorities for the coming year.
39% of business and tech leaders prioritise changes in cyber insurance policies in response to the current geopolitical landscape.
More than a quarter of executives reported that their most damaging data breach in the past three years cost their organisation at least $1 million.
Only 6% of organisations feel confident/very capable across all vulnerabilities surveyed, given the current geopolitical landscape.
Quantum computing now ranks among the Top 4 threats that organisations feel least prepared to address.
The top three priority areas for deploying agentic AI solutions are cloud security (39%), data protection (39%), and cyber defence and operations (38%).