Report by EY
The AI landscape in cybersecurity
Key Findings
26% of organizations report their AI cybersecurity governance framework is fully rolled out and integrated across relevant business units.
97% of senior corporate security leaders agree their organization's competitive advantage in the next two years will be directly tied to the maturity of agentic AI cybersecurity defenses.
Currently, 30% of senior corporate security leaders say Advanced Persistent Threat detection is largely run with agentic AI; this rises to 62% in two years.
Currently, 27% of senior corporate security leaders say data privacy and compliance is largely run with agentic AI; this rises to 48% in two years.
Currently, 9% of organizations dedicate at least 25% of their total cybersecurity budget to AI solutions; this share is expected to rise to 48% in two years.
96% of senior corporate security leaders say AI-enabled cybersecurity attacks are a significant threat to their organization.
85% of senior corporate security leaders using AI in cybersecurity say their current cybersecurity budget is insufficient to meet AI-enabled threats.
Currently, 23% of senior corporate security leaders say deep fake and impersonation defense is largely run with agentic AI; this rises to 42% in two years.
Currently, 25% of senior corporate security leaders say third-party risk management is largely run with agentic AI; this rises to 50% in two years.
48% of senior corporate security leaders estimate at least 25% of their organization's cybersecurity incidents in the past year were enabled by AI.
99% of senior corporate security leaders are confident that strategic use of AI will transform their organization's proactive cybersecurity strategies.
Currently, 32% of senior corporate security leaders say real-time fraud detection is largely run with agentic AI; this is expected to rise to 58% in two years.
20% of organizations have optimized their AI cybersecurity governance frameworks and embedded them into organizational culture.
51% of senior corporate security leaders report having a defined AI cybersecurity governance framework that is implemented and embedded in key processes.
98% of senior corporate security leaders with an AI cybersecurity governance framework agree the framework is essential for ensuring the responsible use of AI.
99% of senior corporate security leaders are confident that strategic use of AI will transform their organization's defensive cybersecurity strategies.
Currently, 23% of senior corporate security leaders say Identity and Access Management is largely run with agentic AI; this rises to 51% in two years.