Report by Filigran
AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
Key Findings
27% of security professionals would prioritise automating the conversion of threat intelligence into actionable priorities.
52% of security professionals say threat intelligence helps inform decisions but still requires significant human judgement.
44% of security professionals say a human should always remain in the loop for security decisions.
16% of security professionals say supply chain and third-party risk is the boardroom cyber priority boards ask about most.
15% of security professionals say cloud and infrastructure exposure is the boardroom cyber priority boards ask about most.
21% of security professionals say the volume of threat intelligence information often creates more noise than clarity.
38% of security professionals would trust AI only for low-risk, routine security decisions.
11% of security professionals are still experimenting with AI-driven decision-making.
28% of security professionals say their organisation has a continuous, proactive exposure management programme in place.
13% of security professionals say delays waiting for other teams to act on findings wastes the most time in their security team.
19% of security professionals completely trust threat intelligence to tell them what to fix first.
19% of security professionals say regulatory compliance (including NIS2 and DORA) is the boardroom cyber priority boards ask about most.
32% of security professionals say AI-driven threats and organisational preparedness are the top issues boards ask about most.
8% of security professionals would trust AI to make security decisions without human approval.
41% of cybersecurity professionals identify AI-powered attacks at scale as their biggest security concern, compared with 21% citing supply chain risk and 21% citing unknown threats.
25% of security professionals say validating whether risks are real wastes the most time in their security team.
26% of security professionals say chasing false positives and low-priority alerts wastes the most time in their security team.
17% of security professionals say manually stitching together data from multiple security tools wastes the most time in their security team.