Report by PwC
2027 Global Digital Trust Insights: C‑suite playbook and findings
Key Findings
Half of security leaders identify attacks targeting AI systems as one of their biggest preparedness gaps.
Security and risk leaders rank compromise by autonomous botnets (53%), adversarial attacks (52%), and data poisoning (52%) as the top AI-enabled attacks they are least prepared to address.
Only 21% of organisations are implementing quantum security measures, while 49% have not even begun.
84% of security and finance leaders expect their cyber budget to increase, six percentage points higher than last year.
About half (51%) rank data protection and trust as their top cyber spend priority, 46% rank securing against AI-enabled attacks, and 45% rank securing AI and autonomous agents.
More than half (55%) rank reliability and maturity of AI technology among their top three barriers to increasing AI agent autonomy, while 46% cite accountability and explainability.
To retain employees, organisations place growth opportunities (59%), a strong cyber culture (53%), and AI-enabled tools and training (53%) among their top priorities.
Security leaders rank AI (53%), cloud security (49%), data protection and trust (42%), and threat management (39%) among their top priorities for managed security services over the coming year.
29% of CEOs and security and risk leaders say AI governance accountability sits with the CIO, CTO, or technology function, 26% say it sits with a dedicated AI leader or AI function, and 17% say it sits with the CISO or cyber function.
Only 39% of security, risk, and operations leaders have fully formalised and integrated operational continuity plans that specifically address cyber risks.
58% of security leaders rank AI in their top cyber budget priorities.
Cloud-related threats (40%), third-party breaches (34%), and ransomware (33%) rank after AI as major preparedness gaps.
Half of organisations are making changes to vendor, third-party, and supply chain risk management, while 49% are making changes to cyber insurance, incident response, and crisis management.
On average, companies have implemented only three out of seven key data risk measures across their organisations.
Only 5% of organisations have fully implemented every data risk measure surveyed, down from 7% last year.
About half of organisations have fully implemented data classification policies (49%) and data loss prevention across key egress channels (48%).
50% of security leaders rank threat detection and alerting among their top AI-for-security priorities, followed by fraud detection (43%) and phishing detection and response (42%).
22% of organisations would authorise AI agents to fully execute defensive manoeuvres without human approval, 38% would permit partial autonomy, and 36% prefer human-led execution with AI support.
Organisations are most comfortable authorising autonomous agents for threat intelligence enrichment and correlation (49%), phishing email quarantine or deletion (47%), and malware removal and system remediation (46%).
Nearly half of CISOs (44%) identify workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy.