Brian Sims
Editor

“Cyber teams stretched as attacks intensify and budgets shrink” reports ISACA

CYBER ATTACKS are rising in number, but the teams defending against them are not growing to keep pace. Four in every ten (38%) European IT and cyber security professionals have noted that their organisation faced more attacks this year than last, yet more than half (56%) remain understaffed and underfunded (55%). That’s according to new research conducted by ISACA.

ISACA’s report focused on the State of Cyber Security 2026 notes that attack volumes are expected to rise still further, with half (54%) of those cyber security professionals interviewed believing it’s likely their organisation will experience a cyber attack within the next 12 months.

Cyber security teams are also having to grapple with new threats. Cyber criminals and hackers are now behind 39% of all incidents. It emerges that social engineering (which involves the manipulation of individuals rather than breaking through systems) is the most common form of attack. Social engineering attacks are increasingly supported by Artificial Intelligence (AI), duly overtaking conventional hacking methods.

Compounding this issue, 72% of cyber security-focused professionals report that their role is more stressful now than it was five years ago. The increasingly complex threat landscape is cited as the direct cause of this. Other reasons put forward are unrealistic expectations and too much work (57%), as well as members of staff not being sufficiently trained or skilled (35%).

Despite this, one-fifth (21%) of companies still take no action to mitigate ‘burnout’, choosing not to address such challenges even when cyber security teams are clearly pushed to their limits. Other organisations are taking steps to ease the pressure, with 55% of them offering flexible working hours and 46% encouraging employees to take breaks and holidays to mitigate that ‘burnout’.

Growing gap

Chris Dimitriadis, global chief strategy officer at ISACA, informed Security Matters: “The growing gap between rising threats and under-resourcing in relation to cyber security is taking its toll on the very people tasked with managing it. Too often, we’re seeing budgets being sunk into crisis response, but there’s still a distinct lack of investment in the workforce, training and resources needed to prevent attacks and protect organisations in the first place.”

Dimitriadis continued: “Preparedness is key to resilience. We must see this reflected in the way in which businesses approach cyber security investment. Better funding and a clear plan for improving cyber resilience should absolutely be a C-Suite priority.”

AI’s exponential growth has proved to be an assistance for cyber security teams, with its footprint in cyber operations expanding dramatically across the past year. Almost four in every ten (37%) organisations now use AI to automate threat detection and response. That’s a rise from eight percentage points on the corresponding 2025 figures. AI is also being used for endpoint security by 29% of survey respondents and to automate routine security tasks by 35% of them. 

Cyber professionals are increasingly shaping how AI is adopted. More broadly. 54% said either themselves or their team as a whole had been involved in the development, onboarding or implementation of AI solutions, while 60% have had a hand in developing policies governing AI use within their organisation.

Difficult and serious challenges

That said, AI also serves to present difficult and serious challenges for cyber security teams. AI-enabled cyber attacks mean that bad actors can operate at the speed of intent, automating attacks that once took days or even weeks to plan and perpetrate.

It seems that preparedness for when AI itself goes wrong is lagging well behind adoption. Almost three-quarters (71%) of organisations have not conducted any AI-related incident response exercises. Such exercises can prepare organisations for scenarios including sensitive data exposure through AI systems, AI-enabled phishing, fraud or social engineering, in addition to the misuse of generative AI by employees or insiders.

Just 3% of those organisations surveyed report mature and formal ‘runbooks’ for AI-specific incidents, while close to one-third (30%) have not even begun to address their response to AI-related incidents.

Chris Dimitriadis concluded: “Organisations can effectively use AI for preventing and detecting cyber threats. However, its governance should be non-negotiable. AI governance is critical for ensuring that employees are using AI safely in the workplace and also that businesses understand and can protect themselves from AI generated threats. Implementing checks and balances can realise a structured way in which to benchmark AI governance maturity rather than relying on ad hoc controls as adoption accelerates.”

As AI transforms cyber threats and the tools available to defend against it, ISACA has warned that governance, readiness and funding must be seen to keep pace with adoption.

Upcoming webinar

In order to delve deeper into the subject, ISACA is hosting a complimentary webinar. The event – running under the headline State of Cyber 2026: Global Update on Workforce Efforts, Resources and Cyber Security Operations – takes place on 1 October.

Additionally, further insights on the research findings are offered in the ISACA Now blog post complete with a Q&A featuring perspectives from global cyber security professionals.  

*Access the State of Cyber Security 2026 report and related resources at www.isaca.org/state-of-cybersecurity

**For more cyber security resources visit www.isaca.org/resources/cybersecurity

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up