Download Privacy Needle App

Type to search

Cybersecurity

Most Organisations Unprepared for AI-Driven Security Incidents

Share

Most organisations are unprepared to handle security incidents involving artificial intelligence (AI), despite a significant increase in the technology’s use within security operations.

According to ISACA’s 2026 State of Cyber report, 71% of organisations have not conducted any AI-specific incident response exercises. Furthermore, only 3% of businesses have established mature, formal runbooks to manage AI-related incidents, while 30% have made no attempt to address their response strategies at all.

These preparedness gaps exist as AI adoption accelerates. The report indicates that 37% of organisations now use AI to automate threat detection and response—an increase of eight percentage points since 2025. Additionally, 35% of firms use AI for routine security tasks, and 29% utilise it for endpoint security.

The Gap Between Adoption and Preparedness

The lack of preparedness is particularly concerning as the threat landscape evolves. Security professionals are observing attackers using AI to operate at “the speed of intent,” automating attacks that previously required days or weeks to execute.

Potential AI-related security incidents include the exposure of sensitive data through AI systems, AI-enabled phishing and fraud, and the misuse of generative AI by employees or insiders. Social engineering remains a primary concern, cited by 46% of surveyed professionals, and is increasingly being supported by AI technologies.

Chris Dimitriadis, ISACA’s global chief strategy officer, noted that while AI can be a powerful tool for preventing and detecting threats, governance must be a non-negotiable priority. He suggested that organisations look to the CMMI AI Maturity Model as a benchmark for establishing safe AI usage and protecting against AI-generated threats.

Workforce Pressure and Evolving Threats

The report also highlights increasing pressure on cybersecurity teams. Among European professionals surveyed, 38% reported their organisations faced more cyber-attacks than the previous year, and 54% expect an attack within the next 12 months.

The complexity of the threat landscape is contributing to significant workforce stress, with 72% of professionals stating their jobs are more stressful than they were five years ago. This pressure is exacerbated by resource shortages, as 56% of respondents reported their teams are understaffed and 55% said they are underfunded.

Burnout remains a critical issue, with one-fifth of companies taking no action to address it. Dimitriadis observed that budgets are frequently directed toward crisis response rather than the workforce training and development required to prevent attacks, suggesting that improved funding and clear resilience plans should become a priority for C-suite executives.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.