LONDON, 1 October 2026 — Organisations are doubling down on their cyber investment amid rapid advances in AI, with more than four-fifths (84%) of security and finance leaders expecting cyber budgets to increase—up from 78% last year—according to PwC’s 2027 Global Digital Trust Insights Survey, launched today.
The survey, which captured the views of almost 4,000 business and tech executives across 71 countries and territories, finds that as frontier AI models are rolled out, almost two-thirds (58%) of security leaders rank AI in their top cyber budget priorities for the year ahead.
This comes as less than two-fifths (39%) of security, risk and operations leaders have a fully formalised and integrated operational continuity plan that specifically addresses cyber risks altogether.
When asked specifically about the cyber threats organisations are least prepared to address, half (50%) of security leaders identify attacks targeting AI systems amongst their top threats—ahead of cloud-related threats (40%), third-party breaches (34%) and ransomware (33%).
“The ultimate goal of cybersecurity is not just to protect the business, but to give the business the confidence to move forward. As organisations race to capture the value of AI, cyber resilience needs to become a business capability, embedded in C-suite decision-making from the outset. The survey finds many organisations are still under-prepared for a rapidly evolving cyber landscape and organisations that get this right will be better positioned to innovate with confidence while continuing to operate through disruption.”
Cyber resilience will require C-suite elevation
Organisations should embed cyber-security in their C-suite decision-making if they are to bolster their cyber defences.
Even in the face of rising frontier AI vulnerabilities, companies have only implemented, on average, three out of seven key data-risk measures across their organisations. What’s more, only 5% of those surveyed have fully implemented every data risk measure surveyed—down from 7% last year.
While one-third (33%) of CEOs and security and risk leaders say their organisations have established dedicated AI roles, including a chief AI officer or AI board, less than half strongly agree that cyber risk is a standing agenda item at the board level (47%) or at executive leadership meetings (45%).
Unlocking AI’s defensive potential
As cyber-attacks accelerate beyond human speed, AI is becoming an essential force multiplier for security teams. However, trust remains low—particularly around using autonomous AI agents.
This comes as compromise by autonomous botnets (53%), adversarial attacks (52%), and data poisoning (52%) rank among the top AI-enabled attacks that security and risk leaders say they are least prepared to address.
While security leaders rank threat detection and alerting (50%) and phishing detection and response (42%) among the top priority AI areas for cyber defence—roughly only one-fifth (22%) would authorise fully autonomous execution by AI agents for cyber defence.
Rapid advances in AI, however, are proving problematic. More than half (55%) rank reliability and maturity of AI technology among their top three barriers to increasing AI agent autonomy in security operations, while 46% cite accountability and explainability in AI decision-making.
Nearly half of CISOs (44%) identify workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy.
Bolstering cyber resilience in the age of AI
As organisations contend with a new frontier of cyber risks, they are taking action.
More than half (54%) of security and risk leaders are adopting multi-cloud or hybrid cloud strategies, while others are strengthening regional data and tech redundancy (47%) and localising infrastructure within specific jurisdictions (37%) to reduce concentration risk across their value chain.
As geopolitics shapes the cyber risk landscape, half (50%) are also making changes to vendor, third-party and supply chain risk management.
As cyber budgets take centre-stage, some companies are bringing in managed services to help—with artificial intelligence (53%) the leading focus area as organisations confront a shortage of specialist cyber and AI talent.
If organisations are to insulate their businesses against rapidly evolving AI and cyber threats, they must:
“AI is changing both sides of the cyber equation. It is creating new risks and expanding the attack surface, but it can also transform how organisations defend themselves. The opportunity is to build the trust, governance and human oversight that allow organisations to use AI more confidently to secure the enterprise and create value.”
– ENDS –
Notes to Editors
About PwC’s 2027 Global Digital Trust Insights Survey
PwC’s 2027 Global Digital Trust Insights Survey captured the views of 3,934 business and tech executives across 71 countries and territories. It reveals how leaders are managing cybersecurity in a dynamic digital world and where critical gaps remain. Find out more about the survey findings and how organisations can future-proof their cyber-resilience at www.pwc.com.
About PwC
At PwC, we help clients build trust and reinvent so they can turn complexity into competitive advantage. We’re a tech-forward, people-empowered network with more than 360,000 people in more than 130 countries and territories. Across audit and assurance, tax and legal, deals and consulting, we help clients build, accelerate and sustain momentum. Find out more at www.pwc.com.