Cyber spending is back: After a few years of relatively flat cyber budgets, organisations are doubling down on their investment, with AI being a key driver. Among security and finance leaders, 84% expect budgets to increase—six percentage points higher than last year—and 58% of security leaders rank AI in their top cyber budget priorities.
The trust gap in autonomous agents: Organisations are eager to put AI agents to work for cyber defence, but far less willing to put them in charge. Only 22% would authorise fully autonomous AI actions, with reliability and maturity concerns being the biggest barriers.
When the lights go out: Keeping the business running, even through disruption, is the ultimate goal of cybersecurity. But surprisingly, only 39% of security, risk, and operations leaders have fully formalised and integrated operational continuity plans that specifically address cyber risks, even though cyber incidents have become a matter of when, not if.
Strong foundations matter more than ever: As organisations focus on emerging threats and leveraging data for use in AI systems, many are doing so without fully securing the data they’re entrusted to protect. On average, companies have implemented only three out of seven key data risk measures across their organisations.
Who’s accountable for AI? No single ownership model has emerged for AI governance and risk management: 29% of CEOs and security and risk leaders say accountability sits with the CIO, CTO, or technology function, 26% with a dedicated AI leader or AI function, and 17% with the CISO or cyber function.
Managed services extend critical capabilities: Organisations are turning to strategic partners for specialised expertise as technologies and threats evolve. AI (53%) and cloud security (49%) rank among their top priorities for managed security services over the coming year.
Looking for more? Explore PwC’s full 2027 Global Digital Trust Insights report for comprehensive survey findings and this year’s C-suite playbook. The playbook translates the survey findings into practical actions that leaders—CEOs, CISOs, CIOs/CTOs, CDOs, CFOs, and others—can take. The goal? Building trusted foundations and accelerating the move towards a more intelligent enterprise, one that connects the entire organisation to make better decisions and adapt with speed and confidence.
Amid a complex risk and threat landscape, AI has emerged as the biggest challenge. Half (50%) of security leaders identify attacks targeting AI systems as one of their biggest preparedness gaps, followed by cloud-related threats (40%), third-party breaches (34%), and ransomware (33%). Security for AI has emerged as the most acute preparedness gap, underscoring that deployment speed and security cannot be treated as competing choices.
This preparedness gap becomes more urgent as AI capabilities advance. Frontier AI models are now exceptionally good at finding previously unknown software vulnerabilities and exploiting those weaknesses through sophisticated attack paths with minimal human intervention.
As frontier AI reshapes the threat landscape, organisations are increasingly concerned about AI-enabled attacks. Security and risk leaders rank compromise by autonomous botnets (53%), adversarial attacks (52%), and data poisoning (52%) as the top AI-enabled attacks they’re least prepared to address.
“AI is creating both a new class of security risk and one of the biggest opportunities defenders have had in decades. The challenge is building trust and control at the same speed as adoption.”
Phil Venables, Partner, Ballistic VenturesGeopolitics is also changing the cyber risk landscape. Cyber operations are now a persistent feature of geopolitical competition in both conflict and peacetime. Organisations have been forced to adapt. Half (50%) are making changes to vendor, third-party, and supply chain risk management, while 49% are making changes to cyber insurance, incident response, and crisis management to help bolster their defences against geopolitical threats.
Looking further ahead, the next cybersecurity challenge already looms on the horizon. Quantum computing exposure ranks seventh among the threats organisations feel least prepared to address. CISOs, however, place it fourth among their top concerns, suggesting that those closest to cyber risk see a greater urgency to prepare. The transition to quantum-resistant security will take years, not months, meaning companies should start preparing now to be ready when Q-Day arrives. Still, only 21% of organisations are implementing quantum security measures, while nearly half (49%) have not even begun.
After a few years of relatively flat investment, 84% of security and finance leaders say they are increasing cybersecurity budgets to respond to these evolving threats, with AI emerging as one of the top areas for investment. But will this renewed emphasis on investment translate into resilience?
When asked what factors are influencing their cyber spend priorities for the coming year, about half (51%) ranked 'data protection and trust' as their top choice. Close behind were securing against AI-enabled attacks (46%) and securing AI and autonomous agents (45%).
This focus is critical because AI is only as trustworthy as the data beneath it. Yet many organisations are pursuing AI and other emerging technologies without fully securing one of their most important assets: data. Even in the face of rising frontier AI vulnerabilities, companies have implemented only three out of seven key data risk measures across their organisations. What’s more, only 5% have fully implemented every data risk measure surveyed, down from 7% last year. This key gap identified in last year’s survey has not only persisted but widened.
Beyond this, the fundamentals of data protection still need work. Only about half of organisations have fully implemented data classification policies (49%) and data loss prevention across key egress channels (48%), while other measures ranked even lower. These foundational capabilities become even more critical when AI, cloud, and connected ecosystems come into play. Organisations can’t build cyber resilience on an insecure data foundation.
The top defence against cyber attacks may be AI itself. With AI emerging as the top cyber investment priority, security leaders are deploying it first where speed and scale matter most. Half (50%) ranked threat detection and alerting among their top priorities, followed by fraud detection (43%) and phishing detection and response (42%). As cyber attacks accelerate beyond human speed, AI is becoming an essential force multiplier for security teams.
The journey to using fully autonomous AI agents for cyber defence will happen in stages. While 22% would authorise AI agents to fully execute defensive manoeuvres without human approval, most are taking a more measured approach. More than one-third (38%) would permit partial autonomy, while 36% prefer human-led execution with AI support across all actions.
Routine tasks are the natural starting point. Organisations are most comfortable authorising autonomous agents for well-defined, repeatable activities such as threat intelligence enrichment and correlation (49%), phishing email quarantine or deletion (47%), and malware removal and system remediation (46%).
More than half (55%) rank reliability and maturity of AI technology among their top three barriers to increasing AI agent autonomy in security operations, while 46% cite accountability and explainability in AI decision-making.
The barriers extend beyond the technology itself. Nearly half of CISOs (44%) identify workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy. Compared with the broader respondent population, CISOs appear more likely to recognise that successful deployment depends on having the right people in place to oversee it.
Agents produce probabilistic outputs, so their autonomy should be governed by what stands between the agent and the consequence. Where an outcome should be correct every time, the agent’s output should pass through a control the agent cannot influence, such as review, an approval workflow, or validation by another system, before it takes effect.
"To be successful in the era of AI, we need to be able to defend at machine speed."
Matt Rowe, Chief Security Officer, Lloyds Banking GroupThe cybersecurity skills gap remains a challenge. To retain employees, organisations place growth opportunities (59%), a strong cyber culture (53%), and AI-enabled tools and training (53%) among their top priorities. The emphasis is on development.
As AI becomes embedded in security operations, organisations appear to be placing greater emphasis on helping employees work alongside AI. Yet capability gaps extend beyond AI. A lack of skills and resources remains the biggest challenge to securing operational technology and industrial systems.
With those gaps, the survey tells a consistent story: managed services have become essential. AI and cloud security are the threats organisations feel least prepared to address. They’re also the leading areas for cyber investment and use of managed security services. Security leaders rank AI (53%), cloud security (49%), data protection and trust (42%), and threat management (39%) among their top priorities for managed services over the coming year.
As in last year’s survey, AI and cloud security top the list. This signals that organisations recognise the need for specialised partners that can provide a mix of talent, technology, and strategy to help them defend and adapt in a dynamic digital environment.