DKDKCISSPSearch
AI SecurityDEVELOPING

AI Threats Top Cybersecurity Preparedness Gap, PwC Finds

The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.

DKCISSP News DeskInfosecurity Magazine1 Oct 2026, 3:00 pm
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.

Over half (52%) said adversarial AI attacks represent the biggest cyber preparedness gap.

The challenge of responding to these risks is compounded by governance issues.

Read more on adversarial AI: Researchers Discover Major Security Gaps in LLM Guardrails That said, many are optimistic about the future, with 84% of security and finance bosses expecting budgets to increase – six percentage points higher than in 2025.

Organizations also need clear accountability for AI risk – who owns the decisions, who is responsible when an AI system behaves unexpectedly and where human oversight is required – alongside people with the skills to exercise that oversight effectively.” Over two-fifths (44%) of CISOs identified workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy.

A recent report from Swimlane revealed that 62% of SOC workers believe AI has already helped their SecOps skill development.

PwC claimed no single ownership model has emerged for AI risk management, with respondents split over whether accountability sits with the CIO, CTO or technology function (29%), a dedicated AI leader or AI function (26%), or the CISO or cyber function (17%).

Only around half of responding organizations said they’d fully implemented data classification (49%) and data loss prevention (48%) policies.

However, a third (33%) of CEOs and security and risk leaders said they have already appointed a dedicated AI role, such as a chief AI officer.

Data risk is also proliferating, which in turn impacts AI risk.

Over half (58%) said AI is a top-five cyber budget priority.

Responsible AI governance (42%), platform hardening (38%), and supply chain security (35%) are top of the to-do list when it comes to AI.

However, organizations are also keen to utilize AI in their cyber defenses, including threat detection and alerting (50%), fraud detection (43%), and phishing detection and response (42%).

A recent report by Gartner warned that CISOs must update their playbooks to take into account the rise of sophisticated deepfakes.

What happened

The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.

Over half (52%) said adversarial AI attacks represent the biggest cyber preparedness gap.

The challenge of responding to these risks is compounded by governance issues.

What changed

Read more on adversarial AI: Researchers Discover Major Security Gaps in LLM Guardrails That said, many are optimistic about the future, with 84% of security and finance bosses expecting budgets to increase – six percentage points higher than in 2025.

Organizations also need clear accountability for AI risk – who owns the decisions, who is responsible when an AI system behaves unexpectedly and where human oversight is required – alongside people with the skills to exercise that oversight effectively.” Over two-fifths (44%) of CISOs identified workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy.

A recent report from Swimlane revealed that 62% of SOC workers believe AI has already helped their SecOps skill development.

Who is affected

PwC claimed no single ownership model has emerged for AI risk management, with respondents split over whether accountability sits with the CIO, CTO or technology function (29%), a dedicated AI leader or AI function (26%), or the CISO or cyber function (17%).

Only around half of responding organizations said they’d fully implemented data classification (49%) and data loss prevention (48%) policies.

Why it matters

However, a third (33%) of CEOs and security and risk leaders said they have already appointed a dedicated AI role, such as a chief AI officer.

Data risk is also proliferating, which in turn impacts AI risk.

Technical details

Over half (58%) said AI is a top-five cyber budget priority.

Responsible AI governance (42%), platform hardening (38%), and supply chain security (35%) are top of the to-do list when it comes to AI.

However, organizations are also keen to utilize AI in their cyber defenses, including threat detection and alerting (50%), fraud detection (43%), and phishing detection and response (42%).

Response

A recent report by Gartner warned that CISOs must update their playbooks to take into account the rise of sophisticated deepfakes.

To help counter deepfake attacks, it’s recommended that staff are trained on how to identify them, that phishing resistant controls such as MFA are employed across systems and that security teams should be on the lookout for suspicious communications and impersonation events.

What security teams should do

Tonya Ugoretz, cyber & risk innovation institute co-leader, PwC US, told Infosecurity that organizations should start with the fundamentals to tackle adversarial attacks.

This matters, because over half (55%) ranked reliability of the technology as preventing broader adoption of agents, PwC said.

Attribution

Infosecurity Magazine: The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.

Infosecurity Magazine: The 2026 Pindrop Deepfake Readiness Index , published on 28 September, warned there is a significant gap between the threat of deepfake attacks and enterprise readiness to defend against them.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 am