AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.

The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.
Over half (52%) said adversarial AI attacks represent the biggest cyber preparedness gap.
The challenge of responding to these risks is compounded by governance issues.
Read more on adversarial AI: Researchers Discover Major Security Gaps in LLM Guardrails That said, many are optimistic about the future, with 84% of security and finance bosses expecting budgets to increase – six percentage points higher than in 2025.
Organizations also need clear accountability for AI risk – who owns the decisions, who is responsible when an AI system behaves unexpectedly and where human oversight is required – alongside people with the skills to exercise that oversight effectively.” Over two-fifths (44%) of CISOs identified workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy.
A recent report from Swimlane revealed that 62% of SOC workers believe AI has already helped their SecOps skill development.
PwC claimed no single ownership model has emerged for AI risk management, with respondents split over whether accountability sits with the CIO, CTO or technology function (29%), a dedicated AI leader or AI function (26%), or the CISO or cyber function (17%).
Only around half of responding organizations said they’d fully implemented data classification (49%) and data loss prevention (48%) policies.
However, a third (33%) of CEOs and security and risk leaders said they have already appointed a dedicated AI role, such as a chief AI officer.
Data risk is also proliferating, which in turn impacts AI risk.
Over half (58%) said AI is a top-five cyber budget priority.
Responsible AI governance (42%), platform hardening (38%), and supply chain security (35%) are top of the to-do list when it comes to AI.
However, organizations are also keen to utilize AI in their cyber defenses, including threat detection and alerting (50%), fraud detection (43%), and phishing detection and response (42%).
This matters, because over half (55%) ranked reliability of the technology as preventing broader adoption of agents, PwC said.
What happened
The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.
Over half (52%) said adversarial AI attacks represent the biggest cyber preparedness gap.
The challenge of responding to these risks is compounded by governance issues.
What changed
Read more on adversarial AI: Researchers Discover Major Security Gaps in LLM Guardrails That said, many are optimistic about the future, with 84% of security and finance bosses expecting budgets to increase – six percentage points higher than in 2025.
Organizations also need clear accountability for AI risk – who owns the decisions, who is responsible when an AI system behaves unexpectedly and where human oversight is required – alongside people with the skills to exercise that oversight effectively.” Over two-fifths (44%) of CISOs identified workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy.
A recent report from Swimlane revealed that 62% of SOC workers believe AI has already helped their SecOps skill development.
Who is affected
PwC claimed no single ownership model has emerged for AI risk management, with respondents split over whether accountability sits with the CIO, CTO or technology function (29%), a dedicated AI leader or AI function (26%), or the CISO or cyber function (17%).
Only around half of responding organizations said they’d fully implemented data classification (49%) and data loss prevention (48%) policies.
Why it matters
However, a third (33%) of CEOs and security and risk leaders said they have already appointed a dedicated AI role, such as a chief AI officer.
Data risk is also proliferating, which in turn impacts AI risk.
Technical details
Over half (58%) said AI is a top-five cyber budget priority.
Responsible AI governance (42%), platform hardening (38%), and supply chain security (35%) are top of the to-do list when it comes to AI.
However, organizations are also keen to utilize AI in their cyber defenses, including threat detection and alerting (50%), fraud detection (43%), and phishing detection and response (42%).
Response
This matters, because over half (55%) ranked reliability of the technology as preventing broader adoption of agents, PwC said.
Over half (53%) of respondents claimed that AI-enabled training is among their top priorities to help close the skills gap and retain employees, alongside providing more growth opportunities (59%) and nurturing a strong cyber culture (53%).
What security teams should do
Tonya Ugoretz, cyber & risk innovation institute co-leader, PwC US, told Infosecurity that organizations should start with the fundamentals to tackle adversarial attacks.
Attribution
Infosecurity Magazine: The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.