ISACA’s 2026 State of Cybersecurity survey report also finds that the increasingly complex threat landscape has become an even bigger stressor for cybersecurity professionals this year
Schaumburg, IL, USA—In light of recent news revealing several instances of rogue AI model behavior, new research from ISACA finds concerning news about AI security. While AI is being heavily leveraged within cybersecurity teams, only eight percent of organizations indicate they conduct AI-specific response exercises regularly, according to ISACA’s 2026 State of Cybersecurity survey report.
ISACA’s survey report, sponsored by Wolters Kluwer TeamMate, gathered responses from more than 1,800 cybersecurity professionals across the globe, exploring trends in cybersecurity hiring, staffing and budgets; cyberrisk and threats; cybersecurity operations; and the role of AI in cybersecurity work.
AI incident response planning lags, even as AI transforms cybersecurity roles
This 12th annual survey also found that 64 percent of enterprises have not conducted any AI-related incident response exercises—which cover AI-related incidents such as sensitive data exposure through AI systems (24 percent), AI-enabled phishing, fraud or social engineering (23 percent), and misuse of generative AI by employees or insiders (21 percent). Seventeen percent say that AI incident response is included in broader cyber incident response exercises and 16 percent plan to conduct exercises in the future.
The gaps in planning also extend to AI incident playbooks—48 percent of respondents either don’t know whether their organization has established them or say their organization does not have them.
This comes as more cybersecurity professionals are using AI in their everyday work—only 13 percent do not use AI in their security operations. Among those who leverage AI on the job, top uses include automating threat detection/response (41 percent, up from 32 percent in 2025), automating routine security tasks (40 percent, up from 28 percent last year), and endpoint security (33 percent).
Increasingly, AI is also impacting the skills required in cybersecurity roles. Forty-five percent of respondents report that LLM SecOps is a skill gap they see among cybersecurity professionals, a 12-point increase from 2025 and a 21-point increase from 2024.
Cybersecurity professionals are also now even more hands-on with AI implementation and governance at their organizations, with more than half (51 percent) now involved in developing, onboarding or implementing AI solutions, up from 40 percent in 2025 and 29 percent in 2024. Additionally, 56 percent of respondents say that they or someone from their team were involved in the development of a policy governing the use of AI in their organization.
“AI is quickly becoming embedded in cybersecurity operations, but this research shows that many organizations have not yet matched that adoption with the response planning and workforce readiness required to manage AI-related risk,” says Jon Brandt, ISACA senior director, professional practices and innovation. “As cybersecurity professionals take on a larger role in implementing and governing AI, enterprises need to prioritize AI-specific incident exercises, clear playbooks and upskilling in areas such as LLM SecOps to help their teams use AI securely and effectively.”
Stress growing amid persistent staffing challenges, evolving threats
With increased AI use not only comes new work tools and responsibilities for cybersecurity staff, but also shifting cyber threats to mitigate—and with it, increased stress. Sixty-eight percent of survey respondents report that their roles have become more stressful over the past five years. Respondents cite the main cause of this stress as the increasingly complex threat landscape (71 percent, up from 63 percent in 2025). This is a change from the 18 percentage-point drop for this stress driver from 2024 (81 percent) to 2025 (63 percent).
This sentiment is prevalent as 45 percent of respondents say they expect a cyber-attack on their organization in the next year, and 35 percent indicate they are experiencing an increase in these attacks compared to a year ago. Less than half (42 percent) have high confidence in their organization’s cybersecurity team’s ability to detect and respond to cyber threats. These top attack types that enterprises are facing include social engineering (45 percent), vulnerabilities (39 percent), and remote access (24 percent) (an increase of five percent from 2025).
Additionally, staffing struggles continue to impact cybersecurity teams, with unrealistic expectations/too much work (52 percent) and work-life balance (45 percent) coming up as additional key stressors. Fifty-eight percent of organizations believe their cybersecurity team is understaffed, up slightly from 55 percent last year, and 49 percent report having open cybersecurity positions.
Retention also remains a challenge, with more than half (55 percent) reporting difficulties retaining qualified cybersecurity professionals. High work stress is now the leading reason people leave their roles, cited by 52 percent, up from 47 percent in 2025, followed by limited promotion and development opportunities (47 percent).
Taking steps to support staff, address skills gaps
However, some organizations are stepping up to support their cyber workforce. Fifty-three percent say their employer offers flexible work hours, and 46 percent encourage breaks and vacation time to mitigate burnout. Employers are also offering cybersecurity team members professional development training (68 percent, up from 60 percent last year), paying for certification fees (61 percent, up from 54 percent in 2025) and certification maintenance fees (59 percent, up from 52 percent in 2025), and offering flex work hours (58 percent, up from 52 percent last year) to improve retention.
Cybersecurity teams are also working to remedy skills gaps among their staff. In addition to LLM SecOps, respondents cite soft skills (57 percent), cloud computing (31 percent), data security (31 percent) and ML SecOps (31 percent) as the biggest skills gaps they see.
In this AI era, very human soft skills are still in demand, including critical thinking (59 percent), communication (listening, speaking, conflict resolution) (57 percent), problem solving (53 percent), teamwork (collaboration and cooperation) (47 percent), and adaptability/flexibility (43 percent).
Organizations are largely turning to online learning websites (49 percent) and mentoring (40 percent) to address nontechnical skills gaps. To address technical cybersecurity skills gaps, over a third (35 percent) of cybersecurity teams are increasing their reliance on AI or automation, a 12-point increase from last year. They are also turning to training non-security staff for security roles (27 percent) and increased usage of contract employees or outside consultants (26 percent).
“Despite a majority of organizations struggling with retention and security professionals identifying high workload as a critical factor in job stress, we see a year-over-year increase in organizations with no open cybersecurity positions,” says Sandy Buchanan, Lead Product Manager, Wolters Kluwer TeamMate. “It’s no surprise that we also see many organizations embracing the use of AI to augment their teams’ capabilities across their security operations. This highlights how critical it is for security and compliance platforms to provide AI-powered integrations and automation support to reduce the workload on these teams.”
Supporting cybersecurity professionals across every stage
In addition to thought leadership and resources such as this report, ISACA offers cybersecurity professionals with credentialing and training that meets their needs at every stage of their careers—including Certified Information Security Manager (CISM), Advanced in AI Security Management (AAISM), and the upcoming Certified Cybersecurity Specialist (CCS) certification for early-career professionals, slated to release in December.
Also, as part of its commitment to supporting cybersecurity professionals across their career journeys, the ISACA Foundation is offering cybersecurity scholarships throughout Cybersecurity Awareness Month. For more details and to apply, visit https://isaca.secure-platform.com/a/page/ISACAfoundation/aboutscholarships.
Diving into the research
Delve further into the topic in the complimentary upcoming 20 October webinar, “State of Cyber 2026: Global Update on Workforce Efforts, Resources, and Cybersecurity Operations.”
Additionally, gather more insights into these findings in this ISACA Now blog post with a Q&A featuring perspectives from global cybersecurity professionals.
Access the complimentary 2026 State of Cybersecurity survey report and related resources at www.isaca.org/state-of-cybersecurity. For more cybersecurity resources, visit www.isaca.org/resources/cybersecurity.
About ISACA
ISACA® (www.isaca.org) champions the global workforce advancing trust in technology. For more than 55 years, ISACA has empowered its community of 195,000+ members with the knowledge, credentials, training and network they need to thrive in fields like information security, governance, assurance, risk management, data privacy and emerging tech. With a presence in more than 190 countries and with more than 230 chapters worldwide, ISACA offers resources tailored to every stage of members’ careers—helping them to thrive in a rapidly changing digital landscape, drive trusted innovation and ensure a more secure digital world. Through the ISACA Foundation, ISACA also expands IT and education career pathways, fostering opportunities to grow the next generation of technology professionals.
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews
Contact:
communications@isaca.org
Emily Ayala, +1.847.385.7223
Bridget Drufke, +1.847.660.5554