Cybersecurity teams increasingly are integrating artificial intelligence into their operations, yet only 8 percent of organizations indicate they conduct AI-specific response exercises regularly, according to new research from ISACA.
ISACA’s 2026 State of Cybersecurity survey report, sponsored by Wolters Kluwer TeamMate, gathered responses from more than 1,800 cybersecurity professionals across the globe, exploring trends in cybersecurity hiring, staffing, and budgets; cyberrisk and threats; cybersecurity operations; and the role of AI in cybersecurity work.
ISACA’s 12th annual State of Cybersecurity survey also found that the gaps in planning at enterprises extend to AI incident playbooks—48 percent of respondents either don’t know whether their organization has established them or say their organization does not have them.
This comes as a large majority of cybersecurity professionals are using AI in their everyday work—only 13 percent do not use AI in their security operations. Among those who do leverage it on the job, top uses include automating threat detection/response (41 percent, up from 32 percent in 2025), automating routine security tasks (40 percent, up from 28 percent last year) and endpoint security (33 percent).
“AI is quickly becoming embedded in cybersecurity operations, but this research shows that many organizations have not yet matched that adoption with the response planning and workforce readiness required to manage AI-related risk,” says Jon Brandt, ISACA senior director, professional practices and innovation. “As cybersecurity professionals take on a larger role in implementing and governing AI, enterprises need to prioritize AI-specific incident exercises, clear playbooks and upskilling in areas such as LLM SecOps to help their teams use AI securely and effectively.”
Alongside increased AI use not only comes new work tools and responsibilities for cybersecurity staff but also shifting cyber threats to mitigate—and with it, increased stress. Sixty-eight percent of survey respondents report that their roles have become more stressful during the past five years. Respondents cite the main cause of this stress as the increasingly complex threat landscape (71 percent, up from 63 percent in 2025). This is a change from the 18 percentage-point drop for this stress driver from 2024 (81 percent) to 2025 (63 percent).
Meanwhile, staffing struggles continue to strain cybersecurity teams, with unrealistic expectations/too much work (52 percent) and work-life balance (45 percent) coming up as additional key stressors. Fifty-eight percent of organizations believe their cybersecurity team is understaffed and 61 percent report open cybersecurity roles in their organizations.
Retention also remains a challenge, with more than half (55 percent) reporting difficulties retaining qualified cybersecurity professionals. High work stress is now the leading reason people leave their roles, cited by 52 percent, followed by limited promotion and development opportunities (47 percent).
However, some organizations are stepping up to support their cyber workforce. Fifty-three percent say their employer offers flexible work hours and 46 percent encourage breaks and vacation time to mitigate burnout. Employers are also offering cybersecurity team members professional development training (68 percent, up from 60 percent last year), paying for certification fees (61 percent, up from 54 percent in 2025) and paying for certification maintenance fees (59 percent, up from 52 percent in 2025), and offering flex work hours (58 percent, up from 52 percent last year) to improve retention.
Cybersecurity teams are also striving to address skills gaps among their staff. In addition to LLM SecOps, respondents cite soft skills (57 percent), cloud computing (31 percent), data security (31 percent) and ML SecOps (31 percent) as the biggest skills gaps they see.
In this AI era, very human soft skills are still in demand, including critical thinking (59 percent), communication (listening, speaking, conflict resolution) (57 percent), problem solving (53 percent), teamwork (collaboration and cooperation) (47 percent), and adaptability/flexibility (43 percent).
“Cybersecurity professionals also need business understanding, clear communication and sound judgment,” Saurabh Misra, Senior Manager – Technology Risk, Governance, Audit & Cybersecurity, ManpowerGroup, wrote in an ISACA Now blog post analyzing the ISACA research. “Security teams are most effective when they can connect a technical weakness to its potential business impact, explain the risk in plain language and help leaders select a practical response.”
In addition to thought leadership and resources such as this report, ISACA offers cybersecurity professionals credentialing and training that meets their needs at every stage of their careers—including CISM, AAISM, and the upcoming Certified Cybersecurity Specialist (CCS) certification for early-career professionals, slated to release in December.
Also, as part of its commitment to supporting cybersecurity professionals across their career journeys, the ISACA Foundation is offering cybersecurity scholarships throughout Cybersecurity Awareness Month. For more details and to apply, visit https://isaca.secure-platform.com/a/page/ISACAfoundation/aboutscholarships.
Gain deeper insights into the State of Cybersecurity in the complimentary upcoming 20 October webinar, “State of Cyber 2026: Global Update on Workforce Efforts, Resources, and Cybersecurity Operations.”
Access the complimentary 2026 State of Cybersecurity survey report and related resources at www.isaca.org/state-of-cybersecurity. For more cybersecurity resources, visit www.isaca.org/resources/cybersecurity.