MOST organisations have not rehearsed how they would respond to an artificial intelligence-related security incident, despite increasing use of AI by their security teams, according to ISACA’s 2026 State of Cyber report, published on 22 September 2026. The research found that 71% had conducted no AI incident-response exercises, while only 3% had mature, formal runbooks for AI-specific incidents. A further 30% had not started addressing AI incident response.
Potential scenarios include sensitive data exposure through AI systems, AI-enabled phishing, fraud and social engineering, and misuse of generative AI by employees or insiders.
AI adoption is advancing faster than preparation: 37% of organisations use AI to automate threat detection and response, up eight percentage points from 2025, while 35% use it for routine security tasks and 29% for endpoint security. ISACA said AI can help attackers automate activity that previously took days or weeks, and called governance essential.
Among European IT and cybersecurity professionals surveyed, 38% said their organisation had faced more attacks than the previous year, while 54% expected an attack in the next 12 months. Social engineering was the most commonly reported attack, cited by 46%, and was increasingly supported by AI. The report also found that 56% considered their teams understaffed and 55% underfunded, with 72% saying their work was more stressful than five years ago.