top of page

Cyber budgets are rising, but AI is the threat leaders are least ready for

1 hour ago
6 min read

This article summarises findings from PwC’s 2027 Global Digital Trust Insights survey, “Moving targets: Cybersecurity in a dynamic digital world,” published on 1 October 2026. The survey, conducted by PwC Research from May through July 2026, captured the views of 3,934 business and technology leaders across 71 countries. Figures and themes are drawn from PwC’s survey overview, the accompanying C-suite playbook and findings, and the firm’s launch press release, “84% of senior leaders expect cyber budgets to rise as frontier AI models are rolled out.” The piece covers the rebound in cyber spending, attacks on AI systems as the leading preparedness gap, limited trust in autonomous defence agents, and shortfalls in continuity planning, data controls, and AI governance.



PwC’s 2027 Global Digital Trust Insights survey finds that cybersecurity budgets are rising again, driven by frontier AI, while the threat leaders say they are least prepared for is an attack on the AI systems themselves. The report, titled “Moving targets: Cybersecurity in a dynamic digital world,” is based on responses from 3,934 business and technology leaders in 71 countries, surveyed between May and July 2026. It is the 29th edition of the study, previously known as the Global State of Information Security Survey.


The central tension is straightforward. More than four-fifths of security and finance leaders expect cyber budgets to increase over the next year, and AI is a leading reason. At the same time, continuity planning, data controls, quantum readiness, and trust in autonomous defence tools are lagging the pace of adoption.


Spending returns, with AI as the driver


After several years of relatively flat cyber budgets, investment is back. Eighty-four percent of security and finance leaders expect their cyber budget to rise, six percentage points higher than last year and up from 78 percent. Fifty-eight percent of security leaders rank AI among their top cyber budget priorities.


Where the money is going is more specific than a general AI rush. Security leaders rank data protection and trust as the highest spending priority (51 percent), followed by defence against AI-enabled attacks (46 percent) and securing AI systems and autonomous agents (45 percent). On the defensive use of AI, threat detection and alerting leads (50 percent), ahead of fraud detection (43 percent) and phishing detection and response (42 percent).


PwC’s framing is that the goal of cybersecurity is no longer only protection. It is giving the business confidence to move. The survey argues that organisations which embed cyber resilience in C-suite decisions will be better placed to innovate while still operating through disruption.


Attacks on AI are the preparedness gap




When security leaders are asked which threats they are least prepared to address, attacks targeting AI systems come first. Half put them among their top gaps, ahead of cloud-related threats (40 percent), third-party breaches (34 percent), and ransomware (33 percent). Software supply-chain compromise also sits at 33 percent.


The AI-enabled attack types they feel least ready for are compromise by autonomous botnets (53 percent), adversarial attacks (52 percent), and data poisoning (52 percent). The report treats frontier models as a force that changes both sides of the equation: the same capabilities that speed analysis and code generation can be used to find and exploit weaknesses at machine speed.


FBI Cyber Division assistant director Brett Leatherman, quoted in the report, puts the shift plainly: AI is changing the speed and scale of the threat, and defenders will have to use it responsibly to disrupt adversaries. Matt Rowe, chief security officer at Lloyds Banking Group, is blunter: success in this era means being able to defend at machine speed.


The trust gap on autonomous agents


Leaders are willing to use AI in defence. They are much less willing to let it act alone. Only 22 percent would authorise fully autonomous execution by AI agents without human approval. Thirty-eight percent would allow partial autonomy, and 36 percent prefer human-led work with AI in support.


The tasks they are most comfortable automating are still bounded: threat-intelligence enrichment (49 percent), quarantine or deletion of phishing email (47 percent), and malware removal or system remediation (46 percent). The barriers are familiar. Reliability and maturity of the technology is the top obstacle (55 percent), followed by accountability and explainability (46 percent). Nearly half of CISOs (44 percent) also cite workforce skills in AI oversight and governance.


Phil Venables, partner at Ballistic Ventures, captures the trade-off in the report: AI is both a new class of security risk and one of the biggest defensive opportunities in decades, and the hard part is building trust and control at the same speed as adoption.


Foundations are not keeping up with the budget


Higher spend is not yet showing up in the basics. Only 39 percent of security, risk, and operations leaders have a fully formalised and integrated operational continuity plan that specifically addresses cyber threats.



Data protection looks thinner still. Organisations have fully implemented only three of seven key data-risk measures on average. Just 5 percent have implemented all of them, down from 7 percent a year earlier. Data classification policies are fully in place at 49 percent of organisations, and data-loss prevention across key egress channels at 48 percent. Only 5 percent say they have implemented all eight measures surveyed for turning cyber-risk intelligence into context that leaders can act on.

Quantum is still a secondary concern for most, ranking seventh among threats organisations feel least prepared for, though fourth among CISOs. Only 21 percent are implementing quantum-resistant security measures. Forty-nine percent have not started.


No settled owner for AI risk


Governance structures exist on paper more often than they are embedded in decisions. About nine in ten leaders say practices such as board oversight, executive accountability, and enterprise-risk integration are in place. Far fewer strongly agree that cyber risk is a standing board agenda item (47 percent) or a standing item at executive leadership meetings (45 percent).


Ownership of AI governance is split. One-third of CEOs and security and risk leaders say their organisation has created dedicated AI roles, such as a chief AI officer or an AI board. Asked where accountability actually sits, 29 percent point to the CIO, CTO, or technology function, 26 percent to a dedicated AI leader or function, and 17 percent to the CISO or cyber team. About 11 percent say accountability is unclear or shared across roles.


Geopolitics, concentration risk, and the talent squeeze


Geopolitical pressure is already changing operating models. Half of respondents are adjusting vendor, third-party, and supply-chain risk management. Forty-nine percent are changing cyber insurance, incident response, or crisis management, and 47 percent are expanding threat intelligence, geopolitical monitoring, or government collaboration.


Concentration risk is being treated as an operational problem, not only a procurement one. Fifty-four percent of security and risk leaders are adopting multi-cloud or hybrid cloud strategies, 47 percent are strengthening regional data and technology redundancy, and 37 percent are localising infrastructure in specific jurisdictions.


Talent is the other constraint. Retention priorities are growth opportunities (59 percent), a strong cyber culture (53 percent), and AI-enabled tools and training (53 percent). Managed services are filling the gap, especially where specialist AI and cloud skills are scarce. Security leaders rank AI (53 percent), cloud security (49 percent), data protection and trust (42 percent), and threat management (39 percent) as the top areas for managed services over the coming year.


What the C-suite playbook asks leaders to do


The accompanying playbook turns the findings into six lines of action rather than a technology shopping list:

  • Strengthen cyber governance so risk decisions have a clear owner and a place on the board and executive agenda.

  • Protect critical operations, including formal continuity plans that treat cyber disruption as a business event.

  • Secure data, AI pipelines, and emerging technology, starting with classification, loss prevention, and control of training data.

  • Manage ecosystem and concentration risk across vendors, cloud, and the software supply chain.

  • Use trusted technology and data to create enterprise value, not only to reduce loss.

  • Build a model for using agents to defend against agent-enabled attacks, with human oversight where reliability and accountability are not yet proven.


The survey’s sample is weighted toward larger organisations: 36 percent of executives come from companies with $5 billion or more in revenue. Respondents span financial services (21 percent), technology, media and telecom (20 percent), industrial manufacturing and automotive (19 percent), retail and consumer (16 percent), healthcare (10 percent), energy and resources (10 percent), and government (3 percent). Western Europe accounts for 32 percent of the sample, North America 26 percent, and Asia Pacific 18 percent.


The picture that emerges is not a collapse of cyber investment. It is a mismatch of speed. Budgets are moving. Autonomy, ownership, data foundations, and continuity planning are not moving at the same rate as the systems they are meant to protect.

Comments


connexion_panel_edited.jpg
CXO_8-in-1.png
subscribe_button.png

​

Disclaimer: The "Industry Events" section in Inno-Thought website serves as a platform for event organizers and vendors to list their events for free. Ho Hon Asia reserves the right, at its discretion, to not proceed with publication/posting at any time or to remove the content following publication.

 

By providing your email address and submitting this form, you agree to receive updates about the event listed, including schedule changes, reminders, and important information.

 

The event information contained in the listing above is for reference only. While we have made every attempt to ensure that the info has been obtained from reliable sources, we are not responsible for any errors or omissions, or for the results obtained from the use of this info. In no event will Ho Hon Asia Limited, its related partnerships or corporations, or the partners, agents or employees thereof be liable to you or anyone else for any decision made or action taken in reliance on the information in this site or for any consequential, special or similar damages, even if advised of the possibility of such damages.

 

Information subject to change; check official sources. The Organisers reserve the right to modify the Event program, schedule, speakers, and activities without prior notice.

 

Also, the event organizers reserve the right to accept or reject any registration application at its sole discretion, without providing reasons or explanation. Submission of a registration does not guarantee participation in the event.

​​

2026 @ Inno-Thought and its affiliates. All rights reserved.

bottom of page