AI has yet again emerged as the top cybersecurity priority for businesses in the coming year, with fresh research from PwC finding that only 6% of firms are confident they could withstand a cyber-attack.
The professional services giant has released its 2026 Global Digital Trust Insights report, which found that more than three-quarters (78%) of organisations plan to increase their cyber budgets over the next twelve months, with AI security investments their top concern (36%), ahead of cloud security (34%), network security (28%) and data protection (26%).
When looking at the AI capabilities organisations are prioritising, nearly half (48%) of security leaders are prioritising AI threat hunting capabilities, and more than one-third are prioritising other capabilities such as agentic AI (35%).
According to PwC, businesses are planning to deploy AI agents for a variety of use cases, including in cloud security, data protection and cyber defence and operations, highlighting a shift from reactive defence to proactive resilience.
Although AI is at the forefront of security leaders’ minds, the study also revealed a desire to prepare for next-generation threats, particularly when it comes to quantum readiness.
Almost a third (29%) of companies are piloting and testing their transition to post-quantum cryptography, with a further 22% already implementing quantum-resistant security measures.
However, half (49%) haven’t yet considered or started their moves to protect against future quantum threats, with PwC warning that those who delay may be exposing their sensitive data, authentication services and cryptographic systems.
The study, which polled over 3,800 business and tech leaders across more than seventy countries, found that widely acknowledged cyber skills gaps are impeding defence capabilities.
Half (50%) of firms, for example, said a lack of knowledge in the application of AI, or lack of relevant skills (41%), were the biggest internal challenges to implementing AI for cyber defence over the last year.
The cyber skills deficit runs deeper beyond AI, however, with 47% of leaders citing a lack of qualified personnel as a top challenge when securing operational technology and industrial internet of things (IIoT) systems.
Recommended reading
- Gartner: 40% of Enterprise Apps to Feature AI Agents by 2026
- NCSC Issues Quantum Security Roadmap For Businesses
- Firms Race to Adopt Post-Quantum Encryption As ‘Q-Day’ Fears Grow
PwC said this has left around half of security leaders thinking their organisation is not very capable of withstanding cyber-attacks, with only 6% very confident across all areas surveyed.
But while talent shortages weigh heavy, business are responding by prioritising areas such as AI and machine learning tools (53%), security automation tools (48%), cyber tool consolidation (47%) and upskilling or reskilling (47%).
“New and emerging technologies and a rapidly evolving and digitally interconnected global ecosystem and threat landscape have created a tipping point,” said Sean Joyce, global cybersecurity and privacy leader at PwC US.
“The organisations that will lead in the future are those investing in cyber not just to respond, but to anticipate.
“Organisations should ensure they are also investing in AI and cyber skills, prioritising the upskilling and re-skilling of their cyber teams in order to clearly and proactively map the cyber risks they face.”





