As cybersecurity spending reaches new heights, it would be easy to think that business has never been better protected, but new data from Red Canary shows that security leaders are losing ground to threat actors’ evolving tactics and struggling to keep a lid on data breaches.
The cyber firm’s latest Security Operations Trends Report found that 80% of security leaders say they’re spending more than ever on cyber defence, yet the impact of attacks has continued to grow, with the average cyber incident now costing each organisation $3.7 million (£2.8m).
Polling more than 500 security decision-makers from around the world, including the UK, Red Canary found that SOC teams are under immense and growing pressure, driven by a widening attack surface.
Over just the last year, the study found that attack surfaces have swollen by 41%, leaving security teams scrambling as they try to maintain cloud environments, protect machine identities, and make safe the rollout of AI tech.
This has created a never-ending game of threat-actor whack-a-mole, with 83% of security execs saying that attackers no longer have to break in – they can log in using some forgotten access point and stay hidden. Almost three-quarters (73%) of security teams report that the spike in attack vectors has caused considerable detection delays.
The study also highlights how a spike in AI-derived attacks is reshaping defensive postures across the industry.
Red Canary found that while fears of AI unleashing a tidal wave of novel attacks are mostly dismissed, 85% of security leaders believe the real risk is being overwhelmed by the thousand missed threats that will get through if they don’t automate.
With threats coming from every direction, the majority (80%) of security leaders say that AI is essential to navigate the noise and zero in on real threats, with the top use cases for the tech being detection analytics (65%), intrusion detection (59%), and SIEM management (54%).
Recommended reading
- AI Threat Hunting and Quantum Top Cyber Agenda, Finds PwC
- Cyber Leaders Are Dreading AI-driven Cyber Threats for 2026
- AI Stoking Fears of Cyber Warfare
The study found a note of caution on the growing dependence of SOC teams on AI, with 75% of security leaders worrying that while the tech helps them work faster, it could reduce their ability to solve problems independently.
“AI works best as a force multiplier, augmenting human judgment rather than replacing it,” said Brian Beyer, co-founder of Red Canary.
“The organisations that lean into this shift now will not only ease the strain on security analysts, but put themselves in the best position to anticipate emerging threats and stay ahead of disruption in an increasingly unpredictable environment.”





