Site navigation

Nine in 10 UK Security Teams Now Prioritise Agentic AI

Graham Turner

,

Agentic AI cybersecurity
A new Ivanti report highlights a widening cybersecurity readiness deficit, despite growing confidence in AI-powered defences.

More than nine in 10 UK security teams now view adopting agentic AI as a priority, according to new research from enterprise IT and security software firm Ivanti, as organisations look to close a widening gap between rising cyber threats and their ability to defend against them.

Ivanti’s 2026 State of Cybersecurity Report: Bridging the Divide draws on insights from more than 1,200 cybersecurity professionals worldwide and points to what the company describes as a growing “Cybersecurity Readiness Deficit”.

The findings highlight a rapidly widening divide between escalating cyber threats and organisations’ preparedness, even as AI reshapes cybersecurity for both defenders and attackers.

Is the tide turning on weaponsied AI?

The report suggests security professionals believe they are beginning to gain the upper hand. Respondents were 2.7 times more likely to say defenders use AI as effectively as threat actors, if not more effectively, with that confidence rising to 7.3 times in favour of defenders over the next 24 months.

Despite this optimism, Ivanti’s research indicates that operationalising AI and automation across cybersecurity remains limited.

While 93% of UK respondents said automation reduces their team’s mean time to respond, adoption across key security functions varies. Some 56% of security teams currently use AI for cloud security policy enforcement, 47% for incident response workflows, 45% for threat intelligence correlation, and 45% for vulnerability response and remediation.

Promise of agentic AI growing, but work to be done

Agentic AI has yet to earn universal trust. Even so, 91% of security professionals said integrating agentic AI is a priority for their teams, and 79% reported at least some comfort with allowing autonomous AI systems to act without human oversight. Ivanti said this reflects growing, albeit cautious, confidence in automated cybersecurity defences.

Daniel Spicer, chief security officer at Ivanti, said: “Although defenders are optimistic about the promise of AI in cybersecurity, Ivanti’s findings also show companies are falling further behind in terms of how well prepared they are to defend against a variety of threats.

“This is what I call the ‘Cybersecurity Readiness Deficit’ — a persistent, year-over-year widening imbalance in an organizations’ ability to defend their data, people and networks against the evolving threat landscape. This challenge is intensified by the accelerating pace of technological change, particularly as organisations advance their SaaS transformation initiatives and the speed at which new technologies are adopted.”

He added: “Security leaders understand that time and people are their most valuable assets. Currently, AI tools are effective at automatically handling cyber hygiene tasks that can bog down IT teams and helping close some of the most common gaps in an organizations’ defense.”

Organisational friction continues to be a pain point

The report also highlights a growing rift between IT and security teams, with 39% of security professionals saying IT does not respond urgently to cybersecurity concerns and 31% believing IT lacks an understanding of their organisation’s risk tolerance.

Ivanti said this disconnect is particularly damaging for exposure management, which depends on close collaboration between security and IT to align technical risk with business expectations.


Recommended


Organisations are also taking a fragmented approach to measuring cybersecurity performance. Just 60% of security professionals use business impact analysis to inform risk prioritisation, while 59% rely on exposure scores or risk-based indices. Many continue to track process-driven metrics such as mean time to remediate, used by 50%, or percentage of exposures remediated, cited by 46%.

Ivanti noted in the report that while these measures can appear positive in isolation, they offer limited insight into whether remediation efforts genuinely improve risk posture.

Deepfakes and synthetic content on the rise

Deepfake-enabled attacks are emerging as a significant threat.

The survey found that 76% of UK organisations have already been targeted by deepfake attacks, with half experiencing sophisticated, personalised phishing emails powered by deepfake technology.

Almost half of respondents, 48%, said synthetic digital content represents a high or critical threat, yet only 40% felt very prepared. Confidence at executive level was also low, with just 32% of UK security professionals believing their CEOs could reliably identify a deepfake.

Graham Turner

Sub Editor

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences