AI’s role in defending against cyber threats has become impossible to ignore.
Organisations and cybersecurity providers alike are scrambling to incorporate AI to bolster defenses against ever-evolving threats. However, while AI’s potential is undeniable, its implementation comes with complexities and risks that demand careful consideration.
A new report from Sophos, Beyond the Hype: The business reality for AI in cybersecurity dives into the current landscape of AI in cybersecurity, focusing on genAI and its implications, based on insights from a survey of 400 IT and cybersecurity leaders from small to mid-sized organisations.
The widespread adoption of AI in cybersecurity is clear: 98% of surveyed organisations already use AI in some capacity. Among these, 73% utilise solutions powered by deep learning (DL) models, while 65% rely on genAI capabilities.
Additionally, 34% deploy in-house genAI solutions to enhance their defenses. AI’s universal presence is further reflected in purchasing decisions – 99% of organisations prioritise AI capabilities when selecting cybersecurity platforms. For 57%, these capabilities are deemed essential or extremely important, while 41% consider them important.
This ubiquity underscores the central role AI plays in modern cyber defense strategies. As organisations continue to digitise their operations, the demand for AI-driven solutions is poised to grow even further.
The Expectations and Reality of GenAI
Generative AI, which assimilates inputs to create new outputs, has captured significant attention for its potential in cybersecurity. Organisations expect the technology to deliver a range of benefits, from improving threat protection to enhancing return on investment (ROI). The survey revealed the top desired benefits of genAI in cybersecurity tools:
- Improved protection from cyber threats (20%)
- Improved ROI (20%)
- Increased IT analyst efficiency and impact (17%)
- Confidence in keeping up with cybersecurity innovations (15%)
- Greater peace of mind regarding defenses (14%)
- Reduced employee burnout (14%)
Interestingly, while operational and financial benefits top the list, the potential for genAI to alleviate employee burnout ranks lowest. This suggests that organisations may undervalue AI’s ability to support cybersecurity teams. With staff shortages and high attrition rates in the industry, reducing burnout and improving retention are areas where genAI could arguably make a significant impact.
The Risks of AI in Cybersecurity
Despite its advantages, AI is not without risks. The survey identified three primary areas of concern: defense risks, financial risks, and operational risks.
Defense Risks: Poor Quality and Implementation
AI’s effectiveness depends heavily on the quality of its models and their implementation.
Poorly developed or implemented AI can introduce vulnerabilities, undermining an organisation’s defenses. Alarmingly, 89% of respondents expressed concerns about flaws in genAI capabilities harming their organisation, with 43% being extremely concerned.
To mitigate these risks, organisations evaluate the development processes behind genAI solutions, with 73% conducting full assessments and 27% performing partial reviews. However, transparency from vendors and AI expertise within organisations remain limited. This lack of visibility often leaves organisations unaware of potential flaws – a significant blind spot.
Financial Risks: ROI Challenges
While improved ROI is a key motivator for adopting genAI, it also poses financial risks.
Developing and maintaining high-quality genAI capabilities is expensive, and 80% of respondents expect these costs to significantly increase cybersecurity product prices. Despite this, 87% are confident that genAI savings will offset its costs. Confidence varies by organisation size, with larger businesses ($500M+ revenue) 48% more likely to believe in positive ROI than smaller ones (<$10M revenue).
However, quantifying genAI costs remains a challenge. Three-quarters of respondents (75%) agreed that these costs are hard to measure. Larger organisations with more complex infrastructures reported greater difficulty in cost measurement, emphasising the need for improved reporting and transparency.
Operational Risks: Over-Reliance on AI
The pervasive nature of AI can lead to over-reliance, where organisations assume AI is infallible. This reliance raises concerns about accountability and workforce impact:
- 84% of respondents worry about AI-driven pressure to reduce cybersecurity headcount (42% extremely concerned).
- 87% are concerned about a lack of accountability resulting from AI’s use (37% extremely concerned).
Recommended reading
- Cybersecurity in 2024 | The High Cost of Innovation
- IT and Security Leaders Admit Hardware Cybersecurity Gap
- Comment | Get Ready For New Cybersecurity Legislation on Connected Devices
Recommendations for Safe AI Adoption
To maximise the benefits of AI while mitigating risks, the report states that organisations should adopt a thoughtful and informed approach. The following recommendations provide a starting point:
1. Ask Vendors the Right Questions
Transparency is key when evaluating AI capabilities. Organisations should ask vendors about:
- Training data: What is the quality, quantity, and source of the data? High-quality inputs lead to better outputs.
- Development team expertise: Do they have sufficient knowledge of AI and cybersecurity threats?
- Engineering and rollout processes: What controls and checks are in place during development and deployment?
2. Apply Business Rigor to AI Investments
AI investments should be aligned with clear business goals. Organisations should:
- Set specific, measurable outcomes.
- Quantify the expected benefits of AI.
- Prioritise investments based on metrics like cost savings, risk reduction, and staff retention.
- Regularly measure performance and adjust strategies as needed.
3. View AI Through a Human-First Lens
AI should support human teams rather than replace them. Organisations should:
- Maintain perspective, recognising AI as one tool in a broader cybersecurity strategy.
- Use AI to handle repetitive tasks, allowing analysts to focus on higher-value activities.
- Emphasise that ultimate accountability lies with human professionals.





