Security leaders are conflicted, to say the least, about AI‘s role in the future of security, and their policies only match this misalignment, according to a new report from Bugcrowd.
Of the 209 respondents they company surveyed in their Inside the Mind of a CISO report across all populated continents, 89% believe there are more cybersecurity threats, and these threats are more serious.
Despite this, seven in ten (70%) plan to reduce their security team headcount over the next five years, citing the adoption of AI technologies. Nearly all (91%) of respondents believe that AI already outperforms security professionals or will in the future.
Nearly nine in ten (88%) also believe that security roles are becoming more difficult, and 69% believe most organisations are not proactive about security.
Further, over half (58%) believe that the risks associated with AI outweigh its potential, making the shift to AI amid increasing threats and complexity all the more confusing. 42% still do believe in the potential of AI, however, meaning that a consensus is far from being reached.
The wanton shift to AI, despite growing security concerns, could be a sign that CISOs are taking note of the major burnout facing cybersecurity professionals. Two thirds (66%) believe security professionals experience a higher rate of burnout, which is exacerbated by new threats and the skills gap.
Despite this, however, 68% of CISOs believe the cybersecurity skills gap is shrinking – though demand for cyber specialists is still markedly high. Are leaders hoping AI will replace this shortfall of talent?
With AI being cited as a solution to security woes, three-quarters (76%) of leaders also think that the AI threat landscape is evolving too rapidly to adequately secure.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- IT Leaders Split on Generative AI’s Role in Cybersecurity
- Cyber Leaders Reveal Compliance and Boardroom Struggles
This is despite many companies already using methods of AI for defense, such as crowdsourced testing (70%), pen testing (55%) and color teaming (36%).
The confluence of AI risks and AI reward knows no greater arena than in the world of cybersecurity, and CISOs are clearly still grappling with their many options among increasing threats and emerging technological advancements.





