Almost two in five UK and European IT and cybersecurity professionals are reporting more cybersecurity attacks than this time last year, with organisations struggling to keep pace with the pervasive nature of new cyber threats, according to new ISACA research.
The tech association’s latest State of Cyber report found that 39% of IT professionals are suffering from a rising barrage of cyber-attacks, leaving confidence in organisational readiness at a low ebb, with fewer than two in five firms (38%) sure of their ability to detect and respond effectively.
Yet as attacks continue to increase in scale and scope, the pressure is growing, with 65% of professionals identifying the complexity of the threat landscape as a major stress factor, one that incremental improvements to staffing and budgets cannot stave off.
The ISACA study, which polled more than 700 business and IT pros across Europe, found that while some progress has been made, the pace is not fast enough to ease the demands placed on cyber professionals.
Over half (58%) of those surveyed report that their organisation remains understaffed, only a modest improvement of three points compared to last year. Budgets tell a similar story of slow progress, with 54% of professionals saying their firm is underfunded, only a slight improvement from 58% in 2024.
Even if organisations are beginning to prioritise cybersecurity, the study reveals that progress is lagging behind the demands of the threat landscape, leaving cyber professionals on the front line with a lack of resources, and feeling the pressure.
More than two-thirds (68%) say their job is more stressful now than it was five years ago, a figure which remains unchanged from last year, but firms are failing to give professionals the support they need.
Despite over half (54%) reporting unrealistic expectations or excessive workloads and 48% claiming a poor work-life balance, ISACA found that more than one in five organisations have still taken no action to address or prevent employee burnout.
The root cause of this pressure is a crippling lack of talent. Half of organisations (52%) are struggling to find and retain qualified cybersecurity professionals, with entry-level roles particularly difficult to fill – though 19% have open positions that do not require experience, a degree or credentials, 45% of firms said it still takes three to six months to hire at this level.
Recommended reading
- Firms Embracing AI Without Clear Rules, ISACA Warns
- Cyber Teams Left Out of AI Implementation
- 67% of Healthcare Organisations Hit by Ransomware In the Past Year
To make matters worse, cybersecurity and IT teams are being forced to take on the bulk of AI governance and implementation, adding more weight to their workloads.
More than half of European professionals (51%) say they have helped develop their organisation’s AI governance framework, up from 36% last year, while 46% are now directly involved in AI implementation (up from 27%).
“While organisations are starting to acknowledge the problem and take steps to address long-standing issues in budgets and staffing, the pace of change is still far too slow,” said Chris Dimitriadis, chief global strategy officer at ISACA.
“To build resilience and keep pace with the evolving threat landscape, we must widen the pathways into cybersecurity. But recruitment is only the start; continuous training and upskilling are critical. That is how we move from slow, incremental change to real progress, reducing stress and building long-term protection.”





