Only 35% of cybersecurity professionals or teams are involved in the development of policy governing the use of AI technology in their enterprise, new ISACA research shows.
Further, nearly half (45%) report no involvement in the development, onboarding, or implementation of AI solutions, according to the recently released 2024 State of Cybersecurity survey report from ISACA.
In response to new questions asked by the annual study, sponsored by Adobe – which showcases the feedback of more than 1,800 cybersecurity professionals on topics related to the cybersecurity workforce and threat landscape – security teams noted their primary uses for AI.
These include automating threat detection/response (28%), endpoint security (27%), automating routine security tasks (24%), and fraud detection (13%).
“In light of cybersecurity staffing issues and increased stress among professionals in the face of a complex threat landscape, AI’s potential to automate and streamline certain tasks and lighten workloads is certainly worth exploring,” says Jon Brandt, ISACA director, professional practices and innovation.
“But cybersecurity leaders cannot singularly focus on AI’s role in security operations. It is imperative that the security function be involved in the development, onboarding and implementation of any AI solution within their enterprise – include existing products that later receive AI capabilities.”
Cybersecurity leaders are no less stressed from being left out of AI implementation.
Two thirds (66%) say their roles are more stressful, with 81% of respondents crediting this to an increasingly complex threat environment.
Recommended reading
- 600M Cyber-attacks Daily, Microsoft Report Reveals
- NCSC Issues Warning Over Iran Spear-Phishing Attacks
- 67% of Healthcare Organisations Hit by Ransomware In the Past Year
Further, over half (57%) say their cybersecurity teams are understaffed. This combination can be disastrous for organisations as cybersecurity professionals notoriously face burnout due to a constant influx on threats, which are only exacerbated by the introduction of new technologies.
Nearly two fifths (38%) of cybersecurity teams have said they’ve experienced an increase in cyber-attacks, the survey found, showing that if anything, threats are expanding.
Despite this increase in attacks, cybersecurity funding levels have dropped significantly this year, and its incremental year-on-year decline shows signs of a potential multiyear freefall.
About 44% of respondents think their budgets are somewhat underfunded. While 47% of respondents think budgets will increase, 13% think they will shrink, a figure that continues to grow year on year.





