Site navigation

Report: Security Budgets Stagnate as AI Threats Multiply

Tom Quinn

,

CISO AI
CISOs are struggling to stay ahead of fast-evolving threats while patching fewer vulnerabilities and facing tighter budgets.

AI is fast becoming a major headache for security teams, with new research revealing that a surge in AI-powered threats is forcing CISOs to overhaul their risk models and reprioritise defences.

According to Team8’s latest CISO Village Survey, one in four CISOs has already faced a confirmed AI-driven attack, and dealing with this AI risk is at the top of security leaders’ priorities this year.

While deepfakes, voice cloning, and real-time impersonation remain the most visible threats, the report warns that the true scale of AI abuse is likely far worse. 

Many attacks now mimic human behaviour so convincingly that they can evade traditional defences, only being detectable through advanced metrics like time to exploitation and velocity indicators.

However, CISOs are even more concerned with getting internal threats under control, with securing AI agents (37%) and employees’ use of AI tools (36%) ranking as the most urgent concerns.

Worries are likely growing because 70% of enterprises already have AI agents in production, while another 23% are planning deployments next year, with more than two-thirds (67%) of these enterprises building their own AI agents in-house.

To try and plug every conceivable gap, some security leaders are scrutinising employee AI use. Despite pressure to adopt AI, nearly 50% of organisations are still restricting or allow-listing AI tools for workers. 

According to Team8, with shadow AI use on the rise and few governance systems in place, there’s a growing need to build stronger “allow-by-default” controls on employee use of AI tools.

Those security systems might prove trickier to build, however, with the report finding that only half (52%) of CISOs reported a budget increase this year, down from 70% in 2024.

Security budgets are stagnating, with more than double seeing no change this year from last (37% vs 15%) despite the threat landscape becoming more complex, with macroeconomic pressures like tariff policies, fiscal tightening, and a competitive talent market, forcing security leaders to do more with less.  


Recommended reading


This is having a knock-on effect, with vulnerability management proving a particularly significant struggle. Roughly 40% of CISOs said that more than two-fifths of critical vulnerabilities remain unpatched within SLA, with headcount shortages (62%), unavailable patches (32%) and downtime risk (30%) being the key roadblocks.

On a more positive note, Team8 found that a growing number of CISOs are embracing product security in a shift away from traditional security models.

Half (50%) of security leaders are now prioritising this new paradigm, with CISOs expanding away from AppSec and a focus on scanning code for bugs, to a broader model that embeds security across the full software lifecycle, from design to deployment, with 36% having already built a dedicated product security program, and 23% planning to do so by next year.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data