ISACA’s survey report, sponsored by Wolters Kluwer Teammate, gathered responses from more than 1,800 cyber security professionals across the globe, exploring trends in cyber security hiring, staffing and budgets; cyber risk and threats; cyber security operations; and the role of AI in cyber security work.
AI incident response planning lags, even as AI transforms cyber security roles
This 12th annual survey also found that 64 percent of enterprises have not conducted any AI-related incident response exercises—which cover AI-related incidents such as sensitive data exposure through AI systems (24 percent), AI-enabled phishing, fraud or social engineering (23 percent), and misuse of generative AI by employees or insiders (21 percent). Seventeen percent say that AI incident response is included in broader cyber incident response exercises and 16 percent plan to conduct exercises in the future.
The gaps in planning also extend to AI incident playbooks—48 percent of respondents either don’t know whether their organisation has established them or say their organisation does not have them.
This comes as more cyber security professionals are using AI in their everyday work—only 13 percent do not use AI in their security operations. Among those who leverage AI on the job, top uses include automating threat detection/response (41 percent, up from 32 percent in 2025), automating routine security tasks (40 percent, up from 28 percent last year), and endpoint security (33 percent).
Increasingly, AI is also impacting the skills required in cyber security roles. Forty-five percent of respondents report that LLM Secops is a skill gap they see among cybersecurity professionals, a 12-point increase from 2025 and a 21-point increase from 2024.
Cyber security professionals are also now even more hands-on with AI implementation and governance at their organisations, with more than half (51 percent) now involved in developing, onboarding or implementing AI solutions, up from 40 percent in 2025 and 29 percent in 2024. Additionally, 56 percent of respondents say that they or someone from their team were involved in the development of a policy governing the use of AI in their organisation.
“AI is quickly becoming embedded in cyber security operations, but this research shows that many organisations have not yet matched that adoption with the response planning and workforce readiness required to manage AI-related risk,” says Jon Brandt, ISACA senior director, professional practices and innovation. “As cyber security professionals take on a larger role in implementing and governing AI, enterprises need to prioritise AI-specific incident exercises, clear playbooks and upskilling in areas such as LLM SecOps to help their teams use AI securely and effectively.”


















