AI is expanding the cybersecurity challenge faster than budgets and security teams can absorb.
Our latest global survey of approximately 300 cybersecurity leaders shows why. Cyber spending continues strong growth, with over 80% of respondents continuing to increase budgets into 2027. Yet that growth is being stretched across a much larger mandate. Security leaders must continue defending the traditional enterprise while also securing AI systems, responding to AI-enabled threats, and evaluating a flood of new AI-powered security tools.
The Stakes Are Rising for Cybersecurity Leaders
AI is expanding what organizations need to protect. Chief information security officers (CISOs) still must secure networks, endpoints, cloud environments, applications, data, identities, and third-party ecosystems. Now, they also need controls for models, agents, copilots, prompts, training data, synthetic data, AI-generated code, and non-human identities. Most organizations are still early in this transition.
At the same time, AI is changing the economics of attack. Although the possibility of AI agents being used to crack complex cybersecurity defenses has been a concern for several years, the recent release of several frontier AI models made that prospect a reality. These models can now help identify and exploit software vulnerabilities and with a speed, scale, and level of autonomy that would have been difficult to imagine only a few years ago. One identified thousands of high-severity vulnerabilities across major operating systems and browsers, including flaws that had survived years of human review and automated testing.
This is the new reality for CISOs. Budgets are increasing, but complexity is increasing faster. Incumbent vendors are asking customers to pay more for AI-enabled features. AI-native startups are challenging established categories. New vendors are emerging to secure AI-specific risks that barely existed a few years ago.
The result is a more selective cybersecurity market. Companies are still investing to secure AI systems, counter AI-enabled threats, and adopt AI-powered security tools. But they are also under pressure to stretch budgets, reduce vendor complexity, and separate real innovation from AI-branded noise.
Cyber spending continues to rise, but some categories are more investable than others.
Cybersecurity remains one of the most resilient areas of enterprise technology spending. Overall cyber spending grew by 12% in 2025, well above the expected 7%, and companies are still increasing their budgets, in large part because they need to secure a growing portfolio of AI assets and systems. Most CISOs expect AI-driven budget increases to continue for another one to two years before spending normalizes.
The specific security product categories of cloud, data, and threat intelligence are the highest priorities, with more than half of CISOs saying they plan to increase their spend in these areas.
Most companies have adopted minimal AI-specific security controls.
Despite the growing importance of AI to businesses and increasing cyber spending, companies still have gaps in their coverage as the protection estate expands to include AI systems and agents. Only 41% of respondents have formal AI governance policies in place, and only 23% have applied monitoring or logging to agents. Less than 20% have adopted shadow AI monitoring, prompt injection detection, or non-human identity governance.
Yet our data shows that these measures are well-correlated to better cybersecurity. CISOs that have higher adoption of these controls were far less likely to report significant impact from AI vulnerabilities being exploited, data leaked to AI tools, or shadow AI use among employees.
AI-enabled threats were reported by 89% of companies in the last year.
Nearly nine in ten companies reported AI-enabled attacks in the past 12 months, including 35% that experienced significant financial or operational impact. The average company in our survey reported three significant breaches and 25 sensitive data incidents in the past 12 months. With AI models growing in capability and increasing availability of powerful open-source models, we expect this trend to continue.
Frontier AI labs and cyber platform incumbents are winning the tools battle for AI security.
CISOs prefer frontier AI labs for AI-embedded cyber solutions, followed closely by cyber platform incumbents like CrowdStrike and Microsoft. Hyperscalers and startups are lagging far behind, often winning contracts due to ease of integration or niche security domains.
Platform consolidation remains a significant trend.
Consolidation is accelerating, and most CISOs have already consolidated their vendors in 18 of the 24 product categories we track. More mature organizations tend to consolidate to reduce complexity, while less mature ones do it primarily to save on cost. Standalone category leaders may still win, but for vendors, the middle ground is a dangerous place to be. Buyers have a clear preference for fewer vendors, and mid-tier players may not be able to differentiate their offerings enough to justify a contract.
Bottom-line Implications
For CISOs, our data underscore how rapidly the cybersecurity environment is changing, with AI simultaneously creating new vulnerabilities, enabling new threats, and powering new cybersecurity tools. Among our respondents, no one has truly solved the problem and everyone feels vulnerable. For that reason, it’s critical to continue investing in cybersecurity solutions to protect AI assets and systems, and embedding AI-enabled offerings in the security stack to counter growing AI risks and vulnerabilities. Companies may scale back spending in other areas in order to reallocate resources to the solutions that matter most.
For cybersecurity vendors, differentiation is key. Virtually all vendors are investing heavily in AI-powered solutions—and customers will pay more for security tools that are truly effective. But many companies overpromise on offerings that don’t truly leverage AI and don’t deliver better outcomes.
For investors, our data shows that AI is not replacing the cybersecurity market—it is accelerating it and fueling more demand for security incumbents and startups. This creates growing opportunities, provided investors screen for companies that offer true differentiation rather than me-too products with superficial AI functionality.
The authors wish to thank Ishani Jain and Hannah Kresock for their contributions to this article.