Cybersecurity AI use jumps, but maturity and governance lag
Security teams are embracing AI to keep pace with attackers, but gaps in maturity, detection, and governance remain.
Key takeaways
- Cybersecurity teams are adopting AI faster as attackers use it to scale and speed up attacks.
- AI maturity remains low, with only 27% of survey respondents describing their implementation as mature.
- Governance, detection, and training gaps are limiting how effectively organizations can use AI in cybersecurity.
- Security teams need practical controls, faster vulnerability remediation, and human oversight to reduce AI-related risk.
A global survey of 536 cybersecurity and IT practitioners finds cybersecurity teams are now more aggressively adopting artificial intelligence (AI) tools and platforms in the hopes of leveling a playing field that has generally been lopsided for as long as anyone can remember.
Conducted by the SANS Institute, the survey finds, for example, 61% of respondents now use AI to augment the capabilities of red teams that are trying to discover and remediate vulnerabilities before adversaries can exploit them.
Why AI maturity remains a cybersecurity challenge
However, only slightly more than a quarter (27%) describe their implementation of AI as mature, which suggests that in terms of AI capabilities many cybersecurity teams may be still far behind adversaries that are clearly using AI to launch more sophisticated attacks faster than ever. In fact, the survey finds more than three-quarters (78%) of respondents reported confirmed or suspected AI-enabled attacks in the past year, with nearly all (95%) believing threat actors are using AI.
How AI-enabled attacks are changing vulnerability risk
More troubling still, as more advanced AI models become available, cybercriminals will increasingly be able to discover and exploit vulnerabilities in a matter of hours. While access to the latest AI models from Anthropic and OpenAI is restricted, open-source AI models are rapidly catching up in terms of capability. As a result, it will not be long before every cybercriminal has access to an AI model that can be used to not only discover new vulnerabilities, but also chain together exploits for known vulnerabilities in a novel way.
That puts increased onus on cybersecurity teams to employ AI as quickly as possible to discover and remediate vulnerabilities faster than ever. Even with help from the Federal Government in the form of a Gold Eagle initiative to create a vulnerability coordination clearinghouse, the number of issues that will need to be tracked by cybersecurity teams will be overwhelming.
The challenge is that many of the workflows relied on today to remediate vulnerabilities were designed for a different era. Historically, an organization might not have deployed a patch to remediate a vulnerability for weeks while waiting to determine what impact that update might have on application availability. The assumption, of course, was that it might be months before cybercriminals could develop an exploit for the vulnerability that needed to be remediated. Now, however, as the rate at which exploits can be created exponentially increases, cybersecurity needs to dramatically accelerate the rate at which patches to software are applied.
Where AI governance and detection gaps remain
Unfortunately, AI is not a cybersecurity silver bullet. Nearly two-thirds of respondents (63%) report significant AI shortcomings in threat detection and response. Nearly half of practitioners identify behavioral detection as their most effective control, followed by user awareness training (45%) and human analyst review (39%).
On the plus side, nearly three-quarters of respondents (73%) said AI changed their team's training requirements. The issue now is taking that training beyond the classroom to thwart attacks that are now occurring faster than any human alone is going to be able to detect.
Rapporto sulle minacce via email 2026
Scopri come l'IA e il phishing come servizio stanno rimodellando il panorama delle minacce via email e come rimanere protetti.
Iscriviti al blog di Barracuda.
Iscriviti per ricevere i Threat Spotlight, commenti del settore e altro ancora.
Report sulle minacce globali di Managed XDR
Risultati chiave sulle tattiche adottate dagli attaccanti per colpire le organizzazioni e sui punti deboli della sicurezza che cercano di sfruttare