ISACA's 2026 State of Cyber report found that organizations are deploying AI security capabilities faster than they are preparing to handle AI-related incidents. Seventy-one percent have not conducted an AI incident-response exercise, and only 3% have mature formal runbooks for AI-specific incidents. The report highlights risks including sensitive-data exposure, AI-enabled phishing and fraud, scaled social engineering, and employee or insider misuse of generative AI.
European security teams are also facing a growing operational burden: 38% of surveyed IT and cyber professionals said their organizations had already sustained more attacks this year than during all of 2025, while 54% expect a material attack within the next 12 months. Social engineering remains the most common threat, with AI helping attackers automate and refine targeting; defenders are using AI for detection, response, endpoint protection, and task automation, but persistent understaffing, underfunding, skills gaps, and burnout are limiting resilience.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
An April 2026 ISSA survey found that nearly seven in ten cybersecurity workers believed their jobs had become more difficult over the preceding two years. Nearly half were considering leaving their jobs, with stress and poor work-life balance cited as major factors.
ISACA published its 2026 State of Cyber report, finding that AI adoption in security outpaced preparedness for AI-related incidents: 71% of organizations had not conducted AI incident-response exercises and only 3% had mature AI-specific incident runbooks. The report also documented rising attack volumes, AI-supported social engineering, and widespread understaffing, underfunding, skills gaps, and workforce stress among surveyed European cybersecurity professionals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourceitpro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.