Skip to main content
CybersecurityIncident Response

AI Adoption Outpaces Incident Response Readiness

Empty conference room with long wooden table, chairs, and whiteboard, bathed in natural daylight.

71% of organizations have not run any AI incident response exercises.

71% of organizations have not rehearsed AI incident responses

ISACA's 2026 State of Cyber report found a stark gap between use and preparation: 71% of organizations have not run any AI incident response exercises. The report further shows that only 3% have "mature, formal runbooks for AI-specific incidents" and 30% have not begun to address their response at all. Exercises would typically cover scenarios such as sensitive data exposed through AI systems, AI-enabled phishing and fraud, social engineering, and misuse of generative AI by employees or insiders.

AI is being used to detect threats even as governance lags

Adoption of AI inside security teams is moving ahead of institutional readiness. The report states 37% of organizations now use AI to automate threat detection and response (an increase of eight percentage points from 2025), 35% use it for routine security tasks, and 29% for endpoint security. Security professionals are active in that rollout: 54% say they or their team helped develop, onboard, or implement AI solutions, and 60% have contributed to AI policies in their organization.

Yet ISACA warns that AI also strengthens attackers. The report quotes the organization saying AI allows attackers to operate "at the speed of intent," automating attacks that once took days or weeks — a capability that heightens the risk when formal response plans and runbooks are missing.

CMMI's AI Maturity Model and ISACA's governance call

ISACA's global chief strategy officer, Chris Dimitriadis, framed governance as the essential counterbalance to rapid adoption: "Organizations can effectively use AI for preventing and detecting cyber threats. However, its governance should be non-negotiable." The report points organizations to the CMMI's AI Maturity Model as a benchmark; ISACA owns the CMMI Institute. Dimitriadis added that governance must protect both employee use of AI and businesses from AI-generated threats, and he warned that budgets are often "sunk into crisis response" instead of workforce development and training.

European respondents report rising attacks and a strained workforce

Among European IT and cybersecurity professionals surveyed, 38% said their organization faced more cyber-attacks than a year earlier and 54% expect an attack within the next 12 months. Social engineering was the most commonly cited attack type at 46%, and ISACA said social engineering is increasingly supported by AI. The workforce consequences are tangible: 72% said their job is more stressful than five years ago, 56% said their teams are understaffed, and 55% said their teams are underfunded.

Respondents identified additional workforce challenges: 57% blamed unrealistic expectations and too much work, and 35% said staff were not sufficiently trained or skilled. A fifth of companies take no action on burnout; among those that do, 55% offer flexible hours and 46% encourage staff to take breaks and vacation.

What this means for security professionals, the C-suite, and employees

  • Security professionals: many are directly involved in AI deployments (54%) and policy work (60%), but the lack of exercises and runbooks means teams may be unprepared for AI-specific incidents such as automated social engineering or data exposure tied to generative systems.
  • The C-suite and budgets: ISACA's Dimitriadis argues that better funding and a "clear plan for improving cyber resilience should be a C-suite priority," noting that current spending patterns often favor crisis response over prevention and workforce training.
  • Employees and insiders: the report flags misuse of generative AI by employees as a scenario that incident exercises should cover; without governance and rehearsed responses, organizations may struggle to detect and contain insider-driven AI misuse.

The numbers are unambiguous: organizations are deploying AI into security functions even as formal, practiced responses to AI-enabled incidents remain rare. ISACA's recommendation — governance benchmarks such as the CMMI AI Maturity Model, investment in workforce skills, and a shift away from crisis-only spending — offers a concrete set of priorities. The practical question left on the table is whether organizations will treat runbooks and exercises as optional extras or as the non-negotiable infrastructure Dimitriadis describes.

Original story