Just 4% of Australian organisations regularly test response to AI cyber incidents

0

Just four percent of Australian organisations regularly conduct exercises to test their response to AI-related cybersecurity incidents, according to new research from ISACA.

The 2026 State of Cybersecurity report, based on responses from 1,888 cybersecurity professionals globally, found that almost a third (31 percent) of organisations have conducted no AI-related incident response exercises.

The findings come as organisations expand the use of AI in cybersecurity operations. Globally, 41 percent of respondents said they use AI to automate threat detection and response, up from 32 percent in 2025, while 40 percent use it to automate routine security tasks, up from 28 percent.

The report suggests cybersecurity professionals are increasingly involved in AI initiatives, with 51 percent globally saying they are involved in developing, onboarding or implementing AI solutions, up from 40 percent in 2025 and 29 percent in 2024. However, 48 percent either do not know whether their organisation has established AI incident playbooks or say their organisation does not have them.

Jamie Norton, vice chair of the ISACA board, said the findings show organisations need to match AI adoption with preparation for AI-related incidents.

“AI is changing both how organisations defend themselves and the risks they need to defend against,” said Mr Norton. “While organisations are rapidly building AI into their operations, very few are regularly putting their response to an AI-related incident to the test.

“An incident is not the time to discover that responsibilities are unclear or that your response plan doesn’t account for AI. Organisations need to practise these scenarios, understand where the gaps are and ensure their people know how to respond.”

The most common AI-related incidents covered in organisations’ response exercises included sensitive data exposure through AI systems (24 percent), AI-enabled phishing, fraud or social engineering (23 percent), and misuse of generative AI by employees or insiders (21 percent).

Workforce pressures remain entrenched

In Australia, 69 percent of cybersecurity professionals said their role is more stressful today than it was five years ago, while 58 percent said their teams are understaffed.

ISACA’s research also found Australian organisations reported higher levels of flexible work arrangements than global respondents, with 74 percent of Australian participants saying their employer offers flexible work hours, compared with 53 percent globally.

Retention remained a challenge globally, with 55 percent reporting difficulty retaining qualified cybersecurity professionals. High work stress was the leading reason people leave their roles, cited by 52 percent of respondents, up from 47 percent in 2025. Limited promotion and development opportunities were cited by 47 percent.

The report also pointed to skills shortages beyond technical expertise. Globally, 57 percent identified soft skills as the largest skills gap among cybersecurity professionals, with critical thinking (59 percent), communication (57 percent) and problem-solving (53 percent) among the capabilities employers are seeking.

“AI and automation can help cyber teams work more efficiently, but they don’t solve the workforce challenge. Cybersecurity remains fundamentally dependent on skilled people who can think critically, communicate risk and make good decisions under pressure,” Mr Norton said.

“Organisations need to look at how they attract people into the profession, how they develop them and, importantly, how they create careers that people want to stay in.”

Fewer report rising attacks, but complexity intensifies

Globally, 35 percent of organisations said they are experiencing an increase in cybersecurity attacks compared with a year ago, while in Australia the figure was 24 percent.

However, the report suggested that lower reported growth in attack volume may not reduce the pressure on cyber teams. Among global respondents who said their role had become more stressful, 71 percent cited increasing complexity of the threat landscape as the leading reason, up from 63 percent in 2025. In Australia, 78 percent cited increasing threat complexity as a driver of stress.

Among organisations that reported being compromised, social engineering was the most common attack type (45 percent), followed by vulnerabilities (39 percent) and remote access (24 percent).

Almost half (45 percent) of cybersecurity professionals globally expected a cyberattack on their organisation in the next year, while only 42 percent said they were completely or very confident in their cybersecurity team’s ability to detect and respond to cyber threats.

Investment and governance

More than half (55 percent) of respondents globally said they believe their cybersecurity budget is underfunded. Almost half (47 percent) expected budgets to increase over the next year, up from 41 percent in 2025.

The report also found 77 percent of organisations said they have a chief information security officer, 77 percent said their cybersecurity strategy is aligned with organisational objectives, and 56 percent said they believe their board adequately prioritises cybersecurity.

“While there are some encouraging signs around governance, the pressure on cyber teams hasn’t gone away,” Mr Norton said. “Organisations need to make sure their investment keeps up with the risks they’re asking their people to manage. That means having the right technology in place, but also investing in the people, skills and preparedness needed to respond when something goes wrong.”

The complimentary 2026 State of Cybersecurity survey report was sponsored by Wolters Kluwer TeamMate.

You can read the full report here.

Share.