Australian organisations are rapidly increasing their use of artificial intelligence in cybersecurity, but new research suggests many remain poorly prepared to respond when AI-related security incidents occur.
Just four percent of Australian organisations regularly run exercises testing their response to AI-related cyber incidents, according to ISACA’s 2026 State of Cybersecurity report. Almost one-third, or 31 percent, have conducted no AI-related incident response exercises at all.
The findings raise concerns about a widening gap between AI adoption and organisational preparedness as businesses increasingly rely on the technology to detect threats, automate security processes and support cyber operations.
Globally, 41 percent of cybersecurity professionals surveyed said their organisations now use AI to automate threat detection and response, up from 32 percent in 2025. Another 40 percent use AI for routine security tasks, compared with 28 percent a year earlier.
Cybersecurity professionals are also becoming more directly involved in AI deployment. More than half, or 51 percent, are now involved in developing, onboarding or implementing AI solutions, up from 40% in 2025 and 29% in 2024.
The 2026 State of Cybersecurity report, now in its twelfth year, is based on responses from 1,888 cybersecurity professionals worldwide.
Yet 48% either don’t know whether their organisation has established AI incident playbooks or say their organisation does not have them.
Jamie Norton, Vice Chair of the ISACA Board, said the findings highlight the need for organisations to ensure AI adoption and implementation is matched by active preparation for AI-related incidents.
“AI is changing both how organisations defend themselves and the risks they need to defend against,” said Mr Norton,” Norton said.
“While organisations are rapidly building AI into their operations, very few are regularly putting their response to an AI-related incident to the test.”
“An incident is not the time to discover that responsibilities are unclear or that your response plan doesn’t account for AI. Organisations need to practise these scenarios, understand where the gaps are and ensure their people know how to respond.” he said.
The most common AI-related incidents covered in organisations’ response exercises include sensitive data exposure through AI systems (24 percent), AI-enabled phishing, fraud or social engineering (23 percent), and misuse of generative AI by employees or insiders (21 percent).
Workforce pressures remain entrenched
More than two-thirds (69 percent) of cybersecurity professionals in Australia say their role is more stressful today than it was five years ago, while 58 percent say their teams are understaffed.
However, Australian organisations are taking some steps to support their cyber workforce. Seventy-four percent of Australian respondents say their employer offers flexible work hours, compared with 53 percent globally.
Retention also remains a challenge, with 55 percent of global respondents reporting difficulties retaining qualified cybersecurity professionals. High work stress is now the leading reason people
leave their roles, cited by 52 percent, up from 47 percent in 2025, followed by limited promotion and development opportunities (47 percent).
The research also highlights the continued importance of skills beyond technical expertise.
Globally, 57 percent identify soft skills as the largest skills gap among cybersecurity professionals, with critical thinking (59 percent), communication (57 percent) and problem-solving (53 percent) among the most important capabilities employers are seeking.
Mr Norton said the persistence of workforce pressures shows organisations cannot rely on technology alone to address cyber risk.
“AI and automation can help cyber teams work more efficiently, but they don’t solve the workforce challenge. Cybersecurity remains fundamentally dependent on skilled people who can think critically, communicate risk and make good decisions under pressure,” Mr Norton said.
“Organisations need to look at how they attract people into the profession, how they develop them and, importantly, how they create careers that people want to stay in.”
Fewer report rising attacks, but complexity intensifies
The research also points to a changing threat environment. Globally, 35 percent of organisations say they are experiencing an increase in cybersecurity attacks compared with a year ago. In Australia the figure is lower at 24 percent.
However, lower reported growth in attack volume does not necessarily mean the pressure on cyber teams is easing.
Among cybersecurity professionals globally who say their role has become more stressful, 71 percent point to the increasing complexity of the threat landscape as the leading reason, up from 63 percent in 2025.
The pressure is even greater in Australia, where 78 percent cite increasing threat complexity as a driver of stress.
Among organisations that reported being compromised, social engineering was the most common attack type (45 percent), followed by vulnerabilities (39 percent) and remote access (24 percent).
Almost half (45 percent) of cybersecurity professionals globally expect a cyberattack on their organisation in the next year. Yet only 42 percent are completely or very confident in their cybersecurity team’s ability to detect and respond to cyber threats.
Investment and governance
There are positive signs in cyber governance. Three-quarters (77 percent) of organisations report having a Chief Information Security Officer, 77 percent say their cybersecurity strategy is aligned with organisational objectives and 56 percent believe their board adequately prioritises cybersecurity.
“While there are some encouraging signs around governance, the pressure on cyber teams hasn’t gone away,” Mr Norton said.
“Organisations need to make sure their investment keeps up with the risks they’re asking their people to manage. That means having the right technology in place, but also investing in the people, skills and preparedness needed to respond when something goes wrong.” he said.
Despite these pressures, 55 percent of respondents globally believe their cybersecurity budget is underfunded. Almost half (47 percent) expect budgets to increase over the next year, up from 41 percent in 2025.

