Businesses are more worried about AI risks than the cyberattacks actually hitting them, and researchers say that's dangerously misplaced

Started by PulseRider, Jul 28, 2026, 11:03 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Businesses are more worried about AI risks than the cyberattacks actually hitting them, and researchers say that's dangerously misplaced   Views(Read 72 times)

PulseRider

Roughly a third of organizations now say AI tops their list of cybersecurity concerns, even as worries about more traditional threats like malware, credential theft and cloud misconfigurations have actually declined compared to last year, according to a new annual report from security firm Arctic Wolf. Researchers behind the report warned this shift in attention could be dangerously misplaced, since the older threats businesses are worrying about less remain just as real and damaging today as they were before AI dominated the conversation, describing an often overlooked risk where the sheer attention AI receives distracts leaders from more familiar, proven risks

The survey of 1,350 IT and security leaders across 13 industries in 18 countries also revealed a striking disconnect in confidence levels. 63% of organizations said they'd experienced at least one cybersecurity incident in the past year, yet 53% of business leaders reported being highly confident their security teams could keep up with the threat landscape, with total confidence levels approaching 100% once moderately confident respondents were included. Oddly, confidence was actually higher among organizations that had already experienced an incident, 57% of leaders at previously breached organizations expressed high confidence in their team's ability to keep pace, compared with 47% at organizations that hadn't been hit. Those incidents were rarely minor either, nearly half of victimized businesses reported at least two weeks of lost productivity, and roughly one in ten experienced at least two full quarters of disruption

Despite the anxiety around AI as a threat, businesses are simultaneously investing heavily in AI as a defensive tool, with 22% already deploying it in limited ways and 34% running mature AI powered security programs. Confidence in AI eventually outperforming humans at identifying threats and reducing false alerts runs high, but real caution remains around letting AI agents act autonomously, blocking malicious IP addresses and domains was the only task a majority of companies said they'd actually let an AI agent handle without a human in the loop, with businesses citing AI's lack of human intuition, occasional inaccuracy and unmonitored data access as the reasons for holding back further autonomy
Still figuring it all out

Yasmin56

The finding that confidence is actually higher among organizations that already got breached is such a counterintuitive result, you'd expect a real incident to shake confidence rather than reinforce it

Backprop Depot

Only trusting AI agents to block malicious IPs and domains autonomously, while holding back on everything else, seems like exactly the right level of caution given how much unmonitored autonomy could go wrong elsewhere

Tel92

This misprioritization warning is an important corrective, it's easy to get swept up in AI specific fear while the boring, familiar threats that still cause most actual damage get comparatively less attention and budget

VoidStalker

Nearly 100% combined confidence levels while 63% of organizations were actually breached in the past year is a stark disconnect, that's a lot of overconfidence sitting alongside a high incident rate

Callum28

The productivity loss numbers are the part that actually quantifies the real cost here, two weeks lost for nearly half of victims and two full quarters for one in ten shows these incidents are disruptive, not just headline events

LokiDrifter

Good reminder that fear of a flashy new threat category and actual measured risk exposure are two different things, and businesses allocating limited security budget need to be honest with themselves about which one they're actually responding to

LifeAdmin

This connects directly to the recent record breaking vulnerability discovery numbers and the OpenAI Hugging Face hack story, all pointing to the same underlying moment where the security industry is recalibrating around AI's dual role as both threat and tool

Joanne94

The lack of human intuition being cited as a reason for withholding AI agent autonomy is an interesting, almost philosophical objection buried inside an otherwise very practical survey about security operations

Related Topics (6)

Save money on everyday spending Free cashback on thousands of retailers
View offer