Breaking
SecurityDeveloping Story

AI Response Drills Fall Short as Use Grows

ISACA finds that 71% of organizations have not rehearsed for an AI-related security incident, even as AI adoption accelerates.

··4 hours ago·6 min read
man standing in front of people sitting beside table with laptop computers
Photo by Campaign Creators on Unsplash

Security teams are rolling out artificial intelligence faster than they are preparing to handle what happens when it goes wrong. New research from ISACA suggests that most organizations have not rehearsed how they would respond to an AI-related security incident, leaving a gap between deployment and defensive readiness.

The finding lands as AI tools move deeper into detection, response, and everyday security work — a shift that expands both the capabilities and the potential failure modes defenders must manage.

Few Teams Have Tested AI Response

According to ISACA's 2026 State of Cyber report, 71% of organizations have not run any AI incident response exercises. Only 3% have mature, formal runbooks for AI-specific incidents, and 30% have not begun to address their response at all.

The exercises in question are not abstract tabletop drills. They would cover scenarios such as sensitive data exposed through AI systems, AI-enabled phishing, fraud and social engineering, and misuse of generative AI by employees or insiders.

That list spans accidental exposure and deliberate abuse, meaning the response playbook would need to handle both internal mistakes and external attacks. Yet the numbers show most organizations have not built or tested one.

Adoption Runs Ahead of Preparation

ISACA's data shows security teams are adopting AI at a steady clip. Some 37% of organizations use AI to automate threat detection and response, up eight percentage points on 2025. Another 35% use it for routine security tasks, and 29% for endpoint security.

Security professionals are not just passive users of these tools. More than half — 54% — say they or their team helped develop, onboard, or implement AI solutions. Even more, 60%, have contributed to AI policies within their organization.

That involvement suggests many security staff already have a seat at the table when AI tools are selected and governed. The gap, then, is not awareness but execution: the same teams helping deploy AI have largely not rehearsed what to do when it becomes part of an incident.

Attackers at the Speed of Intent

ISACA said AI allows attackers to operate "at the speed of intent," automating attacks that once took days or weeks. The phrase captures a shift in tempo: tasks that required manual effort and extended timelines can now be performed at machine speed, compressing the window defenders have to notice and react.

That compression makes preparation more important, not less. If an attack can unfold faster, a response plan that exists only on paper — or not at all — narrows the margin for containment.

ISACA's report places AI governance at the center of this problem. The organization argues that governance is needed both to keep employees' use of AI safe and to protect businesses from AI-generated threats.

"Organizations can effectively use AI for preventing and detecting cyber threats. However, its governance should be non-negotiable," said Chris Dimitriadis, ISACA's global chief strategy officer.

— Chris Dimitriadis, global chief strategy officer at ISACA.

Dimitriadis pointed to CMMI's AI Maturity Model as a benchmark for organizations working out where they stand. ISACA owns the CMMI Institute.

Attack Volume Rises Across Europe

Among the European IT and cybersecurity professionals surveyed for the 2026 report, 38% said their organization faced more cyber-attacks than a year earlier. A majority — 54% — expect an attack to happen within the next 12 months.

Social engineering was the most common attack cited, named by 46% of respondents. ISACA said the technique is increasingly supported by AI, which can help attackers craft more convincing messages at greater scale.

The combination of more attacks and more capable tooling puts pressure on teams that are already stretched. It also matters for AI incident response specifically: many AI-related incidents will not announce themselves as such, and may look at first like ordinary phishing or fraud.

Staffing and Funding Under Strain

The workforce data in the report points to a sector under stress. Some 72% of respondents said their job is more stressful than five years ago, with the more complex threat landscape cited as the main cause.

At the same time, 56% said their teams are understaffed and 55% underfunded. Beyond the threat landscape, 57% blamed unrealistic expectations and too much work, while 35% said staff were not sufficiently trained or skilled.

Burnout is widespread, and the response is uneven. A fifth of companies take no action on burnout at all. Among those that do act, 55% offer flexible hours and 46% encourage staff to take breaks and vacation.

  • 71% of organizations have not run any AI incident response exercises.
  • 3% have mature, formal runbooks for AI-specific incidents; 30% have not begun to address response at all.
  • 37% use AI to automate threat detection and response, up eight percentage points on 2025.
  • 54% of security professionals helped develop, onboard, or implement AI solutions; 60% contributed to AI policies.
  • 38% of European respondents said their organization faced more cyber-attacks than a year earlier; 54% expect one within the next 12 months.
  • 72% said their job is more stressful than five years ago; 56% said teams are understaffed and 55% underfunded.

Budgets Sunk Into Crisis Response

Dimitriadis argued that spending patterns are part of the problem, with budgets too often "sunk into crisis response" rather than directed toward the workforce and training needed to prevent attacks.

"Better funding and a clear plan for improving cyber resilience should be a C-suite priority," he added.

— Chris Dimitriadis, global chief strategy officer at ISACA.

The comment ties the report's readiness gap to decisions made above the security team. If funding is consumed by reacting to incidents, the argument goes, less is available for the preparation that might reduce how often those incidents occur or how far they spread.

Governance as the Missing Layer

ISACA's findings sketch a picture in which AI has become a normal part of security operations before the surrounding governance has caught up. The report found security professionals contributing to AI policies and implementations, but also found that formal, tested AI incident response remains rare.

Governance, in this framing, is not a separate compliance exercise. It is what connects an organization's AI use to a plan for when that use is abused, misconfigured, or caught up in an attack. Without it, the response to an AI incident may be improvised in the moment.

The scenarios ISACA lists — data exposure through AI systems, AI-enabled phishing and fraud, insider misuse of generative AI — each call for a different kind of preparation. A single generic incident plan is unlikely to cover all three well.

What the Gap Means for Defenders

For security leaders, the report's central tension is hard to miss: the same technology being adopted to speed up defense is also being used to speed up attack. The organizations furthest along in adoption are not necessarily the ones furthest along in readiness.

That leaves a practical question for any team using AI today. If an employee exposed sensitive data through an AI tool tomorrow, or if an AI-assisted phishing campaign slipped past existing filters, would the response be a rehearsed process or an improvised one? ISACA's data suggests that for most organizations, the answer is the latter.

The workforce numbers add a further constraint. Understaffed, underfunded teams dealing with rising attack volumes have less slack to design and run new exercises, even when the need for them is clear. Addressing the readiness gap may therefore depend on the same C-suite funding decisions Dimitriadis highlighted.

None of this means AI adoption should slow. ISACA's own findings show security teams are using it effectively for detection and response, and that they are helping shape how it is deployed. The gap is in the layer around that use: policies that are tested, runbooks that are exercised, and budgets that fund preparation rather than only reaction.

For businesses, the implication is that AI governance and AI incident response belong together. A policy that says how AI should be used, without a plan for what happens when it is misused or compromised, leaves the most likely failure modes unaddressed. The report suggests most organizations have yet to close that loop.

#ai incident response#isaca#governance#cybersecurity workforce#ai adoption

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories