2026 Cybersecurity Study
Cybersecurity Budgets Are Rising as AI Expands Risk
Cybersecurity budgets are increasing as organizations respond to broader threat surfaces, AI-related risk and growing demands for resilience. On average, survey respondents report a 5% increase in cybersecurity budgets for 2026 compared to 2025. Fifty-eight percent say current security budgets are insufficient to address AI-related risks.
This reflects a market where security funding is growing, but the pressure on programs is also intensifying. Enterprises are expanding investment while still needing to prioritize across prevention, detection, response, recovery and AI-specific controls.
Cybersecurity Budget Growth
Cybersecurity Teams Are Becoming AI Co-Owners
As AI moves into production, cybersecurity teams are taking on broader responsibilities in enterprise AI delivery. The most common role is co-ownership with data, IT or engineering, where the cybersecurity team has a joint governance role and decision rights on AI use cases. Other roles include advisor or consultant, in which the team provides guidance without direct decision-making authority, and policy gatekeeper, in which the team defines and enforces the rules governing AI use.
This shift shows that cybersecurity is moving beyond review and enforcement. Security teams are increasingly expected to help shape AI governance, define guardrails, review vendor risk and support secure deployment across business and technology teams.
Cybersecurity Role in AI Delivery
AI Controls Are Still Catching Up to AI Use
Many organizations have not fully accounted for AI systems in current network and security controls. Fifty-eight percent say AI is partially accounted for with known gaps, while 27% say AI systems are not explicitly accounted for in current architecture or policies.
These gaps matter as AI agents, RPA, autonomous services and other AI-enabled systems begin acting across domains without direct human initiation. Enterprises need clearer controls, stronger visibility and governance models designed for AI-era behavior.
AI Security Controls Gap
MSSPs Remain Critical as AI Risk Pressure Builds
Most organizations now use a blended approach to cybersecurity delivery. Forty-one percent use a balanced mix of internal teams and MSSPs, while others rely on internal teams with selective outsourcing or broader managed security support.
AI is also adding budget pressure. As AI risk pressure mounts, demand is growing for advanced managed capabilities, stronger liability provisions, and clearer risk transfer models. Organizations are increasingly looking to MSSPs not just for operational coverage, but to help define accountability when AI-enabled systems fail or are compromised.
MSSP Delivery and AI Budget Pressure
Study Profile
The study includes 201 senior security decision-makers from enterprises with more than 1,000 employees across the Americas, Europe and other regions. Sixty-four percent of respondents were C-level executives, including CIOs, CISOs, CEOs and CTOs, and 36% were other IT and security leaders.
Respondent organizations were mostly multinational, with median revenue of $4 billion and median size of 10,000 employees. Industries represented include banking and finance, manufacturing, retail, healthcare, services, travel, transportation and hospitality, telecommunications and other sectors.
Contact us to find out more about this study.