getty-images-U4ttQaB2ixE-unsplash

2026 Cybersecurity Study

Cybersecurity Budgets Are Rising as AI Expands Risk

Cybersecurity budgets are increasing as organizations respond to broader threat surfaces, AI-related risk and growing demands for resilience. On average, survey respondents report a 5% increase in cybersecurity budgets for 2026 compared to 2025. Fifty-eight percent say current security budgets are insufficient to address AI-related risks.

This reflects a market where security funding is growing, but the pressure on programs is also intensifying. Enterprises are expanding investment while still needing to prioritize across prevention, detection, response, recovery and AI-specific controls.

Cybersecurity Budget Growth

2026_ Cybersecurity_Study_Graphics_01_cybersecurity_budget_growth_V1

Cybersecurity Teams Are Becoming AI Co-Owners

As AI moves into production, cybersecurity teams are taking on broader responsibilities in enterprise AI delivery. The most common role is co-ownership with data, IT or engineering, where the cybersecurity team has a joint governance role and decision rights on AI use cases. Other roles include advisor or consultant, in which the team provides guidance without direct decision-making authority, and policy gatekeeper, in which the team defines and enforces the rules governing AI use.

This shift shows that cybersecurity is moving beyond review and enforcement. Security teams are increasingly expected to help shape AI governance, define guardrails, review vendor risk and support secure deployment across business and technology teams.

Cybersecurity Role in AI Delivery

2026_ Cybersecurity_Study_Graphics_02_cybersecurity_role_in_ai_delivery_V1

AI Controls Are Still Catching Up to AI Use

Many organizations have not fully accounted for AI systems in current network and security controls. Fifty-eight percent say AI is partially accounted for with known gaps, while 27% say AI systems are not explicitly accounted for in current architecture or policies.

These gaps matter as AI agents, RPA, autonomous services and other AI-enabled systems begin acting across domains without direct human initiation. Enterprises need clearer controls, stronger visibility and governance models designed for AI-era behavior.

AI Security Controls Gap

2026_ Cybersecurity_Study_Graphics_03_ai_security_controls_gap_V2

MSSPs Remain Critical as AI Risk Pressure Builds

Most organizations now use a blended approach to cybersecurity delivery. Forty-one percent use a balanced mix of internal teams and MSSPs, while others rely on internal teams with selective outsourcing or broader managed security support.

AI is also adding budget pressure. As AI risk pressure mounts, demand is growing for advanced managed capabilities, stronger liability provisions, and clearer risk transfer models. Organizations are increasingly looking to MSSPs not just for operational coverage, but to help define accountability when AI-enabled systems fail or are compromised.

MSSP Delivery and AI Budget Pressure

2026_ Cybersecurity_Study_Graphics_04_mssp_delivery_and_ai_budget_pressure_V1

Study Profile

The study includes 201 senior security decision-makers from enterprises with more than 1,000 employees across the Americas, Europe and other regions. Sixty-four percent of respondents were C-level executives, including CIOs, CISOs, CEOs and CTOs, and 36% were other IT and security leaders.

Respondent organizations were mostly multinational, with median revenue of $4 billion and median size of 10,000 employees. Industries represented include banking and finance, manufacturing, retail, healthcare, services, travel, transportation and hospitality, telecommunications and other sectors.

If your organization needs help strengthening cybersecurity strategy, aligning AI governance with security controls and evaluating MSSP and third-party risk models, ISG can help.
Bar Image

Contact us to find out more about this study.  

Bar Image