IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
European cyber teams understaffed as AI threats rise

European cyber teams understaffed as AI threats rise

Tue, 6th Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

ISACA has published research showing that European cybersecurity teams remain understaffed and underfunded as attacks increase. The study also found that most organisations are unprepared for AI-specific security incidents.

Among European IT and cybersecurity professionals surveyed, 38% said their organisation had experienced more cyberattacks than a year earlier, while 54% said an attack was likely in the next 12 months. The findings point to a widening gap between the volume of threats and the resources available to respond.

Pressure on staff is also rising. The research found that 72% of respondents said their job is more stressful now than five years ago, with the increasingly complex threat landscape cited by the same share as the main reason. Unrealistic expectations and excessive workloads were named by 57%, while 35% pointed to a lack of training or skills among staff.

More than half of those surveyed said their teams lacked enough people or money. Overall, 56% described their cybersecurity function as understaffed and 55% as underfunded.

Threat picture

The survey suggests the nature of attacks is also shifting. Cybercriminals and hackers accounted for 39% of incidents reported by respondents, while social engineering was identified as the most common form of attack at 46%.

That matters because social engineering relies on manipulating people rather than directly penetrating systems, and such attacks are increasingly supported by AI. This leaves security teams dealing not only with a higher volume of incidents but also with methods that can be harder to detect using traditional controls.

Despite the strain, a fifth of companies are not taking steps to address burnout. The survey found that 21% of organisations take no action to mitigate burnout among cybersecurity staff, even as retention and recruitment remain persistent concerns across the sector.

Others are trying to reduce pressure on teams. Among respondents, 55% said their organisation offers flexible working hours and 46% said it encourages employees to take breaks and holiday time.

Chris Dimitriadis set out the organisation's view of the findings.

"The growing gap between rising threats and under-resourcing for cybersecurity is taking a toll on the people tasked with managing it. Too often we are seeing budgets being sunk into crisis response, but there's still a distinct lack of investment in the workforce, training, and resources needed to prevent attacks and protect organisations in the first place. Preparedness is key to resilience, and we must see this reflected in the way businesses approach cybersecurity investment. Better funding and a clear plan for improving cyber resilience should be a C-suite priority," said Chris Dimitriadis, Global Chief Strategy Officer at ISACA.

AI exposure

The research found that AI is becoming more embedded in cyber operations even as formal preparation for AI-related failures remains limited. Some 37% of organisations said they use AI to automate threat detection and response, up eight percentage points from the previous year.

Another 29% said AI was used for endpoint security and 35% said it was used to automate routine security tasks. The figures indicate that security teams are adopting AI tools in operational settings rather than treating them as experimental systems.

Cyber teams are also influencing wider AI use inside their organisations. More than half, or 54%, said they or their team had been involved in the development, onboarding or implementation of AI solutions, while 60% said they had helped develop policies governing AI use.

Yet incident planning appears to lag well behind adoption. The study found that 71% of organisations had not conducted any AI-related incident response exercises, despite the growing use of AI in both internal systems and external attacks.

Only 3% said they had mature, formal runbooks for AI-specific incidents. Close to a third, or 30%, said they had not started addressing their response to AI-related incidents at all.

The survey said AI-related exercises could help organisations prepare for scenarios including sensitive data exposure through AI systems, AI-enabled phishing, fraud, social engineering, and misuse of generative AI by employees or insiders. The findings suggest many organisations are adopting the technology faster than they are building governance and response processes around it.

Dimitriadis said stronger controls were needed as AI use expands.

"Organisations can effectively use AI for preventing and detecting cyber threats. However, its governance should be non-negotiable. AI governance is critical to ensuring employees are using AI safely in the workplace, but also to ensuring that businesses understand and can protect themselves from AI-generated threats. Implementing checks and balances such as CMMI's AI Maturity Model (AIM) can give teams a structured way to benchmark AI governance maturity rather than relying on ad hoc controls as adoption accelerates," said Dimitriadis.

The research was based on a survey of 1,888 cybersecurity professionals globally, including 494 respondents in Europe.