AI Forces Cyber Leaders to Rethink Security Spending #AI


Artificial Intelligence & Machine Learning
,
Next-Generation Technologies & Secure Development

PwC Finds Bigger Budgets Must Strengthen Data Protection and Resilience

PwC’s 2027 Global Digital Trust Insights survey found that 84% of security and finance leaders expect their cyber budgets to increase in 2027. (Image: Shutterstock)

Organizations are increasing cybersecurity spending as artificial intelligence accelerates attacks. But investment won’t necessarily improve resilience if it adds tools without strengthening data protection, operational continuity and technology architecture.

See Also: OnDemand | Payments Without Borders: Prevent Fraud and Improve the Customer Experience

PwC’s 2027 Global Digital Trust Insights survey found that 84% of security and finance leaders expect their cyber budgets to increase in 2027, up 6 percentage points over last year. AI is a major driver of that rise, with 58% of security leaders ranking it among their five leading investment priorities.

But this increased spending comes at a time when business leaders are struggling to manage risk. Only 39% of security, risk and operations leaders have fully formalized and integrated operational continuity plans addressing cyber risk, and just 5% of organizations have implemented all seven of the data risk measures examined in the survey.

“More spending doesn’t necessarily translate to more security,” said Tonya Ugoretz, who leads PwC’s Cyber and Risk Innovation Institute. “It has to be done smartly.”

The survey, which polled 3,934 business and technology leaders across 71 countries, found that many organizations are trying to strike that balance. Responsible AI governance was the leading AI-specific investment priority, cited by 42% of respondents, followed by platform hardening at 38% and supply chain security at 35%.

While most respondents expect to see a budget increase this year, some security leaders say they’re not receiving more money. Dan Wilkins, CISO, Arizona Department of Economic Security, said his organization’s cyber budget has remained relatively flat or has been cut slightly for several years.

“Gaps remain gaps, and we have had to delay other initiatives in order to invest resources in defending against the new data protection concerns,” Wilkins said.

Wilkins said AI has moved his team’s resources toward governance, monitoring and visibility, and the organization has developed dedicated policies and procedures, expanded prompt training and invested in controls intended to prevent unauthorized AI use.

The speed at which vendors have added generative AI has been especially difficult to manage, he said. In some cases, a vendor’s addition of AI has created regulatory problems that his team has had to address.

Escape the Additive Trap

The findings reflect an industry caught in an “additive trap,” said Christopher Frenz, founder of the OWASP Subtractive Security Project.

“For years, the default response to emerging risk has been to purchase another security product, another dashboard or another source of telemetry,” Frenz said. “While those investments can have value, adding more software to a fundamentally conductive environment often increases complexity without proportionately improving resilience.”

AI has made the limitations of that approach more apparent, dramatically increasing the speed and scale of attacks but not fundamentally changing what attackers set out to accomplish, Frenz said. They still must find a path to gain control, move through an environment, escalate privileges, access data or disrupt operations.

“We measure progress by what attackers can no longer do,” he said. Investments that remove lateral movement opportunities, eliminate standing privileges, constrain execution paths or reduce trust relationships receive higher priority than investments that simply generate additional alerts.

“Once a path has been removed, it cannot be traversed whether the attacker is operating at human speed or machine speed,” he said.

Prioritize Business Operations

Ugoretz said resilience planning should begin by identifying an organization’s “minimum viable company” – what must remain operational in the event of a disruption. CIOs and CISOs can then map the applications, data, infrastructure and vendors supporting those capabilities and prioritize controls around their most critical dependencies.

Wilkins uses a similar process to make investment decisions. His team conducts a detailed business impact analysis, compares the results with existing tool and platform coverage, identifies control risks and prioritizes improvements that will have the greatest impact for the cost. It then develops phased procurement plans that identify immediate needs and one-, three- and five-year objectives.

That process helps prevent AI from spooking organizations into making impulse buys.

It can also reveal where basic data protections, such as data classification and data-loss prevention, remain incomplete. Only 49% of respondents have fully implemented data classification policies, and 48% have fully deployed data loss prevention across the key channels through which information leaves the organization.

Without those protections, organizations may struggle to identify sensitive data and prevent it from leaving the enterprise. The consequences are growing as AI helps attackers find and exploit vulnerabilities faster and at greater scale.

“The margin for error in cybersecurity is shrinking,” Ugoretz said.



Click Here For The Original Source.

——————————————————–

..........

.

.