Cybersecurity spending continues to outpace projections amid a surge in AI-related cyber threats, according to a Boston Consulting Group (BCG) survey.
The report – Cybersecurity Budgets Are Growing Fast. AI Threats Are Growing Faster – showed that cybersecurity spending grew 11% this year compared to a projection of 8%. Respondents are expecting their budgets to grow by 12% next year.
That uptick comes as chief information security officers (CISOs) anticipate that AI adoption will continue to push cyber budgets higher, with 49% expecting spending to increase over the next one to two years, before normalising thereafter.
Broader AI growth is contributing to increased cyber risk. As many as 89% of CISOs said their organisations had experienced an AI-enabled attack, with 35% saying those attacks had a significant operational or financial impact.
Another 80% said their organisations rely on incomplete AI threat intelligence, which means they can’t identify what an AI-powered phishing attack on their systems would look like.
Meanwhile, there were 25 incidents on average per organisation last year where sensitive data was leaked to generative AI tools.
Against that backdrop, 59% of respondents said they plan to adopt AI-powered SOC (security operations centre) triage this year, although a fully autonomous SOC is at least three to five years away, CISOs say.
A third of respondents said they are comfortable with Gen AI-powered security tools, though 44% of respondents said they are waiting for stronger AI governance and clearer vendor value before investing.
Organisations that have adopted a higher number of AI-specific security controls were less likely to experience a ‘significant’ AI threat impact. Some 24% of respondents with high control adoption said they had significant threat impact from AI vulnerability exploitation, compared to 46% with low control adoption. Meanwhile, 18% with high control adoption said shadow AI use was a significant threat, compared to 30% with low control adoption.
The most commonly adopted AI controls were a formal AI governance process (41%), followed by secrets management and token rotation (31%) and AI agent monitoring and logging, and API/runtime protection (both 23%). Only 19% of respondents said they are currently monitoring shadow AI use.
The report was based on a survey of around 300 global cybersecurity professionals.
Email your news and story ideas to: [email protected]


