According to PwC's 2026 Global Digital Trust Insights survey, organizations plan to allocate the largest share of cybersecurity resources to artificial intelligence (AI) over the next 12 months. Among 3,887 business and technology leaders surveyed, 36% of planned cybersecurity spending is expected to go to AI, ahead of cloud infrastructure security (34%), network security (28%) and data protection (26%).
The data for the survey were collected between May and July 2025. Respondents represented organizations across 72 countries, and one-third (33%) of respondents represented large companies with revenues of USD 5 billion or more.
Resilience and preparedness: mixed results
The survey found that about half of security and business leaders believe their organization is "definitely able" to withstand cyberattacks, but only 6% say that this resilience covers all assessed areas. Around half of respondents reported being "definitely able" to address weak authentication and access controls (55%), vulnerable connected products and devices (48%), legacy systems (45%) and supply chain vulnerabilities (43%).
PwC notes that organizations need to invest in understanding and applying AI technologies and in developing related cybersecurity skills. It is also important that business leaders and the teams deploying these technologies clearly understand the governance and cyber risks, including scenarios where AI is used offensively or defensively.
Budgets are rising and priorities reflect AI momentum
Seventy-eight percent of organizations said their cybersecurity budgets will increase over the coming year; about one-third of that group (32%) expect budgets to grow by 6–10%. AI's rapid advance is reflected in budget priorities: investment in AI tops the list at 36%, followed by cloud security at 34%, network security at 28% and data protection at 26%.
When asked about AI security capabilities for the next 12 months, nearly half of leaders (48%) prioritize AI-supported threat detection and more than a third (35%) prioritize agent-based AI applications.
Cyber risk quantification and incident costs
Organizations are increasingly quantifying cyber risk financially: half of respondents said they currently use cyber risk quantification to a significant or substantial degree to measure financial impact, up from 44% last year. At the same time, one quarter of leaders reported that their most serious data breach in the past three years cost at least USD 1 million, consistent with last year's findings. Companies most exposed include those with revenues above USD 5 billion (41%), US-headquartered organizations (37%), and firms in the technology, media and telecommunications (TMT) sector (33%).
Talent shortage impedes AI-based defenses
A shortage of cybersecurity talent remains a major barrier to practical AI deployment, protection of complex digital environments and preparation for next-generation threats. Half of respondents (50%) said the biggest internal difficulty in deploying AI-based cybersecurity over the past 12 months was a lack of knowledge and relevant skills for cybersecurity uses of AI (41%).
In response, companies are focusing on areas such as AI and machine learning tools (53%), security automation solutions (48%), consolidation of cyber tools (47%) and reskilling or upskilling cybersecurity teams (47%). The skills gap extends beyond AI: 47% of leaders pointed to a lack of appropriately trained staff as a primary obstacle to securing operational technology (OT) and industrial IoT (IIoT) systems.
Low preparedness for quantum threats
The development of quantum technologies is seen as a significant but underprepared-for risk: only 26% of respondents feel prepared for quantum computing threats. Preparedness rates for other areas were 33% for cloud-based threats, 28% for attacks against connected devices and 27% for third-party data breaches.
Nearly half of organizations (49%) have not considered or started implementing quantum-resistant security measures. PwC attributes this to limited knowledge of post-quantum risks, constrained internal resources and competing priorities.
Conclusion
PwC's 2026 Global Digital Trust Insights survey shows that AI's rapid adoption is reshaping cybersecurity priorities and budget allocations. At the same time, uneven preparedness—especially skills shortages and limited readiness for quantum threats—leaves organizations exposed even as they increase investment in AI-enabled defenses.
Methodology (for editors)
The PwC 2026 Global Digital Trust Insights survey collected responses from 3,887 business and technology leaders between May and July 2025. Respondents were broadly representative across industries and regions; this is the 28th consecutive year of the annual survey.


