Rapid advances in artificial intelligence (AI) are increasing cyber threats while a substantial share of corporate digital assets remain insufficiently protected, according to EY’s latest global research published in March 2026. The report warns that AI‑enabled attackers are increasingly exploiting less‑secure entry points and then moving through interconnected networks to reach critical systems, rather than focusing only on the most valuable targets.
Key findings and figures
- On average, 36% of organisations’ digital assets fall into what EY calls “exposure zones”: devices and systems that lack adequate security oversight or protection.
- The survey polled 840 senior executives and cybersecurity leaders from companies with annual revenues above US$1 billion; half of the firms surveyed reported revenues exceeding US$10 billion.
- Respondents represented companies across 17 industries in 128 countries.
Most vulnerable areas
EY highlights several areas of particular vulnerability: operational technology that supports day‑to‑day business, internet‑connected physical devices (IoT), digital environments shared with external partners, AI‑based applications, and network infrastructure.
Visibility gaps and the limits of a recovery‑first approach
More than two‑thirds of the cybersecurity leaders surveyed said their biggest concern is internal “blind spots” for which they lack adequate visibility. EY argues that traditional, recovery‑focused cybersecurity approaches are now insufficient: organisations must identify in advance which business processes need to remain operational during a severe cyber incident to ensure uninterrupted customer service.
Erik Slooten, partner for EY AI Confidence, said: “The emergence of artificial intelligence in cyberattacks has fundamentally changed the threat landscape, and most organisations are not yet fully prepared. It is no longer enough to protect only the most critical systems; the security of the entire digital operation must be assured.”
Recommended actions and timeline
EY warns companies have at most 12–18 months to prepare for next‑generation, AI‑driven attacks. The report recommends that organisations:
- Build comprehensive visibility of their digital asset estate;
- Remediate the most critical security gaps;
- Adopt AI‑driven defensive solutions;
- Strengthen protections for external partners and network infrastructure;
- Treat cybersecurity as an integral part of corporate operations, not merely a technical issue.
Mihály Zala, partner at EY, added: “Over the next 12–18 months companies should prioritise gaining full visibility of their digital assets, closing the most important security gaps, deploying AI‑based defensive solutions, and hardening the defenses of their external partners and network infrastructure.”
Why this matters to organisations
AI‑enhanced attacks spread faster and become more effective, and the presence of poorly monitored assets enables attackers to move laterally inside networks. EY’s findings indicate that significant visibility gaps increase operational, customer service and reputational risks, making visibility and proactive defence top priorities for businesses.
About the study
The EY Global Cybersecurity Leadership Insights Study 2026, carried out in March 2026, sought to understand how organisations can improve visibility and cybersecurity coverage of assets identified as part of the attack surface in response to frontier AI‑driven risks.



