UK CISOs say attackers have AI advantage in cyber threat
Fri, 2nd Oct 2026 (Today)
Kai has published UK research on how Chief Information Security Officers view AI-driven cyber threats and response readiness. The survey found that most believe attackers currently hold the advantage.
The findings are based on a survey of 100 UK CISOs at private sector companies with annual revenue of at least USD $500 million. They highlight a gap between concern about AI-assisted attacks and the speed at which many organisations address serious security flaws.
Nearly all respondents said their organisations were prepared to defend against AI-accelerated vulnerability exploitation, with 94% expressing some level of preparedness. However, only 33% said they were very prepared, suggesting a clear gap between general confidence and strong assurance.
That caution is reflected in views on the balance of power between attackers and defenders. Some 59% said attackers have the advantage at current levels of AI adoption and advancement, while 13% said defenders hold the advantage.
Remediation delays
The research also highlighted the slow pace of vulnerability remediation in many UK organisations. It found that 67% take more than a week to remediate critical vulnerabilities, while 54% said at least a quarter of known vulnerabilities remain unresolved for more than 30 days.
Manual work remains a major part of the process. More than half of respondents, 54%, said their vulnerability and exposure management processes are at least half manual, indicating that many security teams still rely heavily on human-led workflows even as attack methods accelerate.
Those operational demands appear to be affecting staff. The survey found that 84% of UK CISOs said vulnerability and exposure management contributes at least moderately to security team burnout, including 19% who described it as a major contributor.
Nick Degnan, Chief Revenue Officer at Kai, said the results show pressure building on defenders as attacks speed up.
"AI is changing the speed of cyberattacks, and security teams can't afford to fall further behind. The concern is that attackers are getting faster while many defenders are still operating with processes built for a different era. UK organisations know they need to change, but moving from human-led to machine-led security takes trust, governance and a willingness to let machines take on more of the work. The longer that transition takes, the more room attackers have to pull ahead," Degnan said.
Automation barriers
While the survey suggests many organisations want more automation, it also shows significant hesitation about letting software take direct action. A total of 51% of respondents cited a lack of trust in automated decisions as one of the biggest barriers to wider adoption.
Governance or compliance concerns and skills or talent gaps were each cited by 45% of respondents. The data suggests the barriers are not limited to technology, but also involve oversight, accountability and internal readiness.
Current use of automation appears strongest in lower-risk tasks. The survey found that 57% of organisations use automation for vulnerability prioritisation and 55% for asset discovery and inventory.
Far fewer allow automation to act without human approval. Only 32% said their organisations permit automated remediation actions without sign-off, showing that many remain wary of allowing systems to make changes directly to their environments.
Respondents also identified the conditions that would make them more comfortable with machine-led remediation. Some 54% pointed to vendor accountability and liability protections, 53% cited auditability and explainability, and 52% said regulatory clarity would increase their confidence.
Shift under way
Despite those concerns, the study indicates that machine-led approaches are already gaining ground in the UK. Forty-six per cent of respondents described their vulnerability and exposure management approach as mostly or primarily machine-led.
Governance structures also appear to be adapting. Some 94% said their organisation's governance approach is either already designed to support machine-led security actions or is being adapted to allow more machine-led operation.
When asked about the next 12 to 18 months, 40% said they expect humans to supervise machine-led systems that lead prioritisation and execution. Another 25% expect most vulnerability and exposure management workflows to be machine-led, while 14% expect autonomous security operations to become the primary operating model.
The survey was conducted by Wakefield Research among 500 CISOs across four markets, including 100 in the UK. All UK findings cited in the research are based on those 100 respondents.