What Happened

ISACA published its 2026 State of Cybersecurity report on 24 September 2026, revealing a pronounced gap between how quickly Australian organisations are adopting AI in security operations and how prepared they are to handle AI-related incidents when they occur.
Just 4 per cent of Australian organisations regularly run exercises testing their response to AI-related cyber incidents. Almost one-third, or 31 per cent, have conducted no AI-related incident response exercises at all. A further 48 per cent either do not know whether their organisation has established AI incident playbooks or say their organisation does not have them.
The report, now in its twelfth year, is based on responses from 1,888 cybersecurity professionals worldwide.
Why It Matters
The figures point to a concrete operational risk. Organisations are deploying AI in security functions at pace, but the internal processes for handling failures or attacks involving that AI have not been built out to match. Globally, 41 per cent of cybersecurity professionals surveyed said their organisations now use AI to automate threat detection and response, up from 32 per cent in 2025. Another 40 per cent use AI for routine security tasks, compared with 28 per cent a year earlier.
"While organisations are rapidly building AI into their operations, very few are regularly putting their response to an AI-related incident to the test," the report states.
The most common AI-related incident scenarios covered in response exercises, where they exist, include sensitive data exposure through AI systems (24 per cent), AI-enabled phishing, fraud or social engineering (23 per cent), and misuse of generative AI by employees or insiders (21 per cent).
Key Details
Cybersecurity professionals are becoming more directly involved in AI deployment. More than half, or 51 per cent, are now involved in developing, onboarding or implementing AI solutions, up from 40 per cent in 2025 and 29 per cent in 2024.
On workforce conditions, more than two-thirds (69 per cent) of cybersecurity professionals in Australia say their role is more stressful today than it was five years ago, while 58 per cent say their teams are understaffed. Seventy-four per cent of Australian respondents say their employer offers flexible work hours, compared with 53 per cent globally.
The report includes a direct call for organisations to close the preparedness gap: "An incident is not the time to discover that responsibilities are unclear or that your response plan doesn't account for AI. Organisations need to practise these scenarios, understand where the gaps are and ensure their people know how to respond."
On the workforce side, the report notes: "AI and automation can help cyber teams work more efficiently, but they don't solve the workforce challenge. Cybersecurity remains fundamentally dependent on skilled people who can think critically, communicate risk and make good decisions under pressure."
Background and Context
ISACA is a global professional association focused on IT governance, audit, and cybersecurity. Its annual State of Cybersecurity report tracks practitioner sentiment and organisational practice across a broad international sample.
The 2026 edition reflects a period in which AI tools have moved from experimental to operational in many security teams, raising questions about governance and accountability that existing incident response frameworks were not designed to address.
"AI is changing both how organisations defend themselves and the risks they need to defend against," the report states.
The report also flags a retention dimension: "Organisations need to look at how they attract people into the profession, how they develop them and, importantly, how they create careers that people want to stay in."
What Comes Next
The report does not set a specific timeline for regulatory or industry action, but it frames the current period as one requiring deliberate investment. "While there are some encouraging signs around governance, the pressure on cyber teams hasn't gone away," it notes. "Organisations need to make sure their investment keeps up with the risks they're asking their people to manage. That means having the right technology in place, but also investing in the people, skills and preparedness needed to respond when something goes wrong."