SecurityWeek

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says


On the global stage, too few organizations are implementing new technology to defend against new technology employed by attackers.

PwC’s 2027 Global Digital Trust Insights report surveys just short of 4,000 businesses and tech leaders in more than 70 countries. It seeks to understand how industry is responding to a rapidly evolving digital environment. Artificial intelligence (AI) is the nexus.

AI takes center stage in this report. An increase in the volume and speed of AI-assisted attacks goes without saying; but the report highlights that leaders identify attacks targeting their own AI systems as the top cyber threat they are least prepared to address. Compromise by autonomous botnets (53%), adversarial attacks (52%), and data poisoning (52%) are the primary concerns they are unprepared to defend.

It is worth remembering OpenAI’s statement in late 2025 that prompt engineering, like social engineering, is unlikely ever to be fully solved. Better known as prompt injection when used by an attacker, a prompt injection attack can leak data or execute unauthorized commands; and it is unlikely we can prevent it. Noticeably, prompt injection is also the #1 in this year’s OWASP top ten list of LLM application threats.

AI is also considered to be the #1 cybersecurity defense for threat detection and alerting. However, only 22% of leaders would use “fully autonomous execution by AI agents for cyber defense without human approval”. Fifty-five percent say failings in reliability and maturity are the main causes of this reluctance. Forty-four percent also highlight a lack of workforce skills in AI oversight and governance. 

While this is the majority view at the time the survey was conducted, one must wonder if it is sustainable into the future. AI-assisted attacks are advancing in speed, scale and sophistication – faster than humans can counter without similar defensive speed. Only autonomous agent defense can match this speed; but an autonomous agent is not really autonomous if there is a human in the loop. It may simply become essential to use fully autonomous agents or risk repeated compromise.

Advertisement. Scroll to continue reading.

Full autonomy, however, will simultaneously increase a firm’s attack surface; but life and cybersecurity are both swings and roundabouts (or six of one, half a dozen of the other in the US). And there is no single ownership model for accountability. Twenty-nine percent of leaders believe it rests with the CIO, CTO or technical sphere; 26% with a dedicated and named AI leader or function, and perhaps surprisingly, only 17% with the CISO or cyber function. Eleven percent have accountability shared across multiple functions.

The security focus on AI has a knock-on effect. Eighty-four percent of security and finance leaders expect budgets to increase, with 58% ranking AI as the top cyber budget priority.

Surveys, especially large surveys, provide an interesting snapshot of opinions. But it is useful to remember that they represent a slice in time view of opinions that are historical by the time they reach us. AI in particular is advancing so fast that opinions held a few weeks ago may not reflect our understanding and priorities today. They are also fundamentally subjective, in both questions and answers, and can provide no ground truth.

Indeed, they may even have a negative effect. You may understand that you ought to do something that you haven’t yet done. Learning that many of your compatriots are similarly tardy could lessen the rightful sense of urgency and further delay your own action.

The fundamentals of cybersecurity have not been changed by the emergence of AI, but the process of security has been disrupted by the speed of new technology. There are more ways a network can be breached at speed, and the need to implement a strong security foundation is ever more critical. This PwC survey highlights the failure of many organizations throughout the world to do so adequately.

A typical example can be seen in the protection of corporate data. If we consider data to be the attackers’ gold, it is becoming easier to steal it with AI assistance. If it is impossible to guarantee the stronghold cannot be breached, the gold it contains must have additional protection. Encryption is the obvious and common solution – thieves may have the data, but they will not have access to the content. 

Emerging quantum technology is changing this. Quantum computers will soon be able to decrypt classic encryption with Shor’s algorithm, a date depicted as ‘Q-day’. So, attackers are stealing data today and holding it for decryption on Q-day – a process known as ‘harvest now, decrypt later’.

A solution exists. Current encryption can and should be replaced by new quantum resistant cryptography. But according to PwC, while the time to prepare is now, only 21% of those taking part in the survey are implementing quantum resistant security measures. 

The outstanding message of the survey is simple. We have the technology to strengthen our cybersecurity, but globally too few companies are implementing it. “Technology is moving incredibly fast, but the fundamentals of cybersecurity haven’t changed,” comments Morgan Adamski, PwC’s cyber, data & technology risk leader “You can invest heavily in AI and the latest security tools, but if you don’t have secure data, operational continuity, clear accountability and strong cyber hygiene underneath them, you’re building on a weak foundation. The goal isn’t to slow innovation down – it’s to make sure your organization is resilient enough to keep up with it.”

Related: AI Has Changed Attack Speed, Not Security Fundamentals

Related: Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments

Related: Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration

Related: Reco Raises $55 Million for Agentic Security

Related: Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense



Source link