84% of Senior Leaders Expect Cyber Budgets to Rise
Organizations are intensifying their cybersecurity investments in response to rapid advancements in artificial intelligence, according to PwC’s 2027 Global Digital Trust Insights Survey.
More than four-fifths (84%) of security and finance executives anticipate an increase in cyber budgets, up from 78% in the previous year.

Organizations are intensifying their cybersecurity investments in response to rapid advancements in artificial intelligence, according to PwC’s 2027 Global Digital Trust Insights Survey. More than four-fifths (84%) of security and finance executives anticipate an increase in cyber budgets, up from 78% in the previous year.
The survey, which collected perspectives from nearly 4,000 business and technology executives across 71 countries, indicates that as frontier AI models are deployed, approximately 58% of security leaders identify AI as a top budget priority for the coming year. This occurs while only 39% of security and operations leaders maintain a fully formalized operational continuity plan that specifically addresses cyber risks. When asked about specific vulnerabilities, 50% of security leaders identified attacks targeting AI systems as their primary concern—surpassing cloud-related threats (40%), third-party breaches (34%), and ransomware (33%).
“The ultimate goal of cybersecurity is not just to protect the business, but to give the business the confidence to move forward. As organisations race to capture the value of AI, cyber resilience needs to become a business capability, embedded in C-suite decision-making from the outset. The survey finds many organisations are still under-prepared for a rapidly evolving cyber landscape, and organisations that get this right will be better positioned to innovate with confidence while continuing to operate through disruption,” stated Avinash Rajeev, Global Cyber, Data & Tech Risk Leader at PwC US.
Organizations are advised to integrate cybersecurity into C-suite decision-making to strengthen their defenses. Despite the rise in frontier AI vulnerabilities, companies have implemented an average of only three out of seven critical data-risk measures. Furthermore, only 5% of respondents have fully implemented all surveyed measures—a decrease from 7% last year. While one-third (33%) of CEOs and security leaders report establishing dedicated AI roles, fewer than half strongly agree that cyber risk is a standing agenda item at the board level (47%) or at executive leadership meetings (45%).
As cyber-attacks achieve speeds beyond human capacity, AI is becoming a vital force multiplier for security teams. However, trust remains a significant hurdle, particularly regarding the use of autonomous AI agents. Concerns such as compromise by autonomous botnets (53%), adversarial attacks (52%), and data poisoning (52%) are among the top AI-enabled threats that security leaders feel least prepared to address.
While leaders prioritize threat detection (50%) and phishing response (42%) as key AI focus areas, only 22% would authorize fully autonomous execution by AI agents for defense. Technological maturity remains a concern, with 55% citing the reliability of AI as a primary barrier to increasing autonomy, while 46% point to accountability in AI decision-making. Additionally, 44% of CISOs identify a lack of workforce skills in AI governance as a significant impediment.
In response to this new frontier of risk, 54% of security leaders are adopting multi-cloud or hybrid cloud strategies, while others are enhancing regional data redundancy (47%) and localizing infrastructure (37%). Given the impact of geopolitics on the risk landscape, 50% are also modifying their third-party and supply chain risk management. Furthermore, many organizations are utilizing managed services, with artificial intelligence (53%) being the primary focus as they address a shortage of specialized talent.
To insulate businesses against evolving threats, organizations must strengthen governance, protect critical operations, build resilience, and secure emerging technologies while managing ecosystem and technology concentration risks.
“AI is changing both sides of the cyber equation. It is creating new risks and expanding the attack surface, but it can also transform how organisations defend themselves. The opportunity is to build the trust, governance and human oversight that allow organisations to use AI more confidently to secure the enterprise and create value,” Rajeev concluded.