ISACA finds European cyber teams understaffed as attacks rise
The professional body’s annual workforce survey shows attacks climbing while budgets and headcount lag. Fewer than one in three European organizations have rehearsed an AI-related incident
- Globally, 26% of teams are making more use of contract staff or outside consultants to fill technical skills gaps
- 35% of teams worldwide are leaning more on AI or automation to cover skills gaps, up 12 points on 2025
- 48% of global respondents either lack AI incident playbooks or don’t know whether they have them
- ISACA reports that 21% of European organizations take no action on burnout
Run an AI-specific tabletop exercise this quarter: pick one AI tool already in use, assume it leaks data or has been manipulated, then walk through who decides, who is told and what gets switched off. Turn the result into a short runbook. With social engineering still the leading attack type, refresh verification steps for payment and access requests. Where headcount is frozen, decide which tasks go to automation or outside providers before burnout forces the choice.
“Too often we are seeing budgets being sunk into crisis response, but there’s still a distinct lack of investment in the workforce, training, and resources needed to prevent attacks and protect organisations in the first place.”Chris Dimitriadis, global chief strategy officer, ISACA
ISACA, the professional association for IT governance and security staff, published the European findings of its State of Cybersecurity 2026 survey on 22 September. Almost four in 10 (38%) European respondents said their organization faced more attacks than a year earlier, while 56% described their team as understaffed and 55% as underfunded.
The 12th annual survey, sponsored by Wolters Kluwer TeamMate, gathered responses from more than 1,800 cybersecurity professionals worldwide. ISACA’s European release puts the total at 1,888, 494 of them in Europe, surveyed in May 2026. Globally, 58% said their team was understaffed, up from 55% a year earlier, 49% had open security roles and 55% struggled to keep qualified staff.
In Europe, 54% think a cyberattack on their organization is likely within the next year. Social engineering was the most common attack type, cited by 46%, and 72% said the job is more stressful than five years ago.
AI is spreading faster than the planning around it. Some 37% of European organizations now use AI to automate threat detection and response, yet 71% have run no AI-related incident response exercise, 30% have not started on AI incident response at all and only 3% have mature, formal runbooks. The global release puts the share running AI-specific exercises regularly at 8%.
Sources
- ISACA, “Cyber Teams Stretched Too Thin as Attacks Intensify and Budgets Shrink, ISACA Research Finds”, press release, 22 September 2026. https://www.isaca.org/about-us/newsroom/press-releases/2026/cyber-teams-stretched-too-thin-as-attacks-intensify-and-budgets-shrink-isaca-research-finds
- ISACA, “Only 8 Percent of Organizations Conduct Regular AI-Specific Response Exercises, ISACA Research Finds”, press release, 22 September 2026. https://www.isaca.org/about-us/newsroom/press-releases/2026/only-8-percent-of-organizations-global-enterprises-conduct-regular-ai-specific-response-exercises
- Infosecurity Magazine, “AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds”, 22 September 2026. https://www.infosecurity-magazine.com/news/orgs-lack-ai-incident-response/
