Thursday, 1 October 2026

Where technology leaders come to think out loud

The BriefCybersecurity

ISACA finds European cyber teams understaffed as attacks rise

The professional body’s annual workforce survey shows attacks climbing while budgets and headcount lag. Fewer than one in three European organizations have rehearsed an AI-related incident

The facts
  • Globally, 26% of teams are making more use of contract staff or outside consultants to fill technical skills gaps
  • 35% of teams worldwide are leaning more on AI or automation to cover skills gaps, up 12 points on 2025
  • 48% of global respondents either lack AI incident playbooks or don’t know whether they have them
  • ISACA reports that 21% of European organizations take no action on burnout
What to do now

Run an AI-specific tabletop exercise this quarter: pick one AI tool already in use, assume it leaks data or has been manipulated, then walk through who decides, who is told and what gets switched off. Turn the result into a short runbook. With social engineering still the leading attack type, refresh verification steps for payment and access requests. Where headcount is frozen, decide which tasks go to automation or outside providers before burnout forces the choice.

“Too often we are seeing budgets being sunk into crisis response, but there’s still a distinct lack of investment in the workforce, training, and resources needed to prevent attacks and protect organisations in the first place.”Chris Dimitriadis, global chief strategy officer, ISACA

ISACA, the professional association for IT governance and security staff, published the European findings of its State of Cybersecurity 2026 survey on 22 September. Almost four in 10 (38%) European respondents said their organization faced more attacks than a year earlier, while 56% described their team as understaffed and 55% as underfunded.

The 12th annual survey, sponsored by Wolters Kluwer TeamMate, gathered responses from more than 1,800 cybersecurity professionals worldwide. ISACA’s European release puts the total at 1,888, 494 of them in Europe, surveyed in May 2026. Globally, 58% said their team was understaffed, up from 55% a year earlier, 49% had open security roles and 55% struggled to keep qualified staff.

In Europe, 54% think a cyberattack on their organization is likely within the next year. Social engineering was the most common attack type, cited by 46%, and 72% said the job is more stressful than five years ago.

AI is spreading faster than the planning around it. Some 37% of European organizations now use AI to automate threat detection and response, yet 71% have run no AI-related incident response exercise, 30% have not started on AI incident response at all and only 3% have mature, formal runbooks. The global release puts the share running AI-specific exercises regularly at 8%.

Sources
  1. ISACA, “Cyber Teams Stretched Too Thin as Attacks Intensify and Budgets Shrink, ISACA Research Finds”, press release, 22 September 2026. https://www.isaca.org/about-us/newsroom/press-releases/2026/cyber-teams-stretched-too-thin-as-attacks-intensify-and-budgets-shrink-isaca-research-finds
  2. ISACA, “Only 8 Percent of Organizations Conduct Regular AI-Specific Response Exercises, ISACA Research Finds”, press release, 22 September 2026. https://www.isaca.org/about-us/newsroom/press-releases/2026/only-8-percent-of-organizations-global-enterprises-conduct-regular-ai-specific-response-exercises
  3. Infosecurity Magazine, “AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds”, 22 September 2026. https://www.infosecurity-magazine.com/news/orgs-lack-ai-incident-response/
AdvertisementZoomInfo
More from The BriefAll briefs
Civo

Civo names Hertfordshire as first of 40 planned UK edge data centers

Westcoast Cloud

Westcoast Cloud adds Gamma's Teams calling to its marketplace

Barracuda

Barracuda bundles AI governance into SecureEdge for MSPs

Amazon Web Services

AWS puts Moonshot’s Kimi K3 on Bedrock with US and global routing only

Get the briefs every week in The VETTDD Briefing.