HomePress ReleaseOnly 21% of Indian Organizations Regularly Test Their Response to AI-Driven Cyber...

Only 21% of Indian Organizations Regularly Test Their Response to AI-Driven Cyber Threats: ISACA Research

In light of recent news revealing several instances of rogue AI model behavior, new research from ISACA finds concerning news about AI security. While AI is being heavily leveraged within cybersecurity teams, only 21 percent of organizations in India indicate they conduct AI-specific response exercises regularly, according to new research from ISACA.

Also read: AI Adoption Is Racing Ahead of Governance in India: RV Raghu, ISACA

ISACA’s 2026 State of Cybersecurity survey report, sponsored by Wolters Kluwer TeamMate, garnered responses from more than 1,800 global cybersecurity professionals including 147 cybersecurity professionals in India. The report explored trends in cybersecurity hiring, staffing, and budgets, while focusing on cyberrisk and threats, cybersecurity operations, and the role of AI in cybersecurity work.

AI incident response planning lags, even as AI transforms cybersecurity roles

This 12th annual survey finds that nearly half (49 percent) of enterprises in India have not conducted any AI-related incident response exercises, including top types cited by respondents like AI-enabled phishing, fraud or social engineering (33 percent), AI-related incidents such as sensitive data exposure through AI systems (32 percent), and unauthorized access to AI systems, models, or data (32 percent). Though, 20 percent say that AI incident response is included in broader cyber incident response exercises and 13 percent plan to conduct AI-specific exercises in the future.

The gaps in planning at enterprises also extend to AI incident playbooks. Over a third (35 percent) of India-based respondents either don’t know whether their organization has established them or mention their organization does not have them.

This comes as more Indian cybersecurity professionals are using AI in their everyday work, only 10 percent do not use AI in their security operations. It is interesting to note that top uses of AI in cybersecurity in India include automating routine security tasks (53 percent, up from 34 percent last year), automating threat detection/response (52 percent, up from 42 percent in 2025), and endpoint security (40 percent).

Increasingly, AI is also impacting the skills required in cybersecurity roles.  Thirty four percent of India-based respondents cite LLM SecOps as a skill gap among cybersecurity professionals, a 10-point increase from 2025.

“AI adoption in India is moving at a fast pace and this research is a wake-up call for India’s cybersecurity teams that speed without readiness is a risk in itself. Many enterprises are automating threat detection and routine security work at a rapid pace, yet most still lack tested playbooks for AI-specific incidents like model tampering, data exposure, or AI-powered social engineering. As AI investment continues to scale across Indian organizations, closing the gap between adoption and preparedness is critical through regular incident exercises and dedicated LLM SecOps training. This needs to become a boardroom priority, not just a security issue,” says RV Raghu, ISACA Ambassador & Director, Versatilist Consulting India Pvt. Ltd.

Cybersecurity professionals in India are now even more hands-on with AI implementation and governance within their organizations, with more than half (51 percent) now involved in developing, onboarding or implementing AI solutions, up from 46 percent in 2025 and 27 percent in 2024. Additionally, 52 percent of Indian respondents say that they or someone from their team were involved in policy governing development for the use of AI in their organization.

Stress growing amid persistent staffing challenges, evolving threats

With increased AI use not only comes new work tools and responsibilities for cybersecurity staff but also shifting cyber threats to mitigate and with it, increased stress. More than half (57 percent) of India-based survey respondents reported that work has become more stressful today than five years ago. Respondents cite the main cause being the increasingly complex threat landscape (71 percent, up from 59 percent in 2025). This is a change from the 28 percentage-point drop for this stress driver from 2024 (87 percent) to 2025 (59 percent).  

While stress is high, only 23 percent of India-based respondents say they expect a cyber-attack on their organization in the next year, and 31 percent indicate they are experiencing an increase in these attacks compared to a year ago. More than half of cybersecurity professionals in India (54 percent) are completely or very confident in their organization’s cybersecurity team’s ability to detect and respond to cyber threats, compared to 42 percent globally.

Additionally, staffing struggles continue to impact cybersecurity teams, with work-life balance (51 percent) and hiring/retention challenges (49 percent) coming up as additional key stressors in India. Forty-two percent of Indian organizations believe their cybersecurity team is understaffed and 56 percent report having open cybersecurity positions.

Retention remains a challenge, with more than half (66 percent) reporting difficulties retaining qualified cybersecurity professionals. High work stress is now the leading reason people leave their roles, cited by 46 percent, followed by limited promotion and development opportunities (44 percent).

Taking steps to support staff, address skills gaps

Many organizations are stepping up to support their cyber workforce by offering flexible work hours (54 percent), and encouraging breaks and vacation time to mitigate burnout 41 percent.

Employers are also offering cybersecurity team members benefits, including professional development training (60 percent, up from 53 percent last year), paying for certification fees (57 percent, up from 51 percent in 2025), offering flex work hours (49 percent, down from 52 percent last year) and paying for certification maintenance fees (39 percent, up from 35 percent in 2025) to improve retention.

Cybersecurity teams are also working to remedy skills gaps among their staff. In addition to LLM SecOps, respondents cite soft skills (46 percent), ML SecOps (43 percent), Scripting/automation (41 percent), and Data Security (36 percent) as the biggest skills gaps they see.

In this AI era, human soft skills are still in demand, including critical thinking (56 percent), problem solving (52 percent), communication (listening, speaking, conflict resolution) (48 percent), teamwork (collaboration and cooperation) (46 percent), and Leadership (includes coaching, mentoring, people management) (44 percent).

Organizations are largely turning to online learning websites (59 percent) and mentoring (54 percent) to address nontechnical skills gaps. To address technical cybersecurity skills gaps, nearly half (46 percent) of cybersecurity teams are increasing their reliance on AI or automation, a 16-point increase from last year. They are also turning to training non-security staff for security roles (31 percent) and increased usage of contract employees or outside consultants (22 percent).

“Despite a majority of organizations struggling with retention and security professionals identifying high workload as a critical factor in job stress, we see a year-over-year increase in organizations with no open cybersecurity positions,” Sandy Buchanan, Lead Product Manager, Wolters Kluwer TeamMate. “It’s no surprise that we also see many organizations embracing the use of AI to augment their teams’ capabilities across their security operations. This highlights how critical it is for security and compliance platforms to provide AI-powered integrations and automation support to reduce the workload on these teams.”

Author

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

spot_img
Dhrubabrata Ghosh
spot_img
Dhrubabrata Ghosh