KPMG Survey Finds Cyberattacks Rising as CISOs Grapple With AI & Complexity
Key Takeaways
- Cyberattacks Are Increasing: Eighty-three percent of surveyed organizations reported an increase in cyberattacks over the past 12 months, with phishing, denial-of-service attacks and ransomware among the most common threats.
- AI Investment Is Outpacing Integration: Nearly 70% of organizations dedicate more than 11% of their cybersecurity budgets to AI-related initiatives, but only 24% have fully integrated AI into their cybersecurity programs.
- CISOs Face Growing Pressure to Prove ROI: Forty-two percent of security leaders said they struggle to clearly demonstrate the return on cybersecurity investments to executives and boards.
- Nonhuman Identities Are Expanding the Attack Surface: Service accounts, API keys, tokens, machine credentials and autonomous agents are creating identity governance challenges as organizations adopt generative AI.
- Security Teams Are Set to Grow: Seventy-four percent of respondents expect cybersecurity headcount to increase by more than 11%, while 55% are using managed service providers for cyber threat intelligence.
Deep Dive
Cyberattacks increased at 83% of large U.S. organizations over the past year, according to a recent KPMG survey, even as companies poured more money into artificial intelligence and expanded the responsibilities of the executives charged with keeping their systems secure.
The figure is difficult to separate from what comes after it. Seventy-four percent of security leaders reported a slight increase in attacks and another 9% reported a significant increase, with phishing, denial-of-service attacks and ransomware among the most common threats. At the same time, companies are moving quickly to put AI to work in cybersecurity, though considerably fewer have managed to integrate it fully.
KPMG's 2026 Cybersecurity & Technology Risk Survey, based on responses from 310 security leaders at U.S. organizations with more than $1 billion in annual revenue, captures an awkward moment for the modern security organization. The technology available to both attackers and defenders is becoming more sophisticated. The underlying problems inside many companies are more familiar: sprawling IT environments, fragmented security systems, shortages of skilled workers and controls that have not kept pace with what has been built around them. AI sits squarely in the middle of that problem.
Only 24% of organizations said they had fully integrated AI into their cybersecurity programs. Another 53% had implemented it in specific areas. Nearly 70%, however, already dedicate more than 11% of their cybersecurity budgets to AI-related initiatives. That gap between spending and integration matters because security leaders expect a great deal from the technology. Respondents see AI improving fraud protection, predictive threat analytics, anomaly identification and threat detection and response. But KPMG found that many organizations are trying to make those advances inside security architectures already burdened by complexity and disconnected tools.
There is a temptation in cybersecurity to answer a new problem with a new product. KPMG's findings suggest that the accumulation itself has become part of the problem. The firm identified IT complexity and fragmented security systems as two structural obstacles keeping organizations in a reactive posture, arguing that companies should focus less on adding point solutions and more on connecting the telemetry, inventories and workflows they already have.
“A key practical application for AI in security is not just threat detection but identifying and reducing complexity within the IT environment itself—because complexity is the enemy of security,” Matthew P. Miller, principal for Cybersecurity & Technology Risk at KPMG LLP, said.
For CISOs, that complexity is arriving alongside a second change. Their remit is growing beyond the technical boundaries that once defined the job. Security leaders are increasingly expected to explain cybersecurity in the language of the business, connecting their programs to productivity, customer trust, intellectual property protection, revenue and operational continuity. That is easier to demand than to do. Forty-two percent of leaders surveyed by KPMG said they struggle to demonstrate clearly the return on cybersecurity investments to executive leadership and boards.
The difficulty is partly one of measurement. A vulnerability remediated can be counted. So can an incident or the time required to detect it. The value of an outage that never occurred, intellectual property that was never stolen or an attack that was contained before it reached the business is harder to put neatly into a quarterly presentation.
Organizations are using incident volume, vulnerability remediation rates and mean time to detect as core measures of cybersecurity effectiveness, according to the survey. KPMG argues that those measures need to be connected to a broader account of risk and resilience, one capable of showing progress over time rather than merely recording the condition of the security program at a particular moment. The CISO's position inside the organization matters here as much as the metrics.
“Many companies still perceive the CISO as a business blocker,” Michael Isensee, KPMG's U.S. leader for Cybersecurity & Technology Risk, said. When CISOs are not regarded as partners capable of helping the business innovate safely, he warned, projects can proceed without them and leave the organization less secure.
It is a peculiar burden of the job. The CISO is increasingly accountable for risks created far beyond the security department while still having to earn a place in the decisions that create them. That burden is widening again as the meaning of identity changes.
Security programs have spent years building controls around people: who an employee is, what that person may access, when those privileges should be granted and when they should disappear. Modern technology estates now contain another population altogether. Service accounts, API keys, tokens, machine credentials and autonomous agents can possess access of their own, often without the lifecycle governance and clear ownership applied to human identities.
“We’ve got an entire universe of machine-based identities that doesn’t follow controlled provisioning processes as humans do,” Mick McGarry, principal for GRC Technology at KPMG LLP, said. “And it’s growing exponentially with the adoption of generative AI, making it harder to track, manage, and trust.”
Companies are responding to the broader workload with people as well as technology. Seventy-four percent of respondents expect cybersecurity team headcount to grow by more than 11%, while 55% are using managed service providers for cyber threat intelligence. KPMG said hybrid operating models combining internal teams with managed security services are increasingly being used to extend capabilities in areas including continuous monitoring, identity governance and automated response.
Some threats remain further over the horizon. Only 27% of organizations surveyed said they were actively implementing post-quantum cryptography solutions, even as quantum computing appears among the emerging technologies security leaders expect to affect the threat landscape.
KPMG's recommendations are consequently less exotic than the technologies driving much of the conversation. The firm called on organizations to establish formal AI security and governance programs, strengthen data protection and identity controls, reduce security-tool fragmentation, govern nonhuman identities throughout their lifecycles and develop multi-year plans for threats such as quantum computing.
There is something instructive in that mismatch. The security problem described by the survey is full of AI, autonomous agents and the approach of quantum computing, yet much of the work required of CISOs remains stubbornly practical. They have to know what exists inside their organizations, know who or what can reach it, simplify systems that have accumulated faster than they have been rationalized, and prove that the money being spent is producing something more durable than another layer of technology.
The tools are changing quickly. The discipline required to use them well is changing much more slowly.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

