Dive Brief:
- Businesses are more concerned about AI-fueled threats than traditional cybersecurity dangers, potentially undermining their ability to prepare for the attacks they are most likely to face, researchers at the security firm Arctic Wolf said on Tuesday.
- Roughly a third of organizations said AI topped their list of cybersecurity concerns, while concerns about malware, credential theft and cloud misconfigurations dropped from their 2025 numbers, according to Arctic Wolf’s annual AI and cybersecurity trends report.
- The report also delved into organizations’ use of AI for their security programs, their reasons for reporting cybersecurity incidents and regional trends in cybersecurity challenges.
Dive Insight:
Arctic Wolf described the prominence of AI on businesses’ list of concerns as a potentially worrisome trend.
“An often-overlooked risk surrounding AI is that the attention it receives is distracting leaders from more familiar business risks,” researchers wrote.
The issues that businesses worried less about in 2026 “remain legitimate risks for today’s organizations,” the report continued, “and the challenge for security leaders is to simultaneously develop and implement plans to safeguard against emerging risks (like those associated with AI) without neglecting to safeguard against historical risks that remain just as real today.”
Arctic Wolf’s report also contained a potentially paradoxical finding. Sixty-three percent of organizations said they had experienced at least one cybersecurity incident in the past 12 months, compared with 29% who said they were confident they had not experienced an incident. At the same time, 53% of surveyed business leaders said they were highly confident in their security teams’ ability to keep up with the threat landscape, and 43% were somewhat confident, bringing the total confidence level to nearly 100%.
“Confidence levels are actually higher in organizations that experienced such an incident,” Arctic Wolf researchers wrote. Fifty-seven percent of leaders at those organizations said they were very confident that their security personnel were keeping up with evolving threats, compared with 47% of leaders at non-victimized organizations.
Notably, the cybersecurity incidents that surveyed businesses experienced were not blips on the radar. Nearly half of victimized businesses said they experienced at least two weeks of lost productivity, and roughly one in 10 victims experienced at least two quarters of disruptions.
To augment their human defenders’ work, companies have been investing heavily in AI-powered automation. Nearly half of companies told Arctic Wolf that they were in the early stages of integrating AI into their cybersecurity programs, while 22% have already deployed AI in limited ways and 34% were operating mature deployments.
Businesses expressed high confidence in AI’s ability to help humans with security tasks, and majorities of respondents said AI would eventually outmatch humans at everything from identifying threats to providing context to reducing false-positive alerts.
Even so, agentic AI still inspires caution. Blocking malicious IP addresses and domains was the only activity that a majority of companies said they allowed AI agents to perform. Businesses reported distrusting AI agents due to their lack of human intuition, their occasional inaccuracy and the privacy concerns associated with unmonitored data access.
Arctic Wolf’s report is based on a survey of 1,350 IT and security leaders in 13 industries in the U.S. and 17 other countries.