CISO data reveals temporary AI risk confidence

Security leaders with mature AI controls report strong risk tolerance. But lasting confidence requires organizational catch-up.

See how security leaders rate their AI security maturity, governance, and controls, and where the widest gaps remain—including adversarial testing, attack surface visibility, and non-human identity oversight.

74%

of AI environments already pull data from external connectors

29%

of organizations have tested their AI security

4.9/10

security team AI effectiveness rating

Present-day AI risk vs. future confidence

Leaders that feel exposed today aren't necessarily pessimistic about their AI future. New data from 113 CISOs reveals the factors that lower today’s risk score are almost nothing like the factors that build confidence over the next 24 months. See the one leadership factor that swings CISO optimism by 64 percentage points.
See the data
Today’s AI tooling decisions are inherently temporary, because the security tooling market is changing so rapidly that the right tool 18 months from now likely won’t resemble anything currently available.
Jake Williams, IANS Faculty

AI governance catches up to deployment

Most CISOs have cleared the AI policy baseline: 66% have a dedicated AI policy. Fewer have built the technical controls and adversarial testing to back it up—71% haven’t tested their AI systems at all. New benchmark data illuminates security gaps and IANS Faculty share what to fix first.
Learn more

A deeper dive on the 1H 2026 Benchmark data. Explore what separates confident CISOs from anxious ones as enterprises increase their AI reliance and innovation. Hint: it isn't more controls. Get practical guidance to strengthen your readiness.

 

IANS Faculty, Wolfgang Goerlich explores how IANS MCP integrates expert cybersecurity guidance into AI tools, providing timely, unbiased intelligence that drives faster security decisions.

Advance AI security with practitioner- and peer-sourced intelligence

We're all in the AI security race together. You're already turning to AI to answer urgent governance questions. But do you know who's behind your outputs?

The IANS MCP Server puts practitioner- and peer-sourced intelligence into the AI tools you already use. Built alongside the folks writing today's MCP best practices, our connector won't add to your AI risk—it gives you practical guidance to move forward.

Learn more