⚡ Quick Summary
Published in August 2026, this BCG report draws on the BCG & GLG CISO Survey 3.0 (May 2025, N=300) and Survey 4.0 (March 2026, N=302) to examine how cybersecurity budgets and AI-related threats are moving together. Its central claim is that cyber spending continues to outpace projections, driven by AI adoption and growing compliance requirements, while AI simultaneously expands the attack surface, gives attackers new capability and powers defensive tooling.
The report tracks spending across product categories, ranking expected 2026 changes against 2025, with cloud and container security, data security and managed security services at the top; data security shows the largest share of respondents expecting an increase (65%). It reports that 89% of respondents experienced AI-enabled attacks and that 35% recorded significant operational or financial impact, and that 49% expect AI adoption to keep raising cyber spend for one to two years before growth normalises.
On defences, it measures adoption of capabilities for securing AI systems, AI agents and non-human identities (n=70) — including formal AI governance processes, guardrails for agent actions, shadow AI monitoring and non-human identity governance — and states that high control adoption is well correlated with mitigating AI threats. It closes on provider choice and consolidation.
🧩 What’s Covered
The report moves from spending trends to threat data to defensive control adoption, closing with vendor strategy. Each page presents a chart or figures drawn from the two CISO survey waves.
- Spending versus projections: the opening analysis states that cyber spending continues to outpace projections, driven by AI and growing compliance requirements, and charts year-over-year change in cybersecurity spending for 2025 and 2026 survey respondents across previous-year, current-year and next-year spending, with values between 7% and 12%.
- Category-level budget shifts: a ranking of product categories by expected change in spend for 2026 versus 2025, led by cloud and container security, data security and managed security services, with cloud security posture management, data loss prevention, cloud workload and container protection and managed detection and response appearing as new entries.
- AI's effect on future budgets: 49% of respondents expect AI adoption to increase spend in the near term (1–2 years) then normalise, 18% expect spend to relocate across categories, 15% expect sustained acceleration, 9% expect automation to slow net growth, 6% say it is too early to determine and 3% expect AI to materially reduce spend.
- Three-part framing: AI is presented as increasing cyber and data privacy risks, as part of the hacker toolkit making attacks faster, easier to scale and more frequent, and as powering defences — organised as security for AI, AI-enabled threats and AI for security, with builders, defenders and attackers.
- AI security control adoption: capabilities applied to secure AI systems, AI agents or non-human identities (n=70), covering agent insurance (AIUC), formal AI governance processes, secrets management and token rotation, AI agent monitoring and logging, API/runtime protection, shadow AI monitoring, guardrails for agent actions, prompt injection detection, cross-domain threat detection and non-human identity governance, measured as not applicable, on radar, piloting or in use.
- Threat experience and severity: 89% report experiencing AI-enabled attacks, 35% with significant operational or financial impact, broken down by category including AI-driven targeted social engineering, AI-powered malware, AI-enabled fraud schemes, AI-assisted vulnerability exploitation, vulnerable AI-generated code, shadow AI and data leakage to AI tools, split between malicious external and negligent insider threats.
- Provider landscape: current usage of frontier AI labs (64%), platform incumbents (63%), hyperscaler solutions (39%), AI-enabled security startups (29%) and model plus DIY in-house (19%), each with a short rationale.
- Consolidation by maturity: rationale for consolidation by organisational maturity, using advanced (n=58) and emerging (n=63) archetypes derived from the BCG Cyber Maturity Scorecard within an overall sample of N=302.
💡 Why it matters?
For CISOs and AI governance leads, the report links two decisions that are usually made separately: where security budget goes and how far AI-specific controls have been deployed. It gives a baseline for benchmarking control adoption — formal AI governance processes, guardrails for agent actions and non-human identity governance sit at low maturity for most respondents — and reports that respondents with seven or more active controls see meaningful mitigation impact, which supports sequencing arguments in budget cases. Its threat and provider data help frame third-party and vendor-risk discussions around AI tools, and its consolidation analysis distinguishes what mature and emerging organisations optimise for.
❓ What’s Missing
The document reports survey results rather than methodology: beyond the survey names, dates and sample sizes, there is no detail on question wording, respondent selection, sector or region coverage, or how AI-enabled attacks and significant impact were classified. Several cuts rest on small bases, including n=70 for control adoption, n=18 and n=26 for the adoption tiers and n=58 and n=63 for the maturity split, and percentages are rounded. No recommendations tell readers which controls to prioritise or in what order. Budget expectations over one to two years will date quickly, and no legal or regulatory regime is tied to the compliance pressure that is cited as a spending driver.
👥 Best For
Security leaders and budget owners building the case for AI-related security investment; AI governance and risk leads benchmarking how far AI-specific controls such as agent guardrails, shadow AI monitoring and non-human identity governance have actually been deployed; third-party and vendor-risk teams assessing reliance on frontier AI labs, platform incumbents and specialists; and analysts tracking CISO spending priorities across survey waves.
📄 Source Details
Cybersecurity Budgets Are Growing Fast. AI Threats Are Growing Faster., dated August 2026 and published by BCG. No author names are printed. Nine pages, in English. Source lines credit the BCG & GLG CISO Survey 3.0 (May 2025, N=300) and Survey 4.0 (March 2026, N=302) with BCG analysis. No reference number, edition statement or URL appears in the text. The input was the extracted text of all nine pages; chart labels and values, particularly on page 2, extracted out of order.