CSC Report Reveals CISOs Split on AI: 73% See Opportunity, 86% Fear AI-Powered Attacks
Event summary
- CSC surveyed 300 senior security executives in Q1 2026, finding 73% view AI as more opportunity than risk, but 86% cite AI-powered DGAs as a threat.
- Top 2025 threats ranked: domain/DNS hijacking (1), cybersquatting (2), and ransomware (3).
- Only 14% of respondents are 'very confident' in mitigating domain attacks, with 10% calling major businesses 'significantly underprotected' against DNS outages.
- 98% worry about third-party AI systems accessing company data, yet 70% apply risk controls only to key suppliers.
- 57% now use AI-based monitoring (up from 50% in 2025), and 44% use AI for threat detection (up from 36%).
The big picture
CSC's report highlights a paradox in enterprise cybersecurity: while AI is increasingly seen as a defensive tool, its offensive applications—particularly in domain attacks—are accelerating. The findings reflect broader industry tensions between leveraging AI for security and mitigating its misuse by threat actors. As social media impersonation and defamation emerge as top concerns, CISOs face pressure to balance proactive AI adoption with rigorous risk management across supply chains.
What we're watching
- AI Adoption
- The pace at which CISOs integrate AI tools for threat detection and monitoring will determine how quickly enterprises adapt to evolving cyber threats.
- Supply Chain Risk
- Whether organizations can extend risk controls beyond key suppliers to mitigate AI-related vulnerabilities from third-party partners.
- Regulatory Scrutiny
- How growing concerns over third-party AI access may prompt new compliance requirements for data security.
Related topics
