Technology
Cyber Budgets To Rise As AI Threats Grow – PwC Survey

The firm's Survey of 71 countries found that 84 per cent of respondents expect cyber spending to rise and half of security leaders feel least prepared for attacks on AI systems.
A survey of 3,934 business and tech executives across 71
countries and territories has found that 84 per cent of security
and finance leaders expect their cyber budgets to increase, up
from 78 per cent last year. The study is from PwC in its 2027
Global Digital Trust Insights Survey.
AI tops the spending agenda, with 58 per cent of security leaders
ranking it among their top cyber budget priorities for the year
ahead. Yet half say attacks targeting AI systems are the threat
they are least prepared to address. That puts AI ahead of
cloud-related threats (40 per cent), third-party breaches (34 per
cent) and ransomware (33 per cent).
As readers of this news service know, cybersecurity is a major
concern, given the desire of criminals and other hostile actors
to target wealthy individuals and those who serve them. For
example, in early August, the tiny principality of Liechtenstein revealed
that registers of beneficial ownership had been attacked by
hackers. Family offices are already feeling the impact of
weak cybersecurity. Last year, a survey by Deloitte, the
accountancy and professional services giant, found that almost
half (43 per cent) of family offices around the world (a sector
estimated to hold more than $3 trillion in total
AuM) suffered a cyberattack in the previous two
years.
The cross-sector survey found gaps in basic resilience.
Organisations have implemented, on average, three of seven key
data-risk measures, and only 5 per cent have implemented all
of them, down from 7 per cent. Fewer than two in five (39
per cent) of security, risk and operations leaders have a
fully-formalised operational continuity plan that specifically
addresses cyber risk.
Governance lags too. A third of chief executive officers and
security and risk leaders say their firms have created dedicated
AI roles, such as a chief AI officer or an AI board. Fewer than
half strongly agree that cyber risk is a standing agenda item for
the board (47 per cent) or at executive leadership meetings (45
per cent).
Among AI-enabled attacks, leaders feel least prepared for
compromise by autonomous botnets (53 per cent), adversarial
attacks (52 per cent) and data poisoning (52 per cent). They are
wary of handing defence to machines. Only 22 per cent would
authorise fully autonomous execution by AI agents for cyber
defence. The main barriers cited are the reliability and maturity
of the technology (55 per cent) and accountability and
explainability (46 per cent). Some 44 per cent of chief
information security officers point to a shortage of skills in AI
oversight and governance.
Firms are responding by spreading concentration risk. Over half
(54 per cent) are adopting multi-cloud or hybrid cloud
strategies, 47 per cent are strengthening regional data and
technology redundancy, and 37 per cent are localising
infrastructure within specific jurisdictions. Half are changing
the way they manage vendor, third-party and supply chain
risk in response to geopolitics.
“AI is changing both sides of the cyber equation. It is creating
new risks and expanding the attack surface, but it can also
transform how organisations defend themselves,” said Avinash
Rajeev, global cyber, data and tech risk leader at PwC US.
For financial firms in the EU, third-party and concentration risk
is also a compliance matter. The Digital Operational Resilience
Act, or DORA, has applied since January 2025, requiring firms to
manage information and communication technology third-party risk
and report major incidents.