Information Systems Audit and Control Association’s (ISACA’s) 2026 State of Cybersecurity survey report found that only 21 per cent of organisations in India say they regularly conduct AI-specific response exercises and test their response to AI-driven cyber threats. 

The report, sponsored by Wolters Kluwer TeamMate, gathered responses from more than 1,800 global cybersecurity professionals, including 147 in India. The report explored trends in cybersecurity hiring, staffing, and budgets, while focusing on cyber risk and threats, cybersecurity operations, and the role of AI in cybersecurity work.

The report highlighted that nearly half (49 per cent) of enterprises in India have not conducted any AI-related incident response exercises, including top types cited by respondents like AI-enabled phishing, fraud or social engineering, AI-related incidents such as sensitive data exposure through AI systems, and unauthorised access to AI systems, models, or data.

Gaps in planning at enterprises also extend to AI incident playbooks. It has also been reported that over a third (35 per cent) of India-based respondents either don’t know whether their organisation has established them or mentioned that their organisation does not have them. This comes at a time when more Indian cybersecurity professionals are using AI at work. The report also observes that top uses of AI in cybersecurity in India include automating routine security tasks, automating threat detection or response and endpoint security. Thirty-four per cent of India-based respondents cite LLM SecOps as a skill gap among cybersecurity professionals, a 10-point increase from 2025.

“Many enterprises are automating threat detection and routine security work at a rapid pace, yet most still lack tested playbooks for AI-specific incidents like model tampering, data exposure, or AI-powered social engineering. As AI investment continues to scale across Indian organizations, closing the gap between adoption and preparedness is critical through regular incident exercises and dedicated LLM SecOps training. This needs to become a boardroom priority, not just a security issue,” remarked RV Raghu, ISACA Ambassador & Director, Versatilist Consulting India Pvt. Ltd.

Interestingly, as per the report, cybersecurity professionals in India are now even more hands-on with AI implementation and governance within their organisations, with more than half now involved in developing, onboarding or implementing AI solutions. Nearly half of them also said that they or someone from their team were involved in policy governing development for the use of AI in their organisation.

Work being more stressful today than five years ago has been highlighted as the main cause being the increasingly complex threat landscape. The report says that staffing struggles continue to impact cybersecurity teams, with work-life balance and hiring or retention challenges (49 per cent) coming up as additional key stressors in India. Around 42 per cent of Indian organisations believe their cybersecurity team is understaffed, with the majority of companies having positions for cybersecurity professionals.

The retention of cybersecurity professionals remains a challenge, with more than half of respondents reporting difficulties retaining qualified cybersecurity professionals. High work stress is now the leading reason people leave their roles, cited by 46 per cent, followed by limited promotion and development opportunities.

Cybersecurity teams in Indian companies are also working to remedy skills gaps among their staff. In addition to LLM SecOps, respondents cite soft skills, ML SecOps, scripting/automation and data security (36 per cent) as the biggest skills gaps they see.

In this AI era, human soft skills are still in demand, including critical thinking, problem solving, communication, teamwork (collaboration and cooperation) (46 per cent), and leadership (includes coaching, mentoring, people management, etc.

ISACA report also says that organisations are largely turning to online learning websites and mentoring to address nontechnical skills gaps. To address technical cybersecurity skills gaps, nearly half of the teams are increasing their reliance on AI or automation. They are also training non-security staff for security roles and increasing the use of contract employees or outside consultants for cybersecurity roles.

Disclaimer: Comments posted here are the sole responsibility of the user and do not reflect the views of THE WEEK. Obscene or offensive remarks against any person, religion, community or nation are punishable under IT rules and may invite legal action.