September 03, 2026
AI in Security: A Data-Driven Perspective
While nearly all organizations have added artificial intelligence as a means of threat detection, only a fraction are allowing automated responses or remediation.
The impact of artificial intelligence on cybersecurity over the past few years is undeniable — and it’s being used as a tool by both attackers and defenders.
CDW recently conducted a survey of more than 950 IT and security professionals to uncover the most pressing challenges they’re currently facing. The survey results — compiled in the report, “For Better or Worse, AI is Changing the Landscape for Cybersecurity” — confirmed that AI is the leading weapon on both sides.
For cybersecurity protection, 49% of respondents stated that they already use AI for threat and anomaly detection, and 47% use it for threat intelligence analysis. Surprisingly, only 7% say they don't use AI for defense at all, which means roughly 93% have AI somewhere in their defensive stack. AI has become table stakes for attackers and defenders alike in the span of a single product cycle.
AI-Powered Phishing and Malware Are Now the Top Threats — And Most Organizations Have Already Been Hit
The data from the survey shows it's not a perception problem, it's an experience problem. When we asked which single AI-enabled threat poses the greatest risk, AI-generated phishing and social engineering topped the list at 25%, with AI-powered malware second at 21%. Those aren't abstract fears.
In the same study, 43% of organizations reported experiencing AI-enhanced phishing attacks in the past 12 months, and 37% reported experiencing AI-powered malware. So, the two threats organizations name as most dangerous are the same two they're most likely to have already been hit by. That alignment between fear and lived experience is what makes this moment different.
In the current threat landscape, this is largely a phishing-and-malware arms race layered on top of very recognizable problems. When respondents were asked about their greatest overall security concern, data breaches (20%) and ransomware (16%) still top the list, while phishing, as a stand-alone overall concern, sits at just 7%.
Read together, that tells me organizations don't see AI phishing as a new category of risk; they see it as an accelerant that makes the breaches and ransomware they already fear faster, cheaper and more convincing. AI didn't invent the threat; it industrialized it.
Organizations Use AI for Defense, but Only 34% Have Tested Whether It Actually Works
Organizations are fighting back with AI too. But there's a real gap, and the survey results demonstrate it.
Adoption is broad but skewed toward the “watching” end of the spectrum and away from the “acting” end. The top AI defense uses are all detection and analysis: In addition to threat and anomaly detection and threat intelligence analysis, organizations are leveraging AI to spot phishing and fraud detection (42%). But automated incident response and remediation — letting AI take action — drops to 37%, and vulnerability management to 36%. Organizations trust AI to find things far more than they trust it to do things. That's a maturity signal: Early-stage AI defense augments human eyes; mature AI defense compresses the time between detection and containment. Most of the survey respondents are still in the first phase.
However, if you cross-reference these results with responses about staffing, the gap explains itself. Staffing and skills shortages are the No. 1 limit to cyber resilience (45%) and the No. 1 defense weakness (43%), and 24/7 threat monitoring is the single most challenging responsibility (26%). So, AI is being adopted first exactly where the people shortage hurts most — monitoring and triage. This isn't a considered maturity strategy; it's a staffing patch. A detection tool bolted onto an understaffed team without an automated response just relocates the bottleneck from “noticing” to “acting.” The capability gap isn't the real issue — it's the workflow around it.
The Fastest-Growing Security Gap: Deploying AI Agents Without Identity Controls or Adversarial Testing
When it comes to securing AI itself, the top step organizations have taken is employee training on secure AI use, at 45%. But only 34% have done adversarial testing or red-teaming of AI models.
That gap tells me organizations are securing the user of AI before they secure the AI itself — and that's backward from where the greatest risk lives. Look at the full ordering of steps taken to secure AI initiatives: training (45%), data protection controls (44%), integrating AI into existing monitoring (44%), AI-specific risk assessments (42%), governance policies (39%) — and then, dead last before “taking no steps,” adversarial testing or red-teaming at 34%. The pattern is unmistakable: The lower cost, human-centric, policy-based controls are on top; the technical, expertise-heavy validation is on the bottom.
You see the identical pattern in their mitigation strategy responses: 39% cited AI governance and use policies, but only 19% cited red-teaming and adversarial testing — the lowest actual strategy on the list. Training and policy are where everyone starts because they're accessible and they check a compliance box. Red-teaming is where far fewer go because it requires skills most teams don't have in-house.
Where should they start? Training is a defensible first move — you can't red-team your way out of an employee pasting confidential data into a public model. But it can't be the finish line. Pair every governance policy with at least one concrete test of whether it holds. A policy that's never been adversarially tested is a hope, not a control. The 11-point gap between training (45%) and testing (34%) is the difference between organizations that have written down what “secure AI” means and organizations that have actually checked.
Why Restricting AI Use Is Not the Answer
Shadow AI use by employees and agentic AI each ranked near the bottom of perceived threats, at 6% and 8%, respectively. But both represent growing risks that are hard to see from the inside.
Shadow AI and agentic AI share common traits: They're internal, and they're invisible. Every threat that ranked above them — AI phishing (25%), AI malware (21%), deepfakes (8%) — arrives from outside, where you're actively looking. Shadow AI and agentic sprawl grow inside the perimeter, driven by your own employees and your own productivity initiatives. People systematically underweight risks they can't see and that come from people they trust.
The survey shows the visibility gap concretely. Discovery of current AI agent instances — literally, knowing what agents you have — was done by only 37% of organizations. You cannot underestimate a threat more completely than by not knowing it's there. If almost two-thirds of organizations haven’t even inventoried their agents, the 8% who rank agentic AI as their top concern are, if anything, the ones paying attention.
Here’s an interesting tidbit. The report reveals a self-reinforcing loop: 23% of organizations say their strategy for mitigating AI threats is to limit or restrict AI adoption. Restriction is precisely what drives shadow AI underground; when sanctioned tools are blocked, employees don't stop using AI, they stop telling you about it. So, the very strategy that nearly a quarter of organizations lean on may be inflating the shadow AI risk they rank as trivial. These two threats are the clearest examples in the entire study of where organizations underestimate risks because they're hard to see — not because they're small.
For every organization treating restriction as the plan, roughly four are planning to expand AI's footprint. Restriction as a primary strategy isn't holding a line; it's standing still while the ground moves. The 39% pursuing formal AI governance policies are on a far more durable footing than the 23% pursuing restriction.
Learn how CDW helps organizations leverage AI as part of their cybersecurity posture.