Most Australian Businesses Are Adopting AI Faster Than They're Preparing to Respond to AI Incidents
New research from ISACA has found that just four percent of Australian organisations regularly run exercises to test how they would respond to an AI-related cybersecurity incident. The 2026 State of Cybersecurity report, based on responses from 1,888 cybersecurity professionals worldwide, also found that almost a third of organisations have never conducted any AI-related incident response exercises at all.
The gap is widening as AI use grows within security operations. Globally, 41 percent of respondents now use AI to automate threat detection and response, up from 32 percent last year, and 40 percent use it for routine security tasks, up from 28 percent. Yet nearly half of respondents either don't know if their organisation has AI incident response playbooks or confirm that none exist.
ISACA board vice chair Jamie Norton warned that businesses are moving faster to adopt AI than to prepare for what happens when something goes wrong. The most common scenarios covered in existing response exercises include sensitive data exposure through AI systems, AI-enabled phishing and fraud, and misuse of generative AI tools by staff. In Australia, 69 percent of cybersecurity professionals say their role has become more stressful over the past five years, and 58 percent report their teams are understaffed.