Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Surveyed 200 CISOs/CTOs on securing AI: 93% are worried about the new risks, 15% think their tools can handle them (report + disclosure inside)

0
Low
Published: 08/11/2026 (08/11/2026, 20:59:17 UTC)
Source: Reddit Cybersecurity

Description

A survey of 200 US-based CISOs, CTOs, and other senior security leaders at large organizations reveals widespread concern about new security risks introduced by AI deployments. The majority (93%) are worried about these risks, but only a small fraction (15%) are confident their current security tools can handle them. Key issues include a growing attack surface driven by complex non-human identities and insufficient access controls for machine workloads. The survey highlights operational challenges such as lengthy network change management delays and a widening patch gap. Most organizations are actively exploring new approaches to secure non-human identities, as existing identity systems are largely deemed insufficient.

Reddit Discussion

r/cybersecurity·posted by u/AccordionGuy
00

In this survey, 200 US CTOs and CISOs were interviewed in May/June 2026, all of them working at 1,000+ employee orgs.

Before I continue: the disclaimer. I’m the developer advocate at NetFoundry, who commissioned this survey, which was conducted by Global Surveyz, an independent firm.

In the data: 93% of respondents are concerned about the new risks AI introduces, but only 15% are highly confident their current tools can handle them. 18% of the CTOs gave the “highly confident” answer, which 10% of CISOs said the same (that number should be smaller; CISOs are supposed to be more cautious). The people whose job is to stay skeptical are the least convinced, which either means the skepticism is doing its job or the tooling really isn't there. Probably both.

More data from the survey: vulnerability exploitation has overtaken credential abuse as the leading initial access vector (~31% of breaches), the disclosure-to-exploitation window is collapsing toward hours as attackers automate recon, and defenders went the other way: only 26% of CISA KEVs fully remediated in 2025, down from 38%, median time-to-patch up to 43 days. So the attack surface is growing (100% of respondents agreed it is; avg projected +14% over 12 months) at the same moment the patch gap is widening.

The lowest confidence happens around machine workloads. 69% named machine-to-machine / service / API connectivity as what they're least confident securing today, vs. 7% for human access. A decade of VPN/ZTNA investment made human access the comparatively solved problem; the non-human side never got the same identity foundation.

My read (inference, not a survey finding): most of the above rolls up to one thing: machines don't have real identities. As a result, org lean on proxies such as shared secrets and long-lived credentials, and visibility/access-control/audit all degrade from there. Only 8% called their identity systems “very sufficient” for non-human workloads; 85% are now evaluating or exploring alternatives. NetFoundry has a horse in that race and the report says so; take that part with whatever salt you like. The measured findings stand on their own.

Here’s the report: https://info.netfoundry.io/lp-survey-august-2026

For the defenders here actually patching under this timeline: does the 43-day median match your reality, or is that generous for anything that isn't a headline CVE?

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 11:41:16 UTC

Technical Analysis

This survey-based report captures the perspectives of 200 senior security and technology leaders at organizations with over 1,000 employees regarding AI security risks. It finds that 93% of respondents are concerned about new risks from AI deployments, but only 15% have high confidence in their current security stacks to protect AI workloads. The report identifies machine-to-machine and API connectivity as the least secure areas, with only 8% rating their identity systems as very sufficient for non-human workloads. The attack surface is expanding, with vulnerability exploitation overtaking credential abuse as the leading initial access vector. Operationally, network change management processes introduce significant delays, averaging 8 days per request, contributing to slower deployment and patching cycles. The core challenge is the lack of robust non-human identity frameworks, leading to reliance on shared secrets and long-lived credentials, which degrade security controls. Consequently, 85% of organizations are evaluating new solutions to address these gaps.

Potential Impact

The survey indicates a growing security risk landscape driven by AI deployments, particularly due to insufficient identity and access controls for non-human workloads. The expanding attack surface and slower patching timelines increase exposure to exploitation. The lack of confidence in current security tools suggests organizations may be vulnerable to attacks targeting AI infrastructure and machine-to-machine communications. Operational delays in network change management further hinder timely security updates and risk mitigation.

Defensive Guidance

This is a survey report and does not describe a specific vulnerability or exploit requiring immediate patching. Organizations should consider evaluating and adopting improved identity and access management solutions tailored for non-human workloads, as 85% of respondents are doing. Addressing operational bottlenecks in network change management and accelerating patching processes can also help reduce exposure. No official patches or fixes are applicable as this is an industry-wide risk assessment rather than a discrete vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a7c5bd2bf8831d539798815

Added to database: 08/12/2026, 11:41:06 UTC

Last enriched: 08/12/2026, 11:41:16 UTC

Last updated: 08/12/2026, 18:11:12 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses