Surveyed 200 CISOs/CTOs on securing AI: 93% are worried about the new risks, 15% think their tools can handle them (report + disclosure inside)
A survey of 200 US-based CISOs, CTOs, and other senior security leaders at large organizations reveals widespread concern about new security risks introduced by AI deployments. The majority (93%) are worried about these risks, but only a small fraction (15%) are confident their current security tools can handle them. Key issues include a growing attack surface driven by complex non-human identities and insufficient access controls for machine workloads. The survey highlights operational challenges such as lengthy network change management delays and a widening patch gap. Most organizations are actively exploring new approaches to secure non-human identities, as existing identity systems are largely deemed insufficient.
AI Analysis
Technical Summary
This survey-based report captures the perspectives of 200 senior security and technology leaders at organizations with over 1,000 employees regarding AI security risks. It finds that 93% of respondents are concerned about new risks from AI deployments, but only 15% have high confidence in their current security stacks to protect AI workloads. The report identifies machine-to-machine and API connectivity as the least secure areas, with only 8% rating their identity systems as very sufficient for non-human workloads. The attack surface is expanding, with vulnerability exploitation overtaking credential abuse as the leading initial access vector. Operationally, network change management processes introduce significant delays, averaging 8 days per request, contributing to slower deployment and patching cycles. The core challenge is the lack of robust non-human identity frameworks, leading to reliance on shared secrets and long-lived credentials, which degrade security controls. Consequently, 85% of organizations are evaluating new solutions to address these gaps.
Potential Impact
The survey indicates a growing security risk landscape driven by AI deployments, particularly due to insufficient identity and access controls for non-human workloads. The expanding attack surface and slower patching timelines increase exposure to exploitation. The lack of confidence in current security tools suggests organizations may be vulnerable to attacks targeting AI infrastructure and machine-to-machine communications. Operational delays in network change management further hinder timely security updates and risk mitigation.
Mitigation Recommendations
This is a survey report and does not describe a specific vulnerability or exploit requiring immediate patching. Organizations should consider evaluating and adopting improved identity and access management solutions tailored for non-human workloads, as 85% of respondents are doing. Addressing operational bottlenecks in network change management and accelerating patching processes can also help reduce exposure. No official patches or fixes are applicable as this is an industry-wide risk assessment rather than a discrete vulnerability.
Surveyed 200 CISOs/CTOs on securing AI: 93% are worried about the new risks, 15% think their tools can handle them (report + disclosure inside)
Description
A survey of 200 US-based CISOs, CTOs, and other senior security leaders at large organizations reveals widespread concern about new security risks introduced by AI deployments. The majority (93%) are worried about these risks, but only a small fraction (15%) are confident their current security tools can handle them. Key issues include a growing attack surface driven by complex non-human identities and insufficient access controls for machine workloads. The survey highlights operational challenges such as lengthy network change management delays and a widening patch gap. Most organizations are actively exploring new approaches to secure non-human identities, as existing identity systems are largely deemed insufficient.
Reddit Discussion
In this survey, 200 US CTOs and CISOs were interviewed in May/June 2026, all of them working at 1,000+ employee orgs.
Before I continue: the disclaimer. I’m the developer advocate at NetFoundry, who commissioned this survey, which was conducted by Global Surveyz, an independent firm.
In the data: 93% of respondents are concerned about the new risks AI introduces, but only 15% are highly confident their current tools can handle them. 18% of the CTOs gave the “highly confident” answer, which 10% of CISOs said the same (that number should be smaller; CISOs are supposed to be more cautious). The people whose job is to stay skeptical are the least convinced, which either means the skepticism is doing its job or the tooling really isn't there. Probably both.
More data from the survey: vulnerability exploitation has overtaken credential abuse as the leading initial access vector (~31% of breaches), the disclosure-to-exploitation window is collapsing toward hours as attackers automate recon, and defenders went the other way: only 26% of CISA KEVs fully remediated in 2025, down from 38%, median time-to-patch up to 43 days. So the attack surface is growing (100% of respondents agreed it is; avg projected +14% over 12 months) at the same moment the patch gap is widening.
The lowest confidence happens around machine workloads. 69% named machine-to-machine / service / API connectivity as what they're least confident securing today, vs. 7% for human access. A decade of VPN/ZTNA investment made human access the comparatively solved problem; the non-human side never got the same identity foundation.
My read (inference, not a survey finding): most of the above rolls up to one thing: machines don't have real identities. As a result, org lean on proxies such as shared secrets and long-lived credentials, and visibility/access-control/audit all degrade from there. Only 8% called their identity systems “very sufficient” for non-human workloads; 85% are now evaluating or exploring alternatives. NetFoundry has a horse in that race and the report says so; take that part with whatever salt you like. The measured findings stand on their own.
Here’s the report: https://info.netfoundry.io/lp-survey-august-2026
For the defenders here actually patching under this timeline: does the 43-day median match your reality, or is that generous for anything that isn't a headline CVE?
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This survey-based report captures the perspectives of 200 senior security and technology leaders at organizations with over 1,000 employees regarding AI security risks. It finds that 93% of respondents are concerned about new risks from AI deployments, but only 15% have high confidence in their current security stacks to protect AI workloads. The report identifies machine-to-machine and API connectivity as the least secure areas, with only 8% rating their identity systems as very sufficient for non-human workloads. The attack surface is expanding, with vulnerability exploitation overtaking credential abuse as the leading initial access vector. Operationally, network change management processes introduce significant delays, averaging 8 days per request, contributing to slower deployment and patching cycles. The core challenge is the lack of robust non-human identity frameworks, leading to reliance on shared secrets and long-lived credentials, which degrade security controls. Consequently, 85% of organizations are evaluating new solutions to address these gaps.
Potential Impact
The survey indicates a growing security risk landscape driven by AI deployments, particularly due to insufficient identity and access controls for non-human workloads. The expanding attack surface and slower patching timelines increase exposure to exploitation. The lack of confidence in current security tools suggests organizations may be vulnerable to attacks targeting AI infrastructure and machine-to-machine communications. Operational delays in network change management further hinder timely security updates and risk mitigation.
Defensive Guidance
This is a survey report and does not describe a specific vulnerability or exploit requiring immediate patching. Organizations should consider evaluating and adopting improved identity and access management solutions tailored for non-human workloads, as 85% of respondents are doing. Addressing operational bottlenecks in network change management and accelerating patching processes can also help reduce exposure. No official patches or fixes are applicable as this is an industry-wide risk assessment rather than a discrete vulnerability.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a7c5bd2bf8831d539798815
Added to database: 08/12/2026, 11:41:06 UTC
Last enriched: 08/12/2026, 11:41:16 UTC
Last updated: 08/12/2026, 18:11:12 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.