This report outlines how AI-driven threats are reshaping cybersecurity and why organizations must shift from reactive controls to intelligence-driven resilience.
More than 80% of organizations reported an increase in AI-enabled attacks, with AI-driven social engineering now surpassing ransomware as the top threat. Despite this, confidence remains uneven: while 85% of leaders report strong cyber resilience, only 59% of CISOs feel confident in third-party visibility compared to 79% of non-security peers.
The playbook identifies a critical paradox: organizations are rapidly adopting AI, yet lack the governance, visibility, and expertise needed to manage AI-driven risks. AI governance gaps are the top concern for 42% of CISOs, who fear permissive policies will accelerate impersonation and identity-based attacks. Meanwhile, AI security expertise is the number-one resource constraint, limiting organizations’ ability to operationalize defenses.
The report provides five steps to strengthen resilience: establishing clear AI governance frameworks; improving visibility into third-party AI risk; maturing cyber risk quantification practices; investing in AI security training; and strengthening defenses against AI-enabled social engineering and ransomware. It highlights that 34% of organizations experienced a third-party or supply chain incident, and 69% saw an increase year-over-year.
Ultimately, the playbook argues that cyber resilience in the AI era requires treating security as an enterprise capability—not just a technical function. Organizations must align leadership, governance, and expertise to keep pace with rapidly evolving AI-driven threats.