Organizations Face a Growing Gap Between Cyber Risks and Security Resources

Cyberattacks are increasing faster than security staffing and funding, putting additional pressure on cybersecurity teams and resilience efforts.

Microsoft Security image

Key Takeaways:

  • More than one-third of surveyed professionals reported an increase in cyberattacks over the past year.
  • Many cybersecurity teams face staffing shortages, limited funding, and rising burnout risks.
  • The report recommends combining cybersecurity investments with AI governance, workforce development, and resilience planning.

A new ISACA study found that cybersecurity teams are struggling to keep up with a growing volume of attacks while facing limited resources. More than a third of European IT and security professionals reported an increase in cyberattacks over the past year, yet many organizations continue to operate with insufficient staffing and funding.

According to the report, cyber teams are dealing with increasingly sophisticated threats, including AI-assisted social engineering campaigns. This gap between rising threats and available resources is placing significant pressure on security professionals.

Most respondents mentioned their jobs have become more stressful over the past five years. This study cited the growing complexity of the threat landscape, heavy workloads, and skills shortages. Burnout risks remain high, and many organizations have not implemented measures to address employee well-being. Meanwhile, cyberattacks are expected to keep increasing, raising concerns that understaffed teams may struggle to respond effectively to future incidents.

What business leaders should do next to strengthen cybersecurity preparedness?

Organizations should move beyond a reactive approach to cybersecurity and invest more consistently in resilience. This means allocating resources to cybersecurity staffing, skills development, and training programs so that security teams are better equipped to handle a growing volume of threats. This research also suggests that cybersecurity preparedness should become a leadership priority, with executives ensuring that funding decisions support prevention and long-term risk reduction.

This report also recommends that organizations strengthen their approach to artificial intelligence. It suggests that AI can help automate threat detection, response activities, and routine security operations, but businesses should pair adoption with formal governance and planning.

This includes creating policies for AI use, establishing oversight mechanisms, and conducting AI-specific incident response exercises to prepare for scenarios such as AI-enabled phishing, data exposure, or misuse of generative AI tools. Organizations can benefit from AI-powered security capabilities, but only if they develop the processes and governance needed to manage the new risks that come with the technology.