Summary
- Thirty-eight per cent of European respondents reported more cyberattacks than a year earlier.
- Fifty-six per cent described their teams as understaffed, while 55% said they were underfunded.
- AI is entering defensive operations while AI-specific incident-response maturity remains comparatively weak.
European cybersecurity teams are facing rising attack volumes without a corresponding expansion in people or budgets, according to new ISACA research that exposes a widening gap between the technology organisations are expected to defend and the resources available to defend it.
Among 494 European cybersecurity professionals included in ISACA’s 2026 State of Cybersecurity research, 38% said their organisation was experiencing more cyberattacks than a year earlier. At the same time, 56% described their teams as understaffed and 55% as underfunded.
The pressure is also showing up in working conditions. Seventy-two per cent said cybersecurity work was more stressful than five years ago, with the changing threat environment, workload, and expectations contributing to the increase.
Cybersecurity staffing therefore becomes an operational-resilience problem as well as a recruitment issue. Organisations can buy another detection platform comparatively quickly, but experienced analysts, incident responders, security architects, and identity specialists take longer to develop or recruit.
More tooling does not remove the workload
Security spending has expanded substantially over the past decade, yet much of that investment has created additional systems for teams to operate. Security operations can ingest alerts from endpoints, identity platforms, cloud infrastructure, email, networks, applications, and third parties, leaving analysts to decide which events represent genuine threats.
AI is beginning to automate parts of that work. ISACA reports that 37% of organisations in its research now use AI for threat detection and response, while 35% use it for routine security tasks and 29% for endpoint security.
Cyber teams are also becoming involved in enterprise AI governance outside their conventional defensive role, adding policy, onboarding, and implementation work at the same time that cloud platforms, software supply chains, identity systems, and AI applications broaden the estate they have to protect.
AI creates work on both sides
Social engineering was the most commonly cited attack category among European respondents, while cybercriminals and hackers remained prominent threat actors. AI can reduce the effort involved in producing tailored phishing, impersonation, and fraudulent communications, while defenders are adopting the same technology for detection and automation.
Preparedness for incidents involving AI itself remains thinner. ISACA’s research indicates that most organisations surveyed had not conducted AI-specific response exercises, while mature formal runbooks remained uncommon.
That gap becomes more serious as organisations connect AI tools to sensitive data and internal services. A security team may have mature procedures for a compromised user account while lacking an established response to an agent operating beyond its intended permissions or an employee exposing confidential information through an AI platform.
Workforce resilience becomes cyber resilience
Chronic understaffing can weaken preventative work because analysts dealing with continuous alerts have less time for exercises, control improvement, supplier reviews, architecture, and threat hunting.
Burnout creates a retention problem as well. Experienced staff accumulate detailed knowledge about systems, exceptions, suppliers, and operational habits that is difficult to replace simply by filling a vacancy.
Automation can help where it removes repetitive investigation or enriches alerts, but automated systems still require configuration, monitoring, governance, and maintenance. Poorly designed tooling can simply create another machine-generated queue for the same constrained team to process.
ISACA’s respondents do not represent every European organisation, but the combination of higher reported attack volumes, resource constraints, and sustained stress argues against treating cyber capacity as a matter of tooling alone.
Resilience depends on whether organisations can preserve the human capacity to understand incidents, rehearse failures, and improve architecture before the next urgent problem arrives.












