Decoding the world of cybersecurity

Cyber budgets rise as continuity lags

PwC says 84% of surveyed security and finance leaders expect cyber budgets to rise, while only 39% report a fully formalised cyber-specific continuity plan.

Cyber budgets rise as continuity lags
Summary
  • 84% of surveyed leaders expect cyber budgets to increase over the next 12 months.
  • Only 39% report a fully formalised operational continuity plan specifically addressing cyber risk.
  • Half identify attacks against AI systems among the threats they feel least prepared to address.

Cyber security spending is continuing to rise, but organisations are not translating that investment into the same level of operational preparation, according to PwC’s latest global survey of business, technology, security, and finance leaders.

PwC said 84% of respondents to its 2027 Global Digital Trust Insights Survey expect cyber budgets to increase during the next 12 months, up from 78% a year earlier. AI has become a significant spending driver, with 58% placing it among their leading cyber-budget priorities.

Yet only 39% said their organisation has a fully formalised and operational continuity plan that specifically addresses cyber risk. Less than half — 47% — strongly agreed that cyber risk is a standing item on the board agenda.

The gap between budget growth and operational preparation becomes more consequential as organisations deploy more AI systems. Half of respondents identified attacks targeting AI systems among the cyber threats they felt least prepared to address, while 22% said they would authorise fully autonomous AI agents to conduct cyber defence.

The survey captured the views of 3,934 business and technology executives across 71 countries and territories. Its findings are self-reported rather than an independently tested measure of organisational capability, and definitions such as a “fully formalised” continuity plan can vary between respondents.

Even with those limits, the contrast between spending expectations and preparedness indicators points to a recurring governance problem. Cyber budgets cover tools, staffing, managed services, consulting, compliance, and transformation projects. Continuity depends on how technology, business operations, suppliers, crisis management, and executive decision-making function when preventive controls fail.

That difference explains how spending can rise without producing equivalent resilience. A stronger security stack may reduce the likelihood or duration of some incidents, but operational continuity also requires recovery priorities, tested dependencies, clear authority, communications, and workable alternatives when systems are degraded.

Regulation is increasingly making that distinction explicit. DORA requires financial entities in the EU to treat digital operational resilience as an ongoing governance discipline, while NIS2 places wider management and risk-management obligations on essential and important entities.

Those frameworks do not measure maturity by budget alone. They place greater weight on governance, incident handling, business continuity, testing, supplier dependencies, and evidence that important services can be sustained or restored.

AI adoption adds another layer because frontier models are entering software development, customer operations, knowledge work, and cyber security itself. New deployments can create dependencies on model providers, data sources, external APIs, identity systems, and automated decision paths that may not yet appear in existing continuity plans.

The board figure also points to a gap between security investment and routine governance. A standing agenda item does not guarantee strong oversight, but inconsistent executive attention can make it harder to connect security expenditure with recovery priorities and organisational tolerance for disruption.

PwC’s results therefore present two different measures of cyber commitment. Organisations appear increasingly willing to spend, while a considerably smaller proportion describe themselves as having formalised operational continuity specifically for cyber risk.

As AI deployment expands, that mismatch is likely to become more visible. Additional security technology can improve detection and response, but it cannot replace decisions about which services must continue, how dependencies will fail, who has authority during disruption, and how operations will be restored.

×