Cybersecurity budgets are growing fast, AI threats are growing faster

Articles & Reports
 |  
Aug 2026
 |  
BCG
Save to favorites
Your item is now saved. It can take a few minutes to sync into your saved list.

What: CISOs report that AI is simultaneously expanding the cyberattack surface and powering new defense capabilities, while most organizations still lack mature AI-specific security controls.

Why it is important: With 89% of organizations already reporting AI-enabled attacks and most having adopted only minimal AI-specific controls, retailers face a widening gap between AI-driven risk and their own readiness to manage it.

BCG and GLG's latest CISO survey (N=302) finds cybersecurity spending continuing to outpace projections, with a 12% increase expected in 2026 after an actual 8% increase in 2025. Cloud and data security categories are seeing the steepest planned increases, alongside managed security services and threat intelligence.

AI adoption is the dominant driver: 49% of CISOs expect AI to increase spend in the near term before growth normalizes, and 15% expect sustained acceleration. AI is reshaping the threat landscape on three fronts simultaneously — it is expanding the attack surface for builders, arming attackers with faster and more scalable tools, and powering new defensive capabilities. Nearly nine in ten organizations report experiencing AI-enabled attacks, over a third with significant operational or financial impact, while the average organization logs 25 incidents a year of sensitive data leaking to GenAI tools.

Despite this, adoption of AI-specific security controls remains low. Only 18 of 70 surveyed practitioners report high control adoption (seven or more active measures), though that group shows markedly better outcomes in mitigating AI-driven threats than low-adoption peers.

IADS Notes:  The trend the BCG survey documents — AI simultaneously expanding retail's attack surface and reshaping how it defends itself — sits alongside a body of recent coverage on the same dynamic. AI-enabled hacking is already moving from sandboxed test escapes to state-linked actors weaponizing models for data theft, a shift Bloomberg reported on in August 2026, which also traced the operational cost retailers have already absorbed through the Marks & Spencer and Co-op incidents. The governance gap this creates is a recurring theme: an August 2026 piece from RH-ISAC warned that autonomous AI agents now execute refunds, loyalty adjustments, and access changes without the ownership and auditability traditional security models require. Retail's structural exposure predates the AI-specific risk, though — Retail Insight Network's analysis from July 2026 attributes the sector's attractiveness to attackers to its combination of valuable customer data and interconnected omnichannel systems, naming AI-enabled attacks alongside ransomware and loyalty fraud as a growing vector. The financial stakes of getting this wrong are concrete: Inside Retail's coverage from August 2026 showed Coupang swinging to a quarterly loss after a roughly $410 million penalty tied to a breach affecting more than 33 million customer records.

Cybersecurity budgets are growing fast, AI threats are growing faster