AI-Empowered Cybersecurity Adoption Surges, Governance Gaps Highlighted
A report released by the SANS Institute on Monday indicates that enterprise security teams are integrating AI into security programs at an unprecedented speed, but there is a significant gap in governance policies supporting this expansion. The survey shows that 40% of security practitioners report their organizations have no formal AI adoption policy, and over 60% cannot track where AI models are used or what types of information are exposed. About 75% of practitioners bear governance responsibilities related to enterprise AI, but more than half of respondents say they lack an established AI audit framework. Report author Matt Bromiley points out a 14-percentage-point perception gap between security leaders and frontline practitioners, reflecting the practical challenges of governance implementation.

Key Takeaways:
- Enterprise security teams are integrating AI into security programs at record speed, but there is a significant gap in governance policies supporting this expansion. This conclusion comes from a report released by the SANS Institute on Monday.report。
- The report shows that four in ten security practitioners say their organizationshave no formal AI adoption policy; more than six in ten practitioners say they have no visibility into where AI models are used or what types of information are exposed.
- About 75% of security practitioners have governance responsibilities related to enterprise AI, but more than half of respondents say there is no established AI audit framework.
Deep Dive:
The SANS report highlights a common concern among security and corporate governance experts: AI adoption is outpacing the installation of guardrails that should ensure customer data and other sensitive information are protected.
Report author and SANS Institute certified instructor Matt Bromiley noted a significant perception gap between security leaders and frontline practitioners who carry out the primary execution of security programs.
While half of security leaders say their organizations have formal AI risk management programs, only 36% of practitioners say they are aware of such programs.
"That 14-point gap is a perception problem," Bromiley told Cybersecurity Dive.
Bromiley said security leaders in the same program believe real governance exists, but "the people running the tools" do not see any reasonable safeguards in practical application.
The report is based on a survey of 536 cybersecurity and IT practitioners globally. SANS said the research included a special module of 57 senior security leaders, including CISOs, CSOs, and security vice presidents.
Previously, S&P warned that if companies fail to strengthen security governance,it could jeopardize their credit ratings。
The report also shows how AI adoption is changing the application of specific security practices. For example, six in ten practitioners say their programs use AI for red team testing, compared to just one-third a year ago.