Briefing at a Glance

  • The latest report finds that AI has not made the work of cybersecurity professionals much easier, and companies often lack a clear AI strategy when increasing AI investment.
  • Additionally, according to a joint release by the Information Systems Security Association (ISSA) and Omdia,the latest cybersecurity workforce surveynearly 70% of cybersecurity practitioners said that despite the rise of AI automation, their work has become more difficult over the past two years.
  • A quarter of respondents said their companies increased AI spending without clearly defining how to integrate these AI tools into existing processes.

In-Depth Insights

The report shows that more than 80% of organizations areusing AI for cybersecurity tasksor plan to adopt it soon, with half of users using it for penetration testing and vulnerability scanning, nearly half for risk prediction, and 38% for threat detection.

However, these tools cannot fully replace skilled cybersecurity professionals. Currently, as the threat environment becomes increasingly severe, the workforce primarily responsible for defending enterprise networks is facing burnout and low morale.

ISSA and Omdia found that nearly half of cybersecurity practitioners are considering leaving their jobs, with 17% saying they often think about it and 30% saying they occasionally do. More than half said they are considering leaving the industry entirely, with 20% having this thought frequently.

The main causes of burnout include high stress (53%), lack of career advancement opportunities (37%), work-life imbalance (34%), and insufficient leadership commitment to organizational cybersecurity (33%).

This burnout exacerbates the already massive nationalcybersecurity skills gap, making it harder for companies to ensure cybersecurity. Three-quarters of respondents said the skills shortage has impacted their organizations, with 23% saying the impact is significant.

The skills shortagehas led to a series of consequences. 44% of respondents said colleagues were forced to shift from strategic, long-term work to emergency response due to no one handling crises; a similar proportion mentioned increased workload (42%) and heightened burnout (37%).

Meanwhile, only 29% of respondents rated their organization's cybersecurity culture as "advanced," while half rated it as "average." Respondents identified employee training, resource investment, and governance improvements as the top measures to enhance cybersecurity programs.

The ISSA and Omdia survey is based on interviews with 380 IT and cybersecurity professionals conducted from January to February 2026.

Disclosure: Informa holds a controlling stake in Informa TechTarget, which is the publisher of CIO Dive and the parent company of Omdia. Informa has no influence over CIO Dive's editorial content.