Skip to main content

AI didn’t just accelerate threats. It exposed the old security model.

Cybersecurity operating models built for slower, manual environments are struggling to keep pace with AI-driven cyber threats, identity-based risk, and real-time attack patterns—forcing CISOs to rethink how detection, response, and governance must perform at scale. 

Arrows

Why cybersecurity operating models—not tools—are now the limiting factor in enterprise cyber resilience

There is a tendency in cybersecurity to interpret every shift in the threat landscape as a problem of capability. New attack techniques emerge, new tooling follows, and the program expands. That pattern has held for years.

What AI has introduced is something different. It hasn’t just changed what organizations are defending against; it has changed the conditions under which defense must operate. And when those conditions change, the effectiveness of a security program is determined less by what it includes and more by how it behaves.

That distinction is becoming difficult to ignore.

What’s changing in enterprise cyber risk right now

  • 8 in 10 organizations report increased cyberattacks in the past year
  • Most experience multiple breaches across phishing, Distributed Denial of Service (DDoS), and ransomware
  • More than half report productivity impact from cyber incidents
  • Only 24% have fully integrated AI into cybersecurity

Across large enterprises, there is a growing recognition that many cybersecurity programs are not failing because they lack coverage. They are struggling because the system that connects detection, decision-making, response, and governance is not designed to perform under the speed and variability that now defines the environment.

AI didn’t create that limitation. It removed the space that used to compensate for it. AI didn’t just accelerate attacks. It eliminated the margin for error that legacy security models quietly relied on. What once felt like operational friction is now in danger of becoming structural failure at AI speed.

AI is compressing cyber response timelines in ways most security programs were never designed to handle

The most visible effect of AI is acceleration—faster phishing, faster reconnaissance, faster exploitation. That framing is accurate, but it misses the more consequential impact: AI is compressing the time between signal and consequence.

In a traditional environment, there was enough separation between detection and impact that organizations could rely on manual escalation, cross-team coordination, and expert judgment to fill in gaps. Even when processes were imperfect, the system could compensate.

That buffer is fading.

Signals now emerge in higher volume, with greater variation, and often with less clarity about their relevance. At the same time, the business is introducing new forms of exposure through AI-enabled workflows, machine-to-machine interactions, and increasingly fluid identity boundaries. This includes the supply chain, where dependencies on cloud platforms, SaaS providers, and hundreds of third, fourth, and fifth parties have extended the attack surface well beyond the traditional enterprise perimeter. As organizations are under threat from actors eager to steal intellectual property and disrupt operations, a failure to manage this interconnected ecosystem introduces significant risk.¹ The net effect is not just more risk, it is a faster cycle of exposure, detection, and potential impact.

This is where the strain begins to show.

This shift is already showing up in how organizations experience cyber risk. Eight in ten organizations report an increase in cyberattacks over the past 12 months, with most experiencing multiple incidents across phishing, denial-of-service, and ransomware.² At the same time, more than half report that these attacks are already affecting productivity, turning cyber events into operational disruptions, not just security issues. reinforces the scale of this shift. AI-powered attacks are expected to become the top cyber threat in the next several years, while only a minority of organizations have fully integrated AI into their security operations. At the same time, a substantial portion of cybersecurity budgets is already being directed toward AI-related capabilities.

That combination of rising investment, partial integration, and accelerating threat dynamics points to something more fundamental than a technology gap. It points to an execution gap. For many CISOs, the challenge is no longer whether threats can be detected fast enough, but whether the organization can consistently decide and act at speed when it matters most.

The cyber gap that matters most now sits between visibility and action

Most large organizations no longer struggle to see what is happening in their environments. Telemetry has improved dramatically. Coverage has expanded across endpoints, cloud platforms, applications, and identities. In many respects, visibility is no longer the constraint it once was.

That restriction now resides somewhere between:

  • What the organization can observe, and
  • How consistently it can interpret, prioritize, and act on those observations

This is not a theoretical distinction. It materializes in ways that are familiar but rarely connected within a single problem statement.

Detection capabilities surface issues quickly, but prioritization still varies depending on context and experience. Response procedures are documented, but execution differs across teams and scenarios. Identity controls are deployed but often operate in cycles that do not reflect how access actually changes in real time. Governance frameworks exist, but they are frequently retrospective rather than embedded into operational decision-making.

None of these issues are new. What has changed, however, is the environment’s tolerance for them.

When signals arrive faster and consequences emerge more quickly, inconsistency becomes risk. Variability becomes exposure. And the ability of the system to perform under pressure becomes the defining factor. This is also why many organizations are starting to measure cybersecurity differently. Across industries, leaders are increasingly relying on metrics like coincident volume, vulnerability remediation rates, and mean time to deflect – not as reporting artifacts, but as indicators of whether their security program can perform consistently at scale.³

These are no longer process inefficiencies. They are direct contributors—materializing at AI speed—to delayed containment, an expanded blast radius, and erosion of board confidence. These concerns are far from abstract. Security leaders are recognizing that sophisticated threats directly jeopardize their core business models, citing reduced productivity, the erosion of customer trust, intellectual property theft, and supply chain disruptions as the most severe consequences of a breach.

AI is amplifying both threat volume and operating model weaknesses

It is natural to respond to AI-driven threats by accelerating the adoption of AI-driven defense. Many organizations are doing exactly that, and it is a necessary step.

What has become apparent, however, is that AI does not operate in isolation. Its effectiveness is determined by the system into which it is introduced. In a fragmented operating model, AI tends to amplify the characteristics that already exist. Where workflows are inconsistent, it can accelerate inconsistency. Where data is disconnected, it can increase noise. Where governance is unclear, it can introduce new ambiguity into decision-making.

In this sense, AI is not just a new, rapidly evolving capability. It is a stress test for the overarching security operating model itself.

This is why some organizations have experienced diminishing returns from early AI investments. The issue is not that AI lacks value as a cybersecurity tool; it is that the surrounding system is not yet structured to use it effectively.

By contrast, organizations that are seeing stronger outcomes are approaching AI differently. They are not simply adding it to the environment; they are integrating it into how the environment operates. Detection, prioritization, and response are connected through defined workflows. Identity is treated as a continuously monitored system, not a static control set. Governance is embedded into operations so decisions can be explained and defended as they are made. In those environments, AI enhances performance because it is aligned with a model that is designed for consistency.

The shift from cybersecurity capability to cybersecurity performance

This is where the conversation is beginning to change among more advanced cyber programs. Historically, cybersecurity programs have been evaluated based on capability: the presence of controls, the breadth of coverage, the sophistication of tools. Those dimensions still matter, but they are no longer sufficient to explain how a program will perform when it is under pressure.

The more relevant lens is performance. Performance, in this context, is not about speed alone. It is about the reliability of outcomes:

1

How consistently the organization can detect meaningful threats

2

How predictably it can contain and respond to incidents

3

How clearly it can demonstrate control effectiveness and governance

4

How well it can support the business without introducing unmanaged exposure

This shift from capability to performance is subtle, but critical. It reframes cybersecurity from a collection of components into a system whose effectiveness depends on how those components interact.

Once cybersecurity is viewed through a performance lens, the question shifts from “What do we have?” to “Where does variability still exist and why?”

What changes when cybersecurity is designed as a system rather than a collection of tools

When organizations begin to treat cybersecurity as a system, several changes follow:

01
Identity

becomes more than an access management function. It becomes the control plane that determines how risk moves through the environment. Access is not only granted and revoked; it is continuously understood and governed in context.

02
Detection and response

are no longer separate domains. They are part of a continuous workflow that reflects how incidents unfold in practice. This shifts the focus from simple vendor compliance to active resilience, identifying and prioritizing vulnerabilities across the entire ecosystem—including the supply chain—to prevent attacks before they happen.⁵ The goal is not simply to detect faster, but to ensure that detection leads to consistent, effective action.

03
Governance

shifts from a retrospective activity to an embedded capability. Instead of asking whether controls were followed after the fact, the system is designed to ensure control behavior is visible and defensible as decisions are made.

AI, within this model, is not a standalone capability. It becomes a way to improve how the system functions, accelerating analysis, reducing noise, and supporting decision-making within a structured framework.

This is not a theoretical ideal. It is the direction in which organizations are moving as they try to reconcile increasing complexity with the need for consistent outcomes.

Why this moment creates a strategic opportunity for CISOs

It is easy to frame the current environment as strictly a defensive battle as organizations experience more threats, more pressure, and more complexity. But that is only part of the story.

The same forces that are exposing the limitations of legacy frameworks are also making it easier to identify what needs to change.

Organizations that have advanced their cybersecurity operating models are already seeing materially different outcomes. Higher-maturity organizations are nearly twice as likely to report no security breaches and significantly less likely to experience repeated or severe incidents. These improvements are not driven by awareness alone, they reflect how consistently organizations can execute detection, response, and governance under pressure.

What differentiates these organizations is not simply awareness. It is the way their programs are structured to perform.

For CISOs, this creates a clearer path forward. Instead of trying to incrementally improve every part of the program, the focus can shift to how the program operates as a whole. Where are decisions made? How are they executed? What introduces variability? What creates delay?

Answering those questions leads security teams to focus directly on the elements of the system that matter most.

Cybersecurity at AI speed requires a different kind of design

The environment has changed in a way that makes one thing increasingly clear: cybersecurity performance is no longer a byproduct of effort. It is a function of design.

Programs that continue to evolve primarily by adding tools or expanding coverage will find it difficult to keep pace, not because those investments are wrong, but because they do not address how the system behaves under pressure.

By contrast, programs that continually evaluate and modify their operating model as needed—how detection connects to response, how identity is governed, how decisions are made and validated—are better positioned to adapt.

For CISOs, the next step is not wholesale reinvention but, rather, an honest assessment of where manual handoffs, fragmented workflows, and delayed decisions still define the program. Given the speed at which AI functions, those are no longer operational issues. They are strategic risks.

This is the shift AI has surfaced. Not a new category of threat, but a new standard for how cybersecurity must function. And for CISOs, that standard is becoming the difference between programs that keep up and those that are always catching up.

Proactive cybersecurity to help you guard against tomorrow’s threats today

As cyber threats grow in sophistication, CISOs must navigate an increasingly complex landscape of risks and vulnerabilities. With expanding regulatory requirements and the continuous evolution of attack methods, maintaining a robust cybersecurity posture is more critical than ever. 

At KPMG, we understand these challenges and provide targeted solutions to address them effectively. Today's CISOs need strategies that are both adaptable and multifaceted to stay ahead of ever-evolving threats. KPMG combines cutting-edge technology, actionable insights, and unparalleled expertise to help you prioritize and address your most critical cyber and tech risk challenges.

Our team leverages the latest in AI-driven analytics and industry best practices to deliver proactive, tailored solutions that fortify your security posture. Our cybersecurity and tech risk solutions are designed to enable your organization to anticipate threats, respond swiftly, and emerge stronger. From predictive threat intelligence to rapid incident response, KPMG is your partner in navigating cyber risk with confidence and agility.

 

KPMG Cyber and Tech Risk Services >

 

KPMG Cyber Managed Services >

 

Get in touch >

Advanced Threat Detection

Stay ahead of sophisticated cyber adversaries with AI and machine learning that detect and mitigate threats before they can impact your operations. Our solutions offer real-time threat intelligence and automated response mechanisms to keep your defenses strong and adaptive.

Enhanced Access Management

Effective identity and access management (IAM) is critical for controlling access to your systems and data. Automating IAM processes improves security and operational efficiency, ensuring only authorized users have access based on stringent, dynamic policies.

Regulatory Compliance

Stay compliant with evolving regulations and standards such as GDPR, CCPA, and industry-specific mandates. Our compliance services minimize regulatory risks and potential fines while streamlining audit and reporting processes.

Data Protection and Privacy

Ensure the integrity and privacy of data wherever it resides – on-premises, in the cloud, or in hybrid environments. Our strategies encompass robust encryption, DLP solutions, and strict access controls to protect against breaches and unauthorized access.

Footnotes

KPMG Cyber considerations 2026.

2 2026 KPMG Cyber and Technology Risk Survey.

32026 KPMG Cyber and Technology Risk Survey. 

2026 KPMG Cyber and Technology Risk Survey. 

KPMG Cyber considerations 2026. 

6 2026 KPMG Cyber and Technology Risk Survey. 

Meet our team

Our KPMG Cyber and Tech Risk team offers clients unparalleled expertise and access to cutting-edge technology, ensuring robust protection against evolving cyber threats. By leveraging a unique blend of functional, industry, and technological experience, our professionals help organizations navigate the complex landscape of cybersecurity with confidence.

Our specialists are skilled in areas such as AI-driven threat detection, cloud security, identity and access management, and advanced data privacy. We empower your organization to embrace technological advancements safely and confidently, transforming your cybersecurity posture from reactive to proactive.

Image of Matthew P. Miller
Matthew P. Miller
Principal, Advisory, Cyber Security Services, KPMG US

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.
All fields with an asterisk (*) are required.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline