For Better or for Worse,
AI Is Changing the Landscape for Cybersecurity

Beyond the use cases for attack and defense, IT leaders are relying on automation to quantify their risks and maximize the return on their security investments, CDW research shows.


When the artificial intelligence company Anthropic announced that it would not make its Claude Mythos Preview general-purpose language model available to the public because the company had deemed the new AI tool too dangerous for general release, it became clear that AI is rewriting the rules of the cybersecurity. Anthropic stated that Mythos can identify and exploit zero-day cybersecurity vulnerabilities, which could massively reduce the time and skill needed to carry out sophisticated cyberattacks. 

However, the company said in an April 7 announcement that it would use the language model “to help secure the world’s most critical software, and to prepare the industry for the practices we all will need to adopt to keep ahead of cyberattackers.” Later that month, OpenAI announced that its ChatGPT 5.5 model had demonstrated similar functionality. But this isn’t just about Mythos or Chat GPT 5.5, specifically. Both models are examples of permissive AI that has a high degree of autonomy and wide-ranging access to tools without many guardrails or content moderation. The result is that models such as Mythos and Chat GPT 5.5 can accomplish things that no AI model has ever achieved before: a total takeover of an organization’s network with a high degree of obscurity.

This news aligns with the findings of CDW’s latest market research into cybersecurity. In a survey of 951 IT decision-makers across a variety of industries, CDW found that AI represents both a significant threat and a powerful tool in cybersecurity. In fact, 43% of respondents said they had experienced AI-enhanced or AI-generated phishing attacks, while 37% said they faced AI-powered malware. Conversely, 41% said they planned to deploy AI-driven threat detection, anomaly detection and behavioral analytics to mitigate AI-enabled threats. These results indicate that organizations are realizing quickly that the only way to fight the threats posed by AI is with AI.

Which of the following forms of cyber fraud has your organization experienced in the past 12 months?

Pie Chart 1

THE PERCENTAGE OF RESPONDENTS WHO HAD EXPERIENCED AI-ENHANCED OR GENERATED PHISHING ATTACKS

Pie Chart 2

THE PERCENTAGE OF RESPONDENTS WHO HAD FACED AI-POWERED MALWARE

Pie Chart 3

THE PERCENTAGE OF RESPONDENTS WHO SAID THEY PLANNED TO DEPLOY AI-DRIVEN TOOLS TO MITIGATE AI-ENABLED THREATS

The power that AI delivers for both offensive and defensive cybersecurity should be a top concern for IT professionals, says Buck Bell, director of CDW’s Global Security Strategy Office. In fact, research has shown that not only can frontier AI models — the latest versions — discover vulnerabilities, but they are also capable, based on their goal-seeking bias and reasoning ability, of exploiting complex kill chains to gain access to high-value assets. The AI Security Institute’s security evaluation framework, known as The Last Ones (TLO), shows that these new exploitation capabilities go beyond what simple find-and-patch security efforts will solve.

“We should be concerned about the increasing ability of AI as a technology to discover and exploit weaknesses,” Bell says. “It’s incumbent now on security practitioners to leverage similar tools to find those weaknesses before the bad guys find them. But we also need to be able to measure risk more broadly. Given how powerful these frontier AI models have become, assessment and prioritization are essential.”

back-to-top

Explore the security strategies and solutions you need to take a proactive approach to risk and resilience.

AI Supercharges IT’s Ability To Surveil, Detect and Monitor

CDW’s research indicates that AI has the power to provide a variety of valuable cybersecurity benefits. When asked how their organization is using AI to strengthen cybersecurity, 49% of respondents cited AI-driven threat detection and anomaly detection, while 47% said threat intelligence analysis, and 42% cited phishing and fraud detection. These results suggest that AI has moved beyond experimentation and is already embedded in core security operations. 

“The tool sets that are coming out from companies involved in early closed-access testing cycles of Mythos under Anthropic Glasswing, like Palo Alto Networks, Cisco, Microsoft and CrowdStrike, started with AI-driven threat detection and anomaly detection, so, of course, most organizations are starting to take advantage of those technologies,” says Stephanie Hagopian, senior vice president of CDW’s security practice. “One of the keys to implementing those effectively is to make sure that you’re applying those tools against your entire threat landscape and not just a subset of it. Have you covered all of your third-party risk scenarios? Have you looked at all of your SaaS infrastructure, your hyperscaler environments and on-prem resources? That’s your attack surface.”

Graph 1

Further, as IT teams work to quantify their security risks and strategize their investments, AI provides capabilities to help them derive the greatest possible value from their security investments. In fact, in response to a question about how they are maximizing the value of their security spending, 28% of respondents said they were using automation, integration and consolidation, by far the most common answer. 

“We believe strongly that AI can be leveraged to find ways to consolidate your investments and save money,” Hagopian says. Explaining further, she adds, “AI can expose overlapping or redundant tooling functionality, as well as enable automatic detection and blocking with self-healing response remediation mechanisms. Both of these use cases for AI save money by bringing about better operational efficiencies, while also decreasing risk. The key is to make sure you’re implementing AI use cases that have the right harnesses in place to ensure token consumption costs don’t undermine your objectives. AI FinOps has to be a part of the equation.”

back-to-top
Image Break 1

The Rise of AI-Enabled Threats

AI is reshaping the cybersecurity landscape in multiple ways, creating new opportunities for organizations while also introducing new risks. Our research suggests that IT leaders are especially concerned about AI-enabled attacks that scale quickly with massive email campaigns, exploit human behavior and require relatively little sophistication to deploy.

When we asked respondents which AI-enabled cybersecurity threats pose the greatest risk to their organizations, the most common answers were AI-generated phishing and social engineering attacks (25%) and AI-powered malware and automated attack tools (21%). Deepfake impersonation ranked much lower at 8%.

Graph 2

These findings suggest organizations are most concerned about threats that can be operationalized quickly and broadly by attackers. While deepfakes often generate headlines, more practical threats such as AI-enhanced phishing campaigns and automated malware are already affecting organizations at scale, as they face mass-generated emails and phone calls.

“What’s emerging now is going to create a shift of not just AI increasing scalability, but also thoroughness of vulnerability exploitation, especially zero-day vulnerability exploitation,” says Hagopian.

How AI Scalability Increases the Inevitability of a Breach

The survey results indicate organizations increasingly recognize that AI-enabled threats cannot be entirely prevented. Instead, many are focusing on improving visibility, strengthening governance, and accelerating detection and response.

When we asked about organizations’ strategies for mitigating AI-enabled cybersecurity threats, the most common responses were enhanced detection and monitoring tools (41%), AI governance and use policies (39%), and data protection and loss prevention controls (38%). 

Bell suggests that organizations consider three concepts as they plan their defenses against AI-enabled attacks: continuous threat exposure management (CTEM), cyber resilience and tech rationalization.

“You should assume that you are going to be breached, or that you have been and may not be aware of it,” Bell says. “With CTEM, you want to quickly understand the threats, understand your assets and the value that they have, and understand whether there’s an attack path that’s exploitable back to those assets. And you want to be able to report on that, get visibility to it quickly and remediate quickly.”

back-to-top
“AI is making it imperative to prioritize your defense strategy and remediation plan because AI-based threats have increased the scale and volume of alerts and potential threat vectors exponentially. The only way to do this is by measuring risks.” -Stephanie Hagopian

Building Security Around AI

As organizations expand their use of AI and agentic AI, they must also determine how to secure these systems and manage nonhuman identities. The research suggests that many organizations are still building foundational capabilities in this area.

When we asked respondents about the steps their organizations have taken to manage the identities of AI agents, the most common answers were AI security posture management assessments to provide continuous evaluations of an organization’s AI infrastructure (46%), consistent monitoring and evaluation (46%), and assessments against current risk and regulatory requirements (40%). 

Organizations are also taking steps to secure their broader AI initiatives. The most common measures included employee training on secure AI use (45%), implementation of data protection controls for AI systems (44%) and integration of AI systems into existing security monitoring workflows (44%). 

These findings reflect growing adoption of cyber resilience and zero-trust principles, Hagopian says. However, many organizations still have significant work to do before achieving higher levels of maturity.

“People are establishing the foundations of resilience and zero trust, but they’re not at the right maturity level, because true maturity around these concepts reflects continuous, self-healing systems and internal processes,” she says. “That proactivity component is still not quite there.”

Part of the challenge is that organizations cannot simply purchase a single tool to achieve these outcomes.

“There’s no zero-trust solution or continuous threat management solution. There’s no widget that’s going to solve for it,” Hagopian adds. “It’s going to require you to build mature, cross-departmental processes on top of those tools, likely augmented by organizationally specific AI models and agents, and that takes a long time for companies to do.”

Graph 3

AI and Automation Accelerate Security Operations

Organizations also plan to expand their use of AI significantly in the years ahead. Open-ended survey responses revealed that the most common areas of planned AI expansion involve automation and operational efficiency, representing roughly 24% of responses. 

Respondents described plans to automate repetitive workflows, streamline processes and accelerate incident response activities. One respondent reported: “Automated incident response workflows leveraging AI to triage alerts and trigger containment without manual intervention.” Another said their organization planned to “automate code review and testing, predictive infrastructure scaling.”

These responses suggest organizations increasingly view AI as a necessary operational capability rather than simply an emerging technology trend.

“We talk a lot about an active defense grid,” Hagopian says. “That involves automated detection and blocking where there’s a human in the loop, rather than human management. Human-led security operations can’t keep up with AI-driven attacks.”

As threats increase in scale and speed, organizations need systems capable of responding proactively and automatically, she says.

“It’s important to focus on stopping attacks before exploits happen, which you can do proactively through implementing passwordless access, managing admin rights and implementing automated patching,” Hagopian says. “That creates a framework for a self-healing infrastructure.”

back-to-top

CDW can help you overcome your AI challenges and implement a winning strategy.


“There is a lack of visibility for most organizations into truly understanding the extent of where information is distributed across the ecosystem. You have to extend your ability to control and have visibility over all of these assets.” -Buck Bell

Balancing Cyber Risk With Cybersecurity Investments

As cybersecurity environments become increasingly complex, organizations are also struggling to quantify cyber risk and measure the value of their security investments. The research suggests that many organizations continue to rely heavily on operational and technical indicators rather than business-impact modeling.

When we asked respondents about the biggest challenges they face in quantifying cybersecurity risks, the top responses were complex IT and cloud environments (46%), a rapidly evolving threat landscape (35%) and translating technical risk into business impact (30%). 

These challenges are compounded by the rise of AI-enabled threats and increasingly distributed IT environments.

“AI is making it imperative to prioritize your defense strategy and remediation plan because AI-based threats have increased the scale and volume of alerts and potential threat vectors exponentially,” Hagopian says. “The only way to do this is by measuring risks.”

Bell says organizations often struggle to maintain visibility across increasingly fragmented ecosystems.

“There is a lack of visibility for most organizations into truly understanding the extent of where information is distributed across the ecosystem,” he says. “There are many layers because of the adoption of SaaS, third-party applications, managed services and more. You have to extend your ability to control and have visibility over all of these assets.”


What are the biggest challenges your organization faces in quantifying its cybersecurity risks?

Pie Chart 4

COMPLEX IT AND CLOUD
ENVIRONMENT

Pie Chart 5

A RAPIDLY EVOLVING THREAT
LANDSCAPE

Pie Chart 6

TRANSLATING TECHNICAL RISK INTO
BUSINESS IMPACT


Measuring Risk in Business Terms

Most organizations continue to quantify cybersecurity risks through technical or operational metrics. The most common approaches cited by respondents were threat intelligence-driven assessments (50%), vulnerability and exposure metrics (48%) and qualitative risk assessments (44%). 

By comparison, only 31% said they use quantitative financial modeling methodologies such as Factor Analysis of Information Risk (FAIR). This indicates that many organizations remain focused on measuring exposure rather than understanding broader business impact.

“Organizations need to define what it is they’re trying to measure,” Bell says. “The goal of cybersecurity is not to improve mean time to detection or mean time to resolution. Those things are unquestionably good, but the goal is to keep the organization running and to protect the assets that have value.”

Tying Risk to Financial Outcomes

Bell recommends that organizations develop key risk indicators tied directly to business priorities and operational outcomes. One useful approach involves translating cybersecurity risks into financial terms. This requires collaboration among IT and security teams as well as line-of-business partners such as finance and operations. 

“If you are going to quantify risk in financial terms, you’ve got some options. One would be to use something like the FAIR methodology,” Bell says. “This is often used by organizations that are relatively mature and have strong governance, risk and compliance teams, so they’ve already associated value with the data assets that they have in play.”

Organizations that take this approach can more effectively estimate the impact of operational downtime, data exfiltration and other cyber events, allowing them to prioritize investments and remediation activities more strategically.

“Most organizations can on some level identify what their most valuable assets are,” Bell says. “But what most organizations cannot do effectively is view the threat landscape, view the protections they have in place, view the assets that are in play and then actually map the attack paths back to those assets.”

Focusing Security Investments

The research also indicates that organizations are increasingly focused on maximizing the value of their existing security investments rather than simply purchasing additional tools.

When we asked respondents how they measure the value or return on cybersecurity investments, the most common responses were security performance metrics (39%), improved risk posture (34%) and reductions in security incidents (33%).

Graph 4

Open-ended responses revealed strong themes around automation, integration and consolidation. Many respondents described efforts to reduce tool sprawl, streamline workflows and improve operational efficiency through integrated security platforms. 

At the same time, several lower-adoption areas suggest that organizations may still be missing opportunities to tie cybersecurity more directly to enterprise risk. Areas such as third-party risk scoring, scenario modeling and financial impact estimation ranked significantly lower than operational metrics.

“Security practitioners need to think about things that matter to executives and bring them into their confidence,” Bell says. “This could include the regulatory environment, third-party impacts, customer impacts, overall operations or financials. Wherever you’re going to end up, try to communicate risk in that way.”

back-to-top

Maximize the value of your technology investments by building a compliant, efficient security program aligned to your business goals.

Image Break 2

Managed Services and Security Operations

Maintaining effective cybersecurity operations around the clock remains a major challenge for organizations across industries. When we asked respondents which cybersecurity responsibility their organization struggles with most, 24/7 threat monitoring and detection ranked highest at 26%. Securing cloud and hybrid environments (14%) and third-party and supply chain risk management (13%) followed behind. 

One reason organizations increasingly turn to managed security service providers is the ability to augment internal teams with automation, expertise and continuous coverage. A service provider’s ability to leverage automated tools that an organization may lack or not have the skills to use effectively can be particularly valuable.

“Many organizations still expect humans to make decisions, where in certain cases, humans don’t have to make decisions,” Bell says. “The more that you can identify where you can automate the response, the better off you’ll be. Managed services can help with that.

The Operational Value of Managed Services

The survey results indicate that organizations are primarily seeking operational improvements from managed services engagements rather than dramatic cost savings or transformational change.

When asked about the benefits they would gain from managed security services, respondents most commonly cited 24/7 monitoring and faster incident response (58%), improved security tool optimization and management (41%), and improved cyber resilience and business continuity (40%). 

These responses suggest that organizations are prioritizing speed, consistency and coverage.

“Many organizations are not necessarily looking for cost savings or strategic transformation,” Bell says. “They just want an immediate operational lift. They want consistency and they want people who have expertise to be able to perform this.”

Graph 5

Bringing in Third-Party Expertise

Managed service providers also help organizations address ongoing staffing and skills shortages, which remain among the biggest obstacles to cyber resilience.

“They also don’t want to worry about training people up and then losing them to the broader marketplace, which happens an awful lot,” Bell says. “The managed service provides a professionalized, repeatable, tool-assisted solution.”

Organizations most commonly outsource services that are highly complex or difficult to scale internally. The top outsourced services cited by respondents included cloud security managed services (40%), cyber threat intelligence (39%) and security awareness training services (33%). 

This reflects the growing demand for specialized expertise in areas such as cloud security, threat intelligence and 24/7 monitoring. AI is also becoming increasingly important to managed service providers themselves as they look to scale operations and improve detection capabilities.

“Every managed service company is right now investing heavily in AI,” Bell says. “That includes CDW.”

back-to-top

A Hybrid Approach to Security Tools

As they plan out their cybersecurity environments, organizations appear to be moving away from extremes. Rather than fully consolidating onto a single platform or deploying fragmented best-of-breed environments, many are adopting hybrid approaches.

When we asked respondents about their cybersecurity investment strategies, the most common answer was a hybrid “platform-plus” strategy (32%), followed by risk-based deployment strategies (22%) and best-of-breed approaches (20%). Pure consolidation strategies ranked lowest at roughly 10%. 

These findings suggest organizations increasingly want integration and simplicity without sacrificing depth of capability.

“A hybrid approach is smart,” Hagopian says. “Relying on a single platform means there’s a single point of failure. That’s a bad strategy.”

A Simplified Approach to Security Tooling

At the same time, excessive tool sprawl can create operational inefficiencies and management challenges.

“All point solutions create tool sprawl, which can create challenges around training users, maintaining systems and integrating with other systems,” she says. “A hybrid approach de-risks your environment, simplifies overall management and gains cost efficiencies.”

To optimize these hybrid environments, Hagopian says, organizations should align security initiatives with established frameworks such as the National Institute of Standards and Technology Cybersecurity Framework.

“A common framework helps ensure you’re using your tool capabilities completely, without unnecessary overlap,” she says. “You should consolidate where you can and overlay where you must to fill gaps and become more mature.”

back-to-top

Explore the security strategies and solutions you need to take a proactive approach to risk and resilience.

For Better or for Worse, AI Is Changing the Landscape for Cybersecurity

Beyond the use cases for attack and defense, IT leaders are relying on automation to quantify their risks and maximize the return on their security investments, CDW research shows.

When the artificial intelligence company Anthropic announced that it would not make its Claude Mythos Preview general-purpose language model available to the public because the company had deemed the new AI tool too dangerous for general release, it became clear that AI is rewriting the rules of the cybersecurity. Anthropic stated that Mythos can identify and exploit zero-day cybersecurity vulnerabilities, which could massively reduce the time and skill needed to carry out sophisticated cyberattacks. 

However, the company said in an April 7 announcement that it would use the language model “to help secure the world’s most critical software, and to prepare the industry for the practices we all will need to adopt to keep ahead of cyberattackers.” Later that month, OpenAI announced that its ChatGPT 5.5 model had demonstrated similar functionality. But this isn’t just about Mythos or Chat GPT 5.5, specifically. Both models are examples of permissive AI that has a high degree of autonomy and wide-ranging access to tools without many guardrails or content moderation. The result is that models such as Mythos and Chat GPT 5.5 can accomplish things that no AI model has ever achieved before: a total takeover of an organization’s network with a high degree of obscurity.

This news aligns with the findings of CDW’s latest market research into cybersecurity. In a survey of 951 IT decision-makers across a variety of industries, CDW found that AI represents both a significant threat and a powerful tool in cybersecurity. In fact, 43% of respondents said they had experienced AI-enhanced or AI-generated phishing attacks, while 37% said they faced AI-powered malware. Conversely, 41% said they planned to deploy AI-driven threat detection, anomaly detection and behavioral analytics to mitigate AI-enabled threats. These results indicate that organizations are realizing quickly that the only way to fight the threats posed by AI is with AI.

WHAT ARE YOUR ORGANIZATION’S
STRATEGIES FOR MITIGATING AI-
ENABLED CYBERSECURITY THREATS?

Pie Chart 3

ENHANCED DETECTION
AND MONITORING TOOLS

The power that AI delivers for both offensive and defensive cybersecurity should be a top concern for IT professionals, says Buck Bell, director of CDW’s Global Security Strategy Office. In fact, research has shown that not only can frontier AI models — the latest versions — discover vulnerabilities, but they are also capable, based on their goal-seeking bias and reasoning ability, of exploiting complex kill chains to gain access to high-value assets. The AI Security Institute’s security evaluation framework, known as The Last Ones (TLO), shows that these new exploitation capabilities go beyond what simple find-and-patch security efforts will solve.

“We should be concerned about the increasing ability of AI as a technology to discover and exploit weaknesses,” Bell says. “It’s incumbent now on security practitioners to leverage similar tools to find those weaknesses before the bad guys find them. But we also need to be able to measure risk more broadly. Given how powerful these frontier AI models have become, assessment and prioritization are essential.”

Explore the security strategies and solutions you need to take a proactive approach to risk and resilience.

AI Supercharges IT’s Ability To Surveil, Detect and Monitor

CDW’s research indicates that AI has the power to provide a variety of valuable cybersecurity benefits. When asked how their organization is using AI to strengthen cybersecurity, 49% of respondents cited AI-driven threat detection and anomaly detection, while 47% said threat intelligence analysis, and 42% cited phishing and fraud detection. These results suggest that AI has moved beyond experimentation and is already embedded in core security operations. 

“The tool sets that are coming out from companies involved in early closed-access testing cycles of Mythos under Anthropic Glasswing, like Palo Alto Networks, Cisco, Microsoft and CrowdStrike, started with AI-driven threat detection and anomaly detection, so, of course, most organizations are starting to take advantage of those technologies,” says Stephanie Hagopian, senior vice president of CDW’s security practice. “One of the keys to implementing those effectively is to make sure that you’re applying those tools against your entire threat landscape and not just a subset of it. Have you covered all of your third-party risk scenarios? Have you looked at all of your SaaS infrastructure, your hyperscaler environments and on-prem resources? That’s your attack surface.”

Further, as IT teams work to quantify their security risks and strategize their investments, AI provides capabilities to help them derive the greatest possible value from their security investments. In fact, in response to a question about how they are maximizing the value of their security spending, 28% of respondents said they were using automation, integration and consolidation, by far the most common answer. 

“We believe strongly that AI can be leveraged to find ways to consolidate your investments and save money,” Hagopian says. Explaining further, she adds, “AI can expose overlapping or redundant tooling functionality, as well as enable automatic detection and blocking with self-healing response remediation mechanisms. Both of these use cases for AI save money by bringing about better operational efficiencies, while also decreasing risk. The key is to make sure you’re implementing AI use cases that have the right harnesses in place to ensure token consumption costs don’t undermine your objectives. AI FinOps has to be a part of the equation.”

The Rise of AI-Enabled Threats

AI is reshaping the cybersecurity landscape in multiple ways, creating new opportunities for organizations while also introducing new risks. Our research suggests that IT leaders are especially concerned about AI-enabled attacks that scale quickly with massive email campaigns, exploit human behavior and require relatively little sophistication to deploy.

When we asked respondents which AI-enabled cybersecurity threats pose the greatest risk to their organizations, the most common answers were AI-generated phishing and social engineering attacks (25%) and AI-powered malware and automated attack tools (21%). Deepfake impersonation ranked much lower at 8%.

WHICH AI-ENABLED CYBERSECURITY
THREAT POSES THE GREATEST RISK
TO YOUR ORGANIZATION TODAY?

Pie Chart 3

AI-GENERATED PHISHING 

AND SOCIAL ENGINEERING

These findings suggest organizations are most concerned about threats that can be operationalized quickly and broadly by attackers. While deepfakes often generate headlines, more practical threats such as AI-enhanced phishing campaigns and automated malware are already affecting organizations at scale, as they face mass-generated emails and phone calls.

“What’s emerging now is going to create a shift of not just AI increasing scalability, but also thoroughness of vulnerability exploitation, especially zero-day vulnerability exploitation,” says Hagopian.

How AI Scalability Increases the Inevitability of a Breach

The survey results indicate organizations increasingly recognize that AI-enabled threats cannot be entirely prevented. Instead, many are focusing on improving visibility, strengthening governance, and accelerating detection and response.

When we asked about organizations’ strategies for mitigating AI-enabled cybersecurity threats, the most common responses were enhanced detection and monitoring tools (41%), AI governance and use policies (39%), and data protection and loss prevention controls (38%). 

Bell suggests that organizations consider three concepts as they plan their defenses against AI-enabled attacks: continuous threat exposure management (CTEM), cyber resilience and tech rationalization.

“You should assume that you are going to be breached, or that you have been and may not be aware of it,” Bell says. “With CTEM, you want to quickly understand the threats, understand your assets and the value that they have, and understand whether there’s an attack path that’s exploitable back to those assets. And you want to be able to report on that, get visibility to it quickly and remediate quickly.”

“AI is making it imperative to prioritize your defense strategy and remediation plan because AI-based threats have increased the scale and volume of alerts and potential threat vectors exponentially. The only way to do this is by measuring risks.” -Stephanie Hagopian

Building Security Around AI

As organizations expand their use of AI and agentic AI, they must also determine how to secure these systems and manage nonhuman identities. The research suggests that many organizations are still building foundational capabilities in this area.

When we asked respondents about the steps their organizations have taken to manage the identities of AI agents, the most common answers were AI security posture management assessments to provide continuous evaluations of an organization’s AI infrastructure (46%), consistent monitoring and evaluation (46%), and assessments against current risk and regulatory requirements (40%). 

Organizations are also taking steps to secure their broader AI initiatives. The most common measures included employee training on secure AI use (45%), implementation of data protection controls for AI systems (44%) and integration of AI systems into existing security monitoring workflows (44%). 

These findings reflect growing adoption of cyber resilience and zero-trust principles, Hagopian says. However, many organizations still have significant work to do before achieving higher levels of maturity.

“People are establishing the foundations of resilience and zero trust, but they’re not at the right maturity level, because true maturity around these concepts reflects continuous, self-healing systems and internal processes,” she says. “That proactivity component is still not quite there.”

Part of the challenge is that organizations cannot simply purchase a single tool to achieve these outcomes.

“There’s no zero-trust solution or continuous threat management solution. There’s no widget that’s going to solve for it,” Hagopian adds. “It’s going to require you to build mature, cross-departmental processes on top of those tools, likely augmented by organizationally specific AI models and agents, and that takes a long time for companies to do.”

WHAT STEPS HAS YOUR
ORGANIZATION TAKEN TO ENSURE
THE SECURITY OF ITS AI INITIATIVES?

Pie Chart 3

PROVIDED EMPLOYEE TRAINING
ON SECURE AI USE

AI and Automation Accelerate Security Operations

Organizations also plan to expand their use of AI significantly in the years ahead. Open-ended survey responses revealed that the most common areas of planned AI expansion involve automation and operational efficiency, representing roughly 24% of responses. 

Respondents described plans to automate repetitive workflows, streamline processes and accelerate incident response activities. One respondent reported: “Automated incident response workflows leveraging AI to triage alerts and trigger containment without manual intervention.” Another said their organization planned to “automate code review and testing, predictive infrastructure scaling.”

These responses suggest organizations increasingly view AI as a necessary operational capability rather than simply an emerging technology trend.

“We talk a lot about an active defense grid,” Hagopian says. “That involves automated detection and blocking where there’s a human in the loop, rather than human management. Human-led security operations can’t keep up with AI-driven attacks.”

As threats increase in scale and speed, organizations need systems capable of responding proactively and automatically, she says.

“It’s important to focus on stopping attacks before exploits happen, which you can do proactively through implementing passwordless access, managing admin rights and implementing automated patching,” Hagopian says. “That creates a framework for a self-healing infrastructure.”

CDW can help you overcome your AI challenges and implement a winning strategy.

“There is a lack of visibility for most organizations into truly understanding the extent of where information is distributed across the ecosystem. You have to extend your ability to control and have visibility over all of these assets.” -Buck Bell

Balancing Cyber Risk With Cybersecurity Investments

As cybersecurity environments become increasingly complex, organizations are also struggling to quantify cyber risk and measure the value of their security investments. The research suggests that many organizations continue to rely heavily on operational and technical indicators rather than business-impact modeling.

When we asked respondents about the biggest challenges they face in quantifying cybersecurity risks, the top responses were complex IT and cloud environments (46%), a rapidly evolving threat landscape (35%) and translating technical risk into business impact (30%). 

These challenges are compounded by the rise of AI-enabled threats and increasingly distributed IT environments.

“AI is making it imperative to prioritize your defense strategy and remediation plan because AI-based threats have increased the scale and volume of alerts and potential threat vectors exponentially,” Hagopian says. “The only way to do this is by measuring risks.”

Bell says organizations often struggle to maintain visibility across increasingly fragmented ecosystems.

“There is a lack of visibility for most organizations into truly understanding the extent of where information is distributed across the ecosystem,” he says. “There are many layers because of the adoption of SaaS, third-party applications, managed services and more. You have to extend your ability to control and have visibility over all of these assets.”

WHAT ARE THE BIGGEST

CHALLENGES YOUR ORGANIZATION
FACES IN QUANTIFYING ITS
CYBERSECURITY RISKS?

Pie Chart 3

COMPLEX IT AND
CLOUD ENVIRONMENTS

Measuring Risk in Business Terms

Most organizations continue to quantify cybersecurity risks through technical or operational metrics. The most common approaches cited by respondents were threat intelligence-driven assessments (50%), vulnerability and exposure metrics (48%) and qualitative risk assessments (44%). 

By comparison, only 31% said they use quantitative financial modeling methodologies such as Factor Analysis of Information Risk (FAIR). This indicates that many organizations remain focused on measuring exposure rather than understanding broader business impact.

“Organizations need to define what it is they’re trying to measure,” Bell says. “The goal of cybersecurity is not to improve mean time to detection or mean time to resolution. Those things are unquestionably good, but the goal is to keep the organization running and to protect the assets that have value.”

Tying Risk to Financial Outcomes

Bell recommends that organizations develop key risk indicators tied directly to business priorities and operational outcomes. One useful approach involves translating cybersecurity risks into financial terms. This requires collaboration among IT and security teams as well as line-of-business partners such as finance and operations. 

“If you are going to quantify risk in financial terms, you’ve got some options. One would be to use something like the FAIR methodology,” Bell says. “This is often used by organizations that are relatively mature and have strong governance, risk and compliance teams, so they’ve already associated value with the data assets that they have in play.”

Organizations that take this approach can more effectively estimate the impact of operational downtime, data exfiltration and other cyber events, allowing them to prioritize investments and remediation activities more strategically.

“Most organizations can on some level identify what their most valuable assets are,” Bell says. “But what most organizations cannot do effectively is view the threat landscape, view the protections they have in place, view the assets that are in play and then actually map the attack paths back to those assets.”

Focusing Security Investments

The research also indicates that organizations are increasingly focused on maximizing the value of their existing security investments rather than simply purchasing additional tools.

When we asked respondents how they measure the value or return on cybersecurity investments, the most common responses were security performance metrics (39%), improved risk posture (34%) and reductions in security incidents (33%). 

Open-ended responses revealed strong themes around automation, integration and consolidation. Many respondents described efforts to reduce tool sprawl, streamline workflows and improve operational efficiency through integrated security platforms. 

At the same time, several lower-adoption areas suggest that organizations may still be missing opportunities to tie cybersecurity more directly to enterprise risk. Areas such as third-party risk scoring, scenario modeling and financial impact estimation ranked significantly lower than operational metrics.

“Security practitioners need to think about things that matter to executives and bring them into their confidence,” Bell says. “This could include the regulatory environment, third-party impacts, customer impacts, overall operations or financials. Wherever you’re going to end up, try to communicate risk in that way.”

Maximize the value of your technology investments by building a compliant, efficient security program aligned to your business goals.

Managed Services and Security Operations

Maintaining effective cybersecurity operations around the clock remains a major challenge for organizations across industries. When we asked respondents which cybersecurity responsibility their organization struggles with most, 24/7 threat monitoring and detection ranked highest at 26%. Securing cloud and hybrid environments (14%) and third-party and supply chain risk management (13%) followed behind. 

One reason organizations increasingly turn to managed security service providers is the ability to augment internal teams with automation, expertise and continuous coverage. A service provider’s ability to leverage automated tools that an organization may lack or not have the skills to use effectively can be particularly valuable.

“Many organizations still expect humans to make decisions, where in certain cases, humans don’t have to make decisions,” Bell says. “The more that you can identify where you can automate the response, the better off you’ll be. Managed services can help with that.

The Operational Value of Managed Services

The survey results indicate that organizations are primarily seeking operational improvements from managed services engagements rather than dramatic cost savings or transformational change.

When asked about the benefits they would gain from managed security services, respondents most commonly cited 24/7 monitoring and faster incident response (58%), improved security tool optimization and management (41%), and improved cyber resilience and business continuity (40%). 

These responses suggest that organizations are prioritizing speed, consistency and coverage.

“Many organizations are not necessarily looking for cost savings or strategic transformation,” Bell says. “They just want an immediate operational lift. They want consistency and they want people who have expertise to be able to perform this.”

24/7 THREAT MONITORING

Pie Chart 3

FASTER INCIDENT RESPONSE

Bringing in Third-Party Expertise

Managed service providers also help organizations address ongoing staffing and skills shortages, which remain among the biggest obstacles to cyber resilience.

“They also don’t want to worry about training people up and then losing them to the broader marketplace, which happens an awful lot,” Bell says. “The managed service provides a professionalized, repeatable, tool-assisted solution.”

Organizations most commonly outsource services that are highly complex or difficult to scale internally. The top outsourced services cited by respondents included cloud security managed services (40%), cyber threat intelligence (39%) and security awareness training services (33%). 

This reflects the growing demand for specialized expertise in areas such as cloud security, threat intelligence and 24/7 monitoring. AI is also becoming increasingly important to managed service providers themselves as they look to scale operations and improve detection capabilities.

“Every managed service company is right now investing heavily in AI,” Bell says. “That includes CDW.”

A Hybrid Approach to Security Tools

As they plan out their cybersecurity environments, organizations appear to be moving away from extremes. Rather than fully consolidating onto a single platform or deploying fragmented best-of-breed environments, many are adopting hybrid approaches.

When we asked respondents about their cybersecurity investment strategies, the most common answer was a hybrid “platform-plus” strategy (32%), followed by risk-based deployment strategies (22%) and best-of-breed approaches (20%). Pure consolidation strategies ranked lowest at roughly 10%. 

These findings suggest organizations increasingly want integration and simplicity without sacrificing depth of capability.

“A hybrid approach is smart,” Hagopian says. “Relying on a single platform means there’s a single point of failure. That’s a bad strategy.”

A Simplified Approach to Security Tooling

At the same time, excessive tool sprawl can create operational inefficiencies and management challenges.

“All point solutions create tool sprawl, which can create challenges around training users, maintaining systems and integrating with other systems,” she says. “A hybrid approach de-risks your environment, simplifies overall management and gains cost efficiencies.”

To optimize these hybrid environments, Hagopian says, organizations should align security initiatives with established frameworks such as the National Institute of Standards and Technology Cybersecurity Framework.

“A common framework helps ensure you’re using your tool capabilities completely, without unnecessary overlap,” she says. “You should consolidate where you can and overlay where you must to fill gaps and become more mature.”

Explore the security strategies and solutions you need to take a proactive approach to risk and resilience.