Benchmarks

Cybersecurity Benchmarks

The security side of the governance gap — adoption-versus-security balance, guardrails, incidents, threat rankings, the AI security toolchain, and how teams respond after something goes wrong.

Georgian + NewtonX AI, Applied Benchmarks, Wave 3 · Technical Leadership n=252 unless noted · March–April 2026

Benchmark 4.1

AI security balance

Survey question

How would you describe the balance between your organization’s AI adoption pace and its security and risk management capabilities?

Audience
Technical Decision Makers · n=252
In depth
Ch 7 — The Governance Gap
Balance between AI adoption pace and security capability, Wave 3

55%

say AI adoption is ahead of their security capabilities — only 13% say security leads AI adoption

Technical Leadership · n=252 · Wave 3

Data for Balance between AI adoption pace and security capability, Wave 3
AI significantly outpacingAI somewhat aheadRoughly in balanceSecurity somewhat aheadSecurity significantly ahead
Share of technical leaders17%38%30%9%4%
Share of technical leaders17%38%30%9%0%100%
AI significantly outpacingAI somewhat aheadRoughly in balanceSecurity somewhat aheadSecurity significantly ahead

Technical Leadership · n=252 · Wave 3

Benchmark 4.2

Agentic AI guardrails

Survey question

Which of the following guardrails has your organization implemented for agentic AI systems?

Audience
Technical Decision Makers · n=252
In depth
Ch 7 — The Governance Gap
Agentic AI guardrails implemented, Wave 3

46 pts

separate human approval gates (75%) from policy-as-code (29%) — the governance stack leans manual, a potential risk given AI production levels in R&D

Technical Leadership · n=252 · Wave 3

Data for Agentic AI guardrails implemented, Wave 3
Category% implemented
Human approval gates75%
Sandboxed environments56%
Role-based constraints and permissions48%
Monitoring and audit logs46%
Safe-action lists / allowlists40%
Policy-as-code29%
No guardrails in place6%
0%20%40%60%80%Human approval gatesHuman approval gates — % implemented: 75%75%Sandboxed environmentsSandboxed environments — % implemented: 56%56%Role-based constraints and permissionsRole-based constraints and permissions — % implemented: 48%48%Monitoring and audit logsMonitoring and audit logs — % implemented: 46%46%Safe-action lists / allowlistsSafe-action lists / allowlists — % implemented: 40%40%Policy-as-codePolicy-as-code — % implemented: 29%29%No guardrails in placeNo guardrails in place — % implemented: 6%6%

Technical Leadership · n=252 · Wave 3

Benchmark 4.4

Agentic security threats

Survey question

Which of the following agentic threat vectors are of greatest concern to your organization? Rank up to 3, where #1 is most important.

Audience
Technical Decision Makers · n=252
In depth
Ch 7 — The Governance Gap
Agentic threat vectors of greatest concern, Wave 3

60%

rank excessive agency (32%) or prompt injection (28%) as their #1 agentic security concern — two threats that together dominate the agentic security agenda

Technical Leadership · n=252 · Wave 3

Data for Agentic threat vectors of greatest concern, Wave 3
Category% ranked #1% in top 3
Excessive agency / over-permissioned agents32%55%
Prompt injection28%49%
Credential and secret exfiltration12%40%
MCP / agent-tools exploitation6%38%
Agent-to-agent trust exploitation6%30%
Log and audit-trail blind spots6%26%
Supply-chain compromise via AI-assisted code7%21%
Memory and context poisoning4%19%
0%20%40%60%Excessive agency / over-permissioned agentsExcessive agency / over-permissioned agents — % ranked #1: 32%32%Excessive agency / over-permissioned agents — % in top 3: 55%55%Prompt injectionPrompt injection — % ranked #1: 28%28%Prompt injection — % in top 3: 49%49%Credential and secret exfiltrationCredential and secret exfiltration — % ranked #1: 12%12%Credential and secret exfiltration — % in top 3: 40%40%MCP / agent-tools exploitationMCP / agent-tools exploitation — % ranked #1: 6%6%MCP / agent-tools exploitation — % in top 3: 38%38%Agent-to-agent trust exploitationAgent-to-agent trust exploitation — % ranked #1: 6%6%Agent-to-agent trust exploitation — % in top 3: 30%30%Log and audit-trail blind spotsLog and audit-trail blind spots — % ranked #1: 6%6%Log and audit-trail blind spots — % in top 3: 26%26%Supply-chain compromise via AI-assistedcodeSupply-chain compromise via AI-assisted code — % ranked #1: 7%7%Supply-chain compromise via AI-assisted code — % in top 3: 21%21%Memory and context poisoningMemory and context poisoning — % ranked #1: 4%4%Memory and context poisoning — % in top 3: 19%19%
% ranked #1% in top 3

Technical Leadership · n=252 · Wave 3

Benchmark 4.5

AI security integration

Survey question

At what point in the development process is security or risk management integrated into agentic AI systems?

Audience
Technical Decision Makers · n=252
In depth
Ch 7 — The Governance Gap
When security is integrated into agentic AI systems

64%

integrate security early — at the requirements/design phase (33%) or during development (32%) — but 31% still integrate late or never

Technical Leadership · n=252 · Wave 3

Data for When security is integrated into agentic AI systems
Requirements / designDuring developmentTesting / pre-deployAfter deploymentRarely or never
Share of technical leaders33%32%20%6%5%
Share of technical leaders33%32%20%0%100%
Requirements / designDuring developmentTesting / pre-deployAfter deploymentRarely or never

Technical Leadership · n=252 · Wave 3

Benchmark 4.6

AI-enabled security tool penetration

Survey question

What types of AI-enabled security tools has your organization implemented? Select all that apply.

Audience
Technical Decision Makers · n=252
In depth
Ch 7 — The Governance Gap
AI-enabled security tools implemented, Wave 3

64%

have deployed AI-enabled identity and access management — the most frequently deployed AI security tool and 10 points ahead of email security at 54%

Technical Leadership · n=252 · Wave 3

Data for AI-enabled security tools implemented, Wave 3
Category% implemented
Identity and access management (IAM)64%
Email security54%
Data security50%
Penetration testing / red teaming46%
Continuous threat exposure monitoring46%
Security operations centre (SOC)43%
Supply chain security17%
None of these10%
0%20%40%60%80%Identity and access management (IAM)Identity and access management (IAM) — % implemented: 64%64%Email securityEmail security — % implemented: 54%54%Data securityData security — % implemented: 50%50%Penetration testing / red teamingPenetration testing / red teaming — % implemented: 46%46%Continuous threat exposure monitoringContinuous threat exposure monitoring — % implemented: 46%46%Security operations centre (SOC)Security operations centre (SOC) — % implemented: 43%43%Supply chain securitySupply chain security — % implemented: 17%17%None of theseNone of these — % implemented: 10%10%

Technical Leadership · n=252 · Wave 3

Benchmark 4.7

Risk mitigation after AI incidents

Survey question

Which mitigations did your organization put in place following these AI-related incidents? Select all that apply.

Audience
Technical Decision Makers who reported an incident · n=139
In depth
Ch 7 — The Governance Gap
Mitigations adopted after an AI-related incident, Wave 3

60%

responded by introducing or expanding human review and approval steps — the top mitigation of the eight measured, while the responses that change the system itself are the least used

Technical Leadership who reported an incident · n=139 · Wave 3

Data for Mitigations adopted after an AI-related incident, Wave 3
Category% adopting
Introduced or expanded human review / approval steps60%
Tightened prompts, guardrails, or instructions58%
Restricted data access or changed data handling policies42%
Increased monitoring, logging, or alerting on AI behaviour42%
Updated or added policy-as-code / enforcement rules29%
Limited or disabled affected AI features or use cases27%
Retrained, fine-tuned, or replaced models25%
Engaged external experts or vendors for review12%
0%20%40%60%Introduced or expanded human review /approval stepsIntroduced or expanded human review / approval steps — % adopting: 60%60%Tightened prompts, guardrails, orinstructionsTightened prompts, guardrails, or instructions — % adopting: 58%58%Restricted data access or changed datahandling policiesRestricted data access or changed data handling policies — % adopting: 42%42%Increased monitoring, logging, or alertingon AI behaviourIncreased monitoring, logging, or alerting on AI behaviour — % adopting: 42%42%Updated or added policy-as-code /enforcement rulesUpdated or added policy-as-code / enforcement rules — % adopting: 29%29%Limited or disabled affected AI features oruse casesLimited or disabled affected AI features or use cases — % adopting: 27%27%Retrained, fine-tuned, or replaced modelsRetrained, fine-tuned, or replaced models — % adopting: 25%25%Engaged external experts or vendors forreviewEngaged external experts or vendors for review — % adopting: 12%12%

Technical Leadership who reported an incident · n=139 · Wave 3

Benchmark 4.8

AI vibe coding vs AI cybersecurity adoption

Survey question

Thinking about the areas where your organization is currently using AI, which specific AI tools, platforms, or vendors are you using?

Audience
Technical Decision Makers · n=235 answered
In depth
Ch 7 — The Governance Gap
AI tool adoption — coding vs cybersecurity, by maturity tier

+31 pts

adoption gap between AI automated coding and debugging (93%) and AI cybersecurity (62%) among technical decision makers — offense is outrunning defense

Technical Leadership · n=235 answered · Runner n=61 / Jogger n=90 / Walker n=70 / Crawler n=14 · Wave 3

Data for AI tool adoption — coding vs cybersecurity, by maturity tier
CategoryTotalRunnerJoggerWalkerCrawler
Automated coding and debugging93%100%89%93%86%
Vibe coding solutions (low/no-code)78%85%79%76%50%
Cybersecurity and fraud detection62%77%67%53%14%
0%20%40%60%80%100%Automated coding and debuggingAutomated coding and debugging — Total: 93%93%Automated coding and debugging — Runner: 100%100%Automated coding and debugging — Jogger: 89%89%Automated coding and debugging — Walker: 93%93%Automated coding and debugging — Crawler: 86%86%Vibe coding solutions (low/no-code)Vibe coding solutions (low/no-code) — Total: 78%78%Vibe coding solutions (low/no-code) — Runner: 85%85%Vibe coding solutions (low/no-code) — Jogger: 79%79%Vibe coding solutions (low/no-code) — Walker: 76%76%Vibe coding solutions (low/no-code) — Crawler: 50%50%Cybersecurity and fraud detectionCybersecurity and fraud detection — Total: 62%62%Cybersecurity and fraud detection — Runner: 77%77%Cybersecurity and fraud detection — Jogger: 67%67%Cybersecurity and fraud detection — Walker: 53%53%Cybersecurity and fraud detection — Crawler: 14%14%
TotalRunnerJoggerWalkerCrawler

Technical Leadership · n=235 answered · Runner n=61 / Jogger n=90 / Walker n=70 / Crawler n=14 · Wave 3