AI & Automation

Only 8% of Organizations Run AI Incident Drills Regularly, and 64% Have Never Run One

ISACA's survey of more than 1,800 security professionals finds AI spreading through security operations faster than the planning around it. DigiCert and Kiteworks show the same gap from the governance side.

October 2, 2026 · AI & Automation
Rows of empty black office chairs facing monitors in a dimly lit operations center, with a wall of blue screens behind them

Key Takeaways

  • ISACA's 2026 State of Cybersecurity survey of more than 1,800 professionals found only 8% of organizations conduct regular AI-specific response exercises, while 64% have run none at all.
  • Some 48% of respondents either lack an AI incident playbook or do not know whether one exists, even as 41% now use AI to automate threat detection and response, up from 32% a year earlier.
  • DigiCert reports that 90% of organizations discuss AI governance at the C-level but only 50% have built a program, and half lack centralized visibility into the AI systems they run.
  • Kiteworks found 65% of organizations discovered employees using unapproved AI tools with sensitive data, yet only 27% have deployed AI-specific data loss prevention.

Most security teams can tell you how fast they would restore a server after ransomware, because they have practiced it. Ask the same teams what happens when an AI agent exposes customer records or a model starts leaking data through a prompt, and the honest answer is that they have never tried it. New survey data suggests that is the normal condition, not the exception, and that AI is being wired into security operations faster than the planning around it is being written.

Adoption Sprinted While the Playbooks Stayed Blank

ISACA's 2026 State of Cybersecurity survey, published September 22 and drawing on more than 1,800 security professionals worldwide, puts the gap in plain numbers. Only 8% of organizations run AI-specific response exercises on a regular basis, and 64% have not conducted a single AI-related incident response exercise. Another 48% either confirm they have no AI incident playbooks or do not know whether any exist, which is arguably the more worrying figure, because it means the plan is not just untested but invisible.

Meanwhile the technology keeps moving into the security stack. ISACA reports that 41% of respondents now use AI to automate threat detection and response, up from 32% in 2025, and 40% use it for routine security tasks, up from 28%. Some 45% name large language model security operations as a skill gap, a 12-point rise in a year. Jon Brandt, ISACA's senior director of professional practices and innovation, summed up the pattern: AI is becoming embedded in security operations, but many organizations have not matched that adoption with the response planning and workforce readiness needed to manage the risk.

Governance Talk Is Ahead of Governance Work

The same shape appears in DigiCert's AI Trust Outlook, reported by SD Times in July. It found that 90% of organizations discuss AI governance at the C-level, but only 50% have developed programs. Some 78% of enterprises reported AI-related security incidents or identified vulnerabilities, and 50% lack centralized visibility into their AI systems even though 75% deployed four or more AI-driven systems in the past six months. A further 47% cannot fully trace AI decisions back to models and source data. DigiCert's Brian Trzupek framed the choice as whether organizations can explain, govern and trust the AI they have already deployed.

The data layer is just as exposed. Kiteworks' 2026 survey, published July 29, found 80% of organizations hit by a security or AI-related incident in the past year, and 65% had discovered employees using unapproved AI tools with sensitive data. Customer data appeared in 36% of those cases and IT credentials in 33%. Only 27% have deployed AI-specific data loss prevention, no AI containment control was deployed by more than 31% of respondents, and half could not produce a complete audit trail within one business day.

Why a Drill Beats Another Policy Document

Put the three surveys together and a pattern emerges. Organizations are deploying AI systems, discussing them in the boardroom, and logging incidents, but the operational muscle of rehearsal is missing. A response exercise forces answers that a policy never does: who can shut an agent down, which credentials it holds, where its logs live, and which regulator or customer must be told. An organization that cannot trace an AI decision to its source data, as 47% in the DigiCert sample cannot, will discover that gap in the middle of an incident rather than in a conference room.

Nobody gets credit for a drill that finds nothing, which is why so few organizations run one. The surveys suggest the cheaper lesson is the one learned on a Tuesday afternoon in a tabletop, not the one learned after the first real incident.

Share

More in AI & Automation

All Resources →