$ techbeacon▋
Threats

PwC Study Shows AI Attacks Emerge as Top Cybersecurity Concern Globally

PwC Study Shows AI Attacks Emerge as Top Cybersecurity Concern Globally

A new PwC survey of senior security executives indicates that attacks on artificial‑intelligence (AI) systems now rank as the most pressing threat facing organisations worldwide, exposing a notable gap in current cybersecurity readiness.

The research, which gathered input from security leaders across a broad range of industries and regions, found that a majority of respondents view AI‑related breaches as more likely and potentially more damaging than traditional threats such as ransomware or phishing. While the study did not disclose exact percentages, the consensus points to a growing unease about the vulnerability of machine‑learning models, data pipelines and automated decision‑making tools.

Experts cited several factors that make AI infrastructures attractive to adversaries. Complex model architectures often rely on large volumes of proprietary data, creating high‑value targets. In addition, many organisations deploy AI components without the same level of security testing applied to conventional IT assets, leaving gaps that can be exploited for model poisoning, data exfiltration or manipulation of automated outputs.

This shift in threat perception marks a departure from the focus that dominated the past decade, when ransomware and credential‑based attacks were the headline concerns for security teams. As AI becomes embedded in critical functions—from fraud detection to supply‑chain optimisation—its compromise could have cascading effects far beyond the initial breach, potentially undermining business continuity and regulatory compliance.

PwC warns that the current state of preparedness is insufficient. Companies are urged to integrate AI risk assessments into existing security frameworks, allocate dedicated resources for model‑level testing, and ensure that governance structures keep pace with rapid AI adoption. The firm also highlights a talent shortfall, noting that many security departments lack staff with specialised knowledge of machine‑learning security.

To address these challenges, PwC recommends a multi‑layered approach: establishing clear ownership for AI security, embedding threat‑modeling early in the development lifecycle, conducting regular red‑team exercises that target AI components, and fostering cross‑functional collaboration between data scientists and security professionals. The report stresses that proactive measures are essential to avoid reactive firefighting after a breach.

Industry observers say the findings could spur both private‑sector and regulatory action. Governments are already debating standards for trustworthy AI, and the heightened awareness of AI‑specific risks may accelerate the development of guidelines that mandate robust security controls. As organisations grapple with the dual pressures of innovation and protection, the gap highlighted by PwC is likely to shape cybersecurity strategies for the foreseeable future.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related