Print this article

Cyber Budgets To Rise As AI Threats Expand – PwC Survey

Editorial Staff

2 October 2026

A survey of 3,934 business and tech executives across 71 countries and territories has found that 84 per cent of security and finance leaders expect their cyber budgets to increase, up from 78 per cent last year. The study is from PwC in its 2027 Global Digital Trust Insights Survey.

AI tops the spending agenda, with 58 per cent of security leaders ranking it among their top cyber budget priorities for the year ahead. Yet half say attacks targeting AI systems are the threat they are least prepared to address. That puts AI ahead of cloud-related threats , third-party breaches and ransomware .

Cybersecurity is a major concern in wealth management, given the desire of criminals and other hostile actors to target wealthy individuals and those who serve them. For example, in early August, the tiny principality of Liechtenstein revealed that registers of beneficial ownership had been attacked by hackers. Family offices are already feeling the impact of weak cybersecurity. Last year, a survey by Deloitte, the accountancy and professional services giant, found that almost half of family offices around the world  suffered a cyber attack in the previous two years. 

The cross-sector survey found gaps in basic resilience. Organizations have implemented, on average, three of seven key data-risk measures, and only 5 per cent have implemented all of them, down from 7 per cent. Fewer than two in five of security, risk and operations leaders have a fully-formalized operational continuity plan that specifically addresses cyber risk.

Governance lags too. A third of chief executive officers and security and risk leaders say their firms have created dedicated AI roles, such as a chief AI officer or an AI board. Fewer than half strongly agree that cyber risk is a standing agenda item for the board or at executive leadership meetings .

Among AI-enabled attacks, leaders feel least prepared for compromise by autonomous botnets , adversarial attacks and data poisoning . They are wary of handing defence to machines. Only 22 per cent would authorize fully autonomous execution by AI agents for cyber defense. The main barriers cited are the reliability and maturity of the technology and accountability and explainability . Some 44 per cent of chief information security officers point to a shortage of skills in AI oversight and governance.

Firms are responding by spreading concentration risk. Over half are adopting multi-cloud or hybrid cloud strategies, 47 per cent are strengthening regional data and technology redundancy, and 37 per cent are localizing infrastructure within specific jurisdictions. Half are changing the way they manage vendor, third-party and supply chain risk in response to geopolitics.

“AI is changing both sides of the cyber equation. It is creating new risks and expanding the attack surface, but it can also transform how organizations defend themselves,” said Avinash Rajeev, global cyber, data and tech risk leader at PwC US.

For financial firms in the EU, third-party and concentration risk is also a compliance matter. The Digital Operational Resilience Act, or DORA, has applied since January 2025, requiring firms to manage information and communication technology third-party risk and report major incidents.