Security

Security Scene’s Biggest Buzz Is AI... Preparation Lags Even as AX Spreads

IT DAILY ·

Scene from the '2026 Information Security Solutions Conference' held on the 9th at El Tower in Yangjae-dong, Seoul [Photo: Computerworld/IT Daily]

✦ AI Summary

AI security was identified as the biggest security issue in the 2026 Information Security Solution Conference survey, and the share of companies and institutions using AI was found to be 6 out of 10.

In responses on safe AI use, establishing companywide AI guidelines and security policies ranked highest at 36%, but 24% said they recognized the need yet had not prepared.

For areas of increased information security investment over the next year, AI security ranked highest at 79%, while 34% each said their budget was about the same as last year or that they did not know.

AI emerged as the biggest buzzword in the security field. A survey conducted by Computerworld/IT DAILY at the 2026 Information Security Solution Conference held on the 9th at EL Tower in Yangjae-dong, Seoul, showed that the use of AI as a cyber security work tool has begun. The share of companies and institutions using AI was tallied at 6 out of 10, and the scope of use was found to be actual operations or some tasks. Photo provided by Computerworld/IT DAILY.

However, the expansion of interest and use did not directly translate into systematic responses. AI security was chosen as the area for increased investment in the future, but only 36% of organizations said they have AI security guidelines. In addition, 24% said they recognize the need for AI security but are unprepared. For cyber security budgets, many respondents said they were similar to last year or that they did not know the size, underscoring the contrast between actual expansion of use and the level of institutional preparation.

The survey was conducted by Computerworld/IT DAILY on the 9th among attendees of the 2026 Information Security Solution Conference at EL Tower in Yangjae-dong, Seoul. There were 99 respondents. Percentages were calculated by rounding valid responses for each question, and multiple-response questions were tallied based on respondents.

The survey examined this year's key security issues, as well as the authority of CISOs and security officers, cyber security budgets, the level of AI use in security work, safe AI use measures, areas for increased future investment, and difficulties in building zero trust.

In a question asking respondents to select this year's most noteworthy security issue, multiple responses were allowed, and 'security for artificial intelligence (AI)' received the highest response at 82%. Zero trust came next at 40%, and the National Security Framework for Networks (N2SF) ranked third at 38%.

Cloud security was 22%, cyber threats overall, including ransomware, APT, and phishing, were 17%, and software supply chain security was 12%. AI security stood out as the top concern by a wide margin over other items.

Behind these results were concerns about AI being misused as a new attack vector and the growing use of generative AI and AI agents inside companies. Accordingly, establishing a defense framework for AI use and creating a safe AI usage environment were cited as tasks ahead.

In addition, the high ranking of zero trust and N2SF was interpreted as reflecting interest in the field. The direction of interest has centered on continuously verifying the trust level of users, endpoints, and data, and the shift in security systems is also read as a trend toward continuous verification, not just the adoption of new technologies.

In response to a question about the current status of AI use in security work, 36% said they are using it in actual operations. Another 24% said they are running pilot operations for some tasks. Together, organizations using AI in actual or pilot operations accounted for 60%.

With actual operations and pilot operations making up a majority of responses, the findings show AI moving beyond the review stage and into implementation in security work. AI has entered the stage of being deployed in actual tasks such as security monitoring and threat analysis.

Meanwhile, 18% said they are in the stage of considering adoption. Another 15% said they are interested but have no concrete plans. Only 4% said they have no plans to use it.

A large number of organizations have not yet applied AI to their operating environments, but many of them are in the stage of considering adoption or showing interest. The survey confirmed that many organizations that have not yet applied AI in operations are at the stage of considering adoption or expressing interest.

This distribution is interpreted as pointing toward broader areas of application in the future. The range of security tasks using AI is expected to expand.

Photo source: Computerworld/IT DAILY. A survey was conducted on the top priority area for increasing information security investment over the next year. Multiple responses were allowed, with up to 3 choices.

The survey found AI security at 79%, the highest figure. Zero trust ranked second at 32%, a wide gap behind AI security. In the survey on areas for increasing information security investment over the next year, AI security emerged as the most prominent response.

Data and privacy protection followed at 25%, while security monitoring and threat detection also recorded 25%. Cloud and SaaS security came in at 21%, and authentication, accounts, and access management at 13%. Responses for ransomware response, backup and recovery, software supply chain security, and security consulting and penetration testing were each 6%.

Both current areas of interest and actual investment direction are showing a trend centered on AI security. Interest and investment direction are both leaning toward AI security.

The rise in priority for AI security investment is understood to be accompanied by related demand. There was demand for AI-based attack detection and response technologies, and there was also demand for controlling internal employees' use of AI. There was also demand for preventing data leaks, and these needs appear to have worked together.

Photo source: Computerworld/IT DAILY. This section covers the survey results regarding safe AI use measures in relation to areas for increasing information security investment over the next year. Multiple responses were allowed.

In the survey, responses on how to ensure safe AI use took several forms. Among them, establishing companywide AI guidelines and security policies received the highest share of responses at 36%. Some organizations were found to have established companywide policies.

Other responses included 24% who recognized the need but had not prepared, 22% for introducing separate security solutions, 17% for the stage of establishing security measures, and 14% for operating internal security rules by some departments. Twelve percent said they currently had no plan.

This shows that while the number of organizations actually applying AI to security work is increasing, there are differences among organizations in AI control systems. Some organizations have introduced separate solutions, while others recognize the need but have not prepared. A significant number also have no plan.

In the end, it is interpreted that tasks remain in responding to the speed of AI adoption. The need to define the scope of data input, authority, and responsibility in detail was also raised.

In relation to measures for safe AI use, investment direction was centered on AI. However, the overall budget stance was described as wait-and-see, and no clear increase in cyber security budgets was indicated.

In responses about budget changes this year compared with last year, 'about the same as last year' and 'don't know' each accounted for 34%, the largest shares. Based on the response distribution, the largest proportion said the budget was similar to last year or they did not know whether it had changed.

Responses indicating a budget increase were higher than those indicating a decrease. Among responses about this year's budget change compared with last year, 'up by more than 10%' was 16% and 'up by more than 20%' was 10%, for a combined 26%.

By contrast, among responses about this year's budget change compared with last year, 'down by more than 10%' was 3% and 'down by more than 20%' was 2%. The combined share of budget decrease responses was 5%.

Based on this distribution of responses, the investment priority centered on AI security was clear. While investment interest has shifted to AI security, the stance on overall budget expansion remains cautious.

Accordingly, the outlook for investment methods suggests increasing the share of AI-related areas within existing security budgets rather than significantly raising new budgets. This implies a trend of increasing AI-related allocation within existing security budgets rather than substantially expanding the total amount.

In the survey on the authority of CISOs and security officers, the most common response, at 32%, was the perception that security officers can make suggestions but have limited decision-making authority. Another 22% believed they have decision-making authority equal to that of management, and 20% said they have influence over security policy and investment.

In addition, 11% said their position inside the organization is weak relative to their responsibilities, and 10% said it is difficult to judge because the situation varies widely by organization. Another 3% said their role is merely formal and they cannot perform meaningful functions.

The combined share of responses grouped as limited decision-making authority, weak standing relative to responsibility, and a formal role was 46%. The combined share grouped as equal authority with management or influence over policy and investment was 41%.

The gist of remarks on this point was that organizations where the status of security officers has been strengthened coexist with organizations where authority is insufficient for the responsibilities. Based on this, there appears to be a split in the status and authority of security officers by organization.

As interest in zero trust increased, the biggest difficulty in building zero trust was cited as a lack of guidelines and reference cases, at 42%. It was also confirmed that there is a shortage of concrete models and examples showing how to apply it to an organization's environment.

The second-biggest difficulty in building zero trust was the expertise of internal security practitioners at 27%, and the third was management's level of understanding at 22%. The fourth was a lack of momentum due to insufficient government regulations and legal basis, at 10%.

The survey results showed that it is difficult to complete a zero trust framework with technology adoption alone. To do so, management understanding, practical capabilities, and step-by-step application standards were presented as necessary elements.

The key theme identified in this survey was AI security. The scope related to AI security extended across interest, use, and future investment, but budget expansion was limited.

Accordingly, areas needing improvement were identified as safe AI use systems, security officer authority, and zero trust application cases. As a variable in the success or failure of future security investment, organizational policy, authority, and operational system improvements were cited as more important than the speed of AI adoption. Photo source for the article on the role and standing of CISOs and security officers inside organizations: Computerworld/IT DAILY.

A photo provided by Computerworld/IT DAILY deals with the difficulties of building a zero trust framework.

Source: IT DAILY · Kim Ho-jun, Kim Byung-ju, Seong Won-young, Kwon Young-seok
Original: https://www.itdaily.kr/news/articleView.html?idxno=241742

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.