97% of organisations faced breaches or security incidents related to GenAI this year

97 per cent of organisations using generative AI have faced security incidents or data breaches linked to the technology this year, according to Capgemini Research Institute.

  • Tuesday, 3rd December 2024 Posted 4 months ago in by Phil Alsop

As generative AI becomes more integrated into business operations, over half of these companies (52 per cent) reported financial losses exceeding $50 million, prompting 62 per cent to request larger budgets to mitigate risks.

The surge in cyber threats, including data poisoning, deepfakes, and data leakage, is worsened by employee misuse and highlights the growing vulnerabilities introduced by generative AI.

However, while AI expands the cyberattack surface, it also offers significant benefits. 60 percent of companies surveyed consider AI crucial for faster and more accurate threat detection and response. Over half (58 per cent) also believe AI will strengthen proactive defence strategies, allowing cybersecurity teams to focus on combating complex threats.

Despite these advancements, generative AI remains contentious. It empowers security teams with tools to detect and mitigate risks more efficiently but also introduces new challenges that require continuous monitoring, ethical guidelines, and robust employee training.

Reacting to the findings, Andy Ward, SVP international of Absolute Security, commented: “AI is transforming the cybersecurity landscape, being used for both attacks and defence as a double-edged sword. While AI’s capabilities can detect threats faster and enable proactive defences, the fact that almost all of organisations using generative AI have reported security incidents highlight the urgent need to bolster cyber resilience.

“These AI-powered attacks typically come in the form of generative-AI generated phishing attacks or AI-driven malware, but increasingly, cybercriminals are also using AI to identify lucrative targets for ransomware attacks and to personalise the ransom demands in search of larger pay outs.”

“Our research found that 54 per cent of CISOs feel unprepared to handle AI-powered threats, with AI expanding attack surface and introducing new vulnerabilities. To mitigate these risks, organisations must implement robust network visibility to monitor devices and applications for suspicious activity, freezing, or shutting off, potentially compromised devices in order to minimise the risks of AI-driven threats.”

Earlier this year, Microsoft researchers found that UK organisations using AI tools for cybersecurity were twice as resilient to attacks as those that didn’t. The study also concluded that boosting AI adoption could save the UK economy £52 billion annually, down from the £87 billion lost to cyberattacks each year.

“The use of AI and Gen AI has so far proved to be a double-edged sword. While it introduces unprecedented risks, organisations are increasingly relying on AI for faster and more accurate detection of cyber incidents. AI and Gen AI provide security teams with powerful new tools to mitigate these incidents and transform their defence strategies. To ensure they represent a net advantage in the face of evolving threat sophistication, organizations must maintain and prioritize continuous monitoring of the security landscape, build the necessary data management infrastructure, frameworks and ethical guidelines for AI adoption, and establish robust employee training and awareness programs,” said Marco Pereira, Global Head Cybersecurity, Cloud Infrastructure Services, Capgemini.

AI agents break cover

Posted 1 day ago by Phil Alsop
In a global survey of IT leaders, Cloudera found that enterprises are keen on AI agents, but fears around data privacy, integration, and data quality...
Economist Impact is pleased to announce the inaugural AI Compute summit, scheduled for May 22nd 2025, at the Scandic Copenhagen in Copenhagen. This...

Majority of AI projects don't make it to market

Posted 2 days ago by Phil Alsop
SS&C Technologies Holdings has published findings from a new survey: governance, process orchestration and strategic planning are critical to...

Security and compliance risks make VPNs obsolete

Posted 2 days ago by Phil Alsop
Zscaler has published the Zscaler ThreatLabz 2025 VPN Risk Report, commissioned by Cybersecurity Insiders, which highlights the widespread security,...

AI tops tech growth charts

Posted 6 days ago by Phil Alsop
Despite high interest rates, economic slowdown, stricter regulations on big tech and AI, Trump's tariff policies, and global trade wars, which hit...

94% increase in network malware

Posted 1 week ago by Phil Alsop
Other key findings show an increase in crypto miner detections, a spike in zero-day malware, a drop in endpoint malware, a rise in Linux-based...

Data is not AI-ready

Posted 1 week ago by Phil Alsop
Despite rapid hybrid cloud adoption, enterprises struggle with file data migration, falling behind in AI-driven efficiencies and effective security.
96% of organizations attacked by ransomware said backups were targeted.