Study Finds IT Leaders Overconfident About AI-Driven Cyber Risks

Summary
Deep Instinct’s survey of 500 U.S. IT professionals found widespread confidence in defenses against AI-generated malware, despite the company’s test showing many legacy tools missed the samples tested.
Key points
- Deep Instinct surveyed 500 U.S. IT professionals about AI-related cyber risks and their organizations’ defenses.
- 64% of respondents believed fewer than one million pieces of AI-generated malware are created each day; the article says estimates based on detected malware may undercount the total.
- In a Deep Instinct test, 65 of 73 legacy tools failed to detect the AI-generated malware samples tested. The article cautions that this test does not establish the volume of malware in the wild.
- 86% of respondents believed their existing tools could stop AI-generated malware before execution; 42% of directors and above were very confident, compared with 24% of frontline staff.
- Only 26% of finance-sector respondents were very confident in stopping AI-generated attacks before execution, compared with 46% in technology and software.
- The article argues that reliance on legacy detection models may leave organizations less prepared as attackers automate malware creation, and advocates pre-execution defenses. It is published by a security vendor promoting its approach.
Article Details
- Publisher
- Deep Instinct
- Scope
- Survey of U.S. IT professionals about AI-generated malware, confidence in existing defenses, and AI adoption.
- Sample Size
- 500 U.S. IT professionals
- Key Statistics
- 64% of surveyed IT professionals believed fewer than one million pieces of AI-generated malware are created daily.
- In a test by Deep Instinct threat analyst Brian Black, 65 of 73 legacy tools failed to detect AI-generated malware, an 89% miss rate. Deep Instinct cautioned against using this result to estimate global malware volume.
- 86% of surveyed IT professionals believed their existing tools could stop AI-generated malware before execution.
- Directors and above were more likely than frontline staff to be very confident their organization could stop malware attacks: 42% versus 24%.
- 26% of finance-industry respondents were very confident they could stop AI-generated attacks before execution, compared with 46% in tech and software.
- Recommendations
- Reassess confidence in existing defenses against AI-generated malware rather than relying on assumptions about their effectiveness.
- Deep Instinct recommends moving beyond legacy detection models toward deep learning-native, pre-execution protection.
People
Malware
Vendors
Deep InstinctWhen Deep Instinct threat analyst Brian Black put legacy tools to the test using AI-generated malware, 65 of 73 failed to detect it, a staggering 89% miss rate. If similar patterns hold in production environments, theSitusAMCdeclining confidence is not theoretical. Recent attacks, such as the breach at financial services vendor SitusAMC, which exposed sensitive data tied to major banks, show how even well-defended institutions remain
Countries
Industries
Financial ServicesFor decades, the finance services industry has been at the bleeding edge of cybersecurity – navigating a business environment where risk evaluation is uncompromising, controls are mature, and security spend isHealthcareHealthcare, for instance, is already struggling to keep pace. Its attack surface is large, porous, aging, and expanding faster than security leaders can reinforce it. Healthcare environments remain deeply dependent onTechnologyMeanwhile, tech and software show the highest confidence (46% very confident), despite operating in some of the most rapidly changing and highly targeted environments.