Introduction
For Chief Information Officers (CIOs), AI is both a problem and a solution. On one hand, it could helpthem to increase their organization’s cyber resilience. On the other, adversaries are using it to deploy
increasingly sophisticated types of cyber attack. In LevelBlue’s latest cybersecurity research, we find
out how CIOs are tackling this challenge. Are they embedding a stronger culture of cyber resilience and
investing in proactive threat detection to prepare for the next phase of AI?
CIOs see AI as a way to build resilience
AI is creating business appetite for transformation, and CIOs have identified this as an opportunity to secure C-suite buy-in for new cyber-resilience measures. By framing the cyber-resilience conversation as an opportunity to support business growth and innovation, and reduce operating costs, they can build a robust business case for investment in AI security tools:- Cost reduction: 62% of CIOs say that the business has spent more on responding to cybersecurity
threats than it has on preventing or detecting them over the past two years. - Risk reduction: 46% say that a cyber breach will be more damaging if the security strategy does not
become more proactive. - Growth: 71% of CIOs say their adaptive approach to cybersecurity enables the company to take greater risks with innovation.
ability to defend itself. Two-thirds of CIOs say it is becoming more difficult for employees to identify what is real and what is fake. And nearly three-quarters (72%) say that implementing AI-driven cybersecurity tools will be essential for improving their organization’s threat detection and response
capabilities.In 2026, CIOs have an opportunity to improve understanding of the risks and align the enterprise behind a response. About three-quarters (73%) say that media reports of high-profile breaches have pushed cybersecurity up the C-suite agenda. This increased awareness – combined with the business case outlined above – gives them a way to secure investment for cyber resilience from decision-makers.
CIOs believe that better collaboration increases resilience
Only one-third of CIOs describe alignment between cybersecurity teams and the wider business as “highly effective.” They seem keen to fix that. Our research shows that 49% will prioritize integrating cybersecurity into lines of business and across all projects over the next 12 months. This is their number-one ambition by a significant margin, and is well ahead of the 38% average across all leadership roles.Another problem is the lack of top-down commitment to cyber resilience: 47% of CIOs say that executive leadership not prioritizing cyber resilience is a barrier to improvement. In response, they are targeting their senior peers as a way to change behaviors more broadly across the business: 39% will focus on increasing boardroom engagement in cyber resilience discussions over the next 12 months, compared with just 19% who are focusing on educating the workforce as a priority.The data identifies exactly where better alignment with leadership teams could improve cyber resilience:- Less than half say the organization has set key performance indicators (KPIs) that effectively connect cybersecurity with business outcomes
- A similar number do not believe that the business risk appetite has been effectively aligned with cybersecurity risk management
- Less than one-third say their due diligence in mergers and acquisitions is effective


CIOs are bracing for new types of attack
CIOs are taking the threat of attack far more seriously than the broader leadership team. Our data shows that they are more likely than other senior executives to believe that every type of attack will occurin the next 12 months.They are particularly concerned about AI-powered attacks: 51% say these are likely in the next 12 months, compared with only 42% of senior executives overall. But only one-third of CIOs say their organization is prepared to manage the threat.That lack of preparation could come from misaligned investment strategy. CIOs are far more likely than senior executives overall to say they are committing moderate to significant investment in:
- Cyber resilience processes across the business (79% of CIOs compared with 67% of senior executives overall)
- Application security (78% vs 69%)
- Machine learning for pattern matching (76% vs 67%)
- Generative AI for social engineering attacks (70% vs 64%)
specialists; just 23% have done this over the past 12 months. And 36% plan to work with threat intelligence providers in the next two years, compared with 26% over the past 12 months.

CIOs highlight software supply chain vulnerabilities as AI accelerates
More than half of CIOs (56%) believe that software supply chain attacks are imminent, and most say theyneed to bolster software supply chain resilience. They are more likely than the other senior executives to say that this aspect of cyber resilience is high risk, and just 22% say they have a highly effective view of the software supply chain.Asked about what is driving a need for better software supply chain visibility, CIOs say they are most concerned about source code. They want a better understanding of its origins and also to gain oversight of its integration quality. Regulation is another important reason to improve visibility: needing to complete the Software Bill of Materials (SBoM) is CIOs’ third most important factor.CIOs are also wary of the risks third parties can create for the business:
- 59% see third-party software distribution channels as somewhat or very risky, compared with 49% of senior executives overall
- 57% say the same about third-party risk management, compared with 49% of senior
executives overall

Four ways for CIOs to prepare the organization for AI-powered cyber resilience






