Vanta’s third State of Trust report shows that AI is accelerating risk faster than most organizations can govern it, while budgets, staffing, and compliance time remain stuck. The report highlights rising vendor breaches, growing trust demands, and the rapid adoption of agentic AI—alongside major gaps in control, readiness, and oversight. #Vanta #agenticAI #AI
Keypoints
- Annual trust and cybersecurity reports like this typically open with an executive introduction, followed by key findings, then deeper sections organized by theme. Common sections include risk trends, AI readiness, governance and compliance challenges, third-party/vendor risk, automation benefits, a conclusion with recommendations, and a methodology section explaining the survey scope and sample.
- This report is based on a survey of 2,500 business and IT leaders across the U.S., UK, and Australia, giving it a broad global perspective on trust management and security operations.
- The headline finding is that 72% of security decision-makers say overall risk is at an all-time high, up sharply from 55% in 2024. More than half also report threat activity at least weekly, showing that continuous attacks have become the norm.
- Despite rising risk, budgets are not keeping pace: organizations spend 10% of IT budgets on security versus a 17% ideal, compared with 11% versus 17% in the prior year. This indicates a persistent funding gap even as exposure increases.
- AI-related threats are growing quickly, with roughly half of businesses seeing more AI-generated phishing, AI-powered malware, and AI-driven identity theft or fraud. Larger organizations report even higher rates, suggesting that scale increases the attack surface and the frequency of AI-enabled abuse.
- The report emphasizes an AI readiness gap: 79% are using or planning to use agentic AI, yet 65% say adoption outpaces understanding. Only 48% have a framework to limit autonomy, showing that governance is lagging behind deployment.
- AI threats are also outpacing expertise, with 59% saying AI-related security threats exceed their team’s knowledge. That figure rises to 67% in larger companies, reinforcing the need for AI-specific controls, playbooks, and response processes.
- Governance around AI data use remains weak: 41% apply strict data minimization, 35% rely solely on anonymized data for AI training, and only 31% use customer data with opt-in requirements. At the same time, 44% have now implemented a company AI policy and 45% conduct regular AI risk assessments, both up from last year.
- Agentic AI is becoming mainstream in security operations, especially for forensic log analysis, automated threat correlation, compliance reporting, and vulnerability prioritization. However, only 48% have a governance framework, and 62% worry that agentic AI could erode customer trust.
- The report shows a major shift in attitudes toward autonomy: 71% are comfortable with agentic AI in an advisory role, and 61% would trust it to override human decisions in some scenarios. Even so, the report cautions that autonomous actions should be limited to pre-approved, reversible controls with human oversight for high-impact decisions.
- Trust has become a business requirement rather than a nice-to-have: 82% say better security and compliance increase customer trust, and 77% say stakeholders now demand verified proof of compliance. This reflects a broader move from promise-based assurance to evidence-based trust.
- Security teams are spending too much time on proof rather than protection: 61% say they spend more time proving security than improving it, and 64% describe current frameworks as “security theater.” Compliance work now takes about 12 weeks per year, up from 11 weeks in 2024.
- Third-party risk remains a major operational burden. Teams spend about 9 working weeks per year on vendor reviews, and 56% have experienced a vendor breach in the past 6–12 months, up from 48% last year. In response, 57% have terminated a vendor relationship over security concerns.
- The vendor section highlights a growing mismatch between confidence and reality: 80% believe vendors would disclose a breach, yet breach frequency and vendor terminations continue to rise. This points to the need for continuous monitoring rather than static questionnaires and annual audits.
- Automation is presented as the clearest way to reduce friction and improve outcomes. Ninety-five percent say AI and automation improve security team effectiveness, and 79% report increasing AI use in security programs.
- Top benefits of automation include faster risk assessments (51%), improved accuracy (50%), faster incident response and remediation (48%), more time for strategic work (48%), better collaboration (40%), and streamlined compliance (36%).
- The report also notes a human impact: 76% say AI is reducing burnout by removing repetitive manual work. This suggests automation is not just an efficiency tool, but a workforce sustainability measure.
- Recurring themes across the report include rising attack volume, accelerating AI-driven threats, weak governance, vendor ecosystem risk, and the shift from manual compliance to continuous assurance. The overarching takeaway is that trust must be measurable, automated, and continuously proven to keep pace with modern threats.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)