“As cyber risks shift, PwC finds that businesses are prioritising AI and cloud security above all else for their cybersecurity budgets.”
AI is now the top priority for cybersecurity leaders when planning their cyber-budgets, overcoming talent shortages, and strengthening defence capabilities over the next year, according to PwC’s 2026 Global Digital Trust Insights survey.
The survey, carried out between May and July 2025, polled 3,887 business and technology executives. In India specifically, the report is based on responses from 138 executives.
PwC found that under half of organizations feel “very capable” of managing key vulnerabilities — including unpatched software (57%), weak authentication (55%), endpoint visibility (55%), and supply-chain issues (52%) — with legacy systems (45%) being among the weakest areas.
Sundareshwar Krishnamurthy, Partner and India Cyber Leader at PwC India, highlighted how cyber is now central to business strategy: with 72% of Indian firms prioritising cyber risk at the board level, the approach is shifting from reactive defence to foresight-driven resilience. Krishnamurthy pointed out that while AI, cloud security, and managed services are key investment areas, many firms are still unprepared for third-party breaches or quantum risks — and the talent gap, especially in AI-driven defence and post-quantum cryptography, remains a major hurdle.
In India, 87% of organisations expect their cyber-security budgets to grow in the next 12 months; nearly one-third plan to increase their spend by more than 10%, and 38% anticipate a 6–10% hike.
Within that budget, 46% of Indian leaders intend to prioritise AI, followed by 33% for cloud security and 28% for managed security services.
When it comes to specific AI capabilities, 60% of security leaders in India are focusing on AI-powered threat hunting, and 47% are looking at agentic AI.
On quantifying cyber risk, around half of organisations now use risk-quantification techniques to estimate the financial impact of cyber threats.
Meanwhile, 25% of firms reported that their worst data breach in the last three years cost them at least US$1 million — a figure that climbs to 45% for enterprises with revenues of US$5 billion or more.
Talent remains a significant barrier: 60% of respondents cited a lack of understanding of AI for cyber defence, while 50% pointed to a shortage of relevant skills. To address this, companies are prioritising investments in AI/ML tools (61%), consolidation of cyber tools (51%), automation (49%), and upskilling or reskilling (49%).
Beyond AI, the skills gap extends to securing industrial systems: 55% of leaders said the lack of qualified personnel is a top challenge for protecting OT and IIoT environments.
Quantum risk is also on the radar — but readiness is low. While quantum threats rank high among the least-prepared risks, nearly 40% of surveyed organisations haven’t even started quantum-resistant security measures, citing lack of understanding, limited resources, and competing priorities.


