ISC2’S Security Study Finds an Overburdened Workforce Embracing AI


Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

  • While the escalation in cybersecurity cuts leveled off in 2025, the ISC2 survey showed economic instability is keeping IT budget expansion in check, which is a cause for concern that organizations will hold off on making needed investments in cybersecurity.
  • AI is changing the IT industry as a whole, and cybersecurity specifically. Seen as both an offensive weapon and a potential defensive shield, security professionals see the technology as opportunistic for their careers rather than a threat to job security, offering them a chance to hone their skills and improve their professional trajectory.

One of the most significant challenges in cybersecurity is the resource constraints and skills gaps that plague so many organizations. Add to the mix technologies like AI that enterprising threat actors are all too eager to insert into their arsenals, and the issue of staff limitations is magnified. In its 2025 ISC2 Cybersecurity Workforce Study, the non-profit association uncovered a profession balancing the struggle to keep ahead of increasingly sophisticated adversaries while also savoring the chance to leverage AI and other technologies to elevate their defenses. The annual study of industry workplace trends, which surveyed 16,020 security professionals globally, found resource constraints are front and center in impacting the cybersecurity workplace.

Continue reading “ISC2’S Security Study Finds an Overburdened Workforce Embracing AI” →

Verizon Mobile Security Index: In the AI Era, the Human Element Remains the Weak Link


Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

  • To protect an expansive mobile environment attack surface in the face of a very dangerous threat environment, organizations are ramping up their security investments, with 75% of the 762 polled in a recent Verizon study reporting they had increased spending this year.
  • But concerns still loom large threat actors using AI and other technologies and tactics to breach the enterprise; and only 17% have implemented security controls to stave off AI-driven attacks.

Mobile and IoT devices play an essential role in most organizations’ operations today. However, the convenience and flexibility they bring comes with risk, opening new points of exposure to enterprise assets. Organizations that were quick to embrace bring your own device (BYOD) strategies often didn’t have a solid plan for safeguarding this environment when so many of these devices were under-secured. Enterprises have made progress in layering their defenses to better protect mobile and IoT environments, but there is still room for progress.

Continue reading “Verizon Mobile Security Index: In the AI Era, the Human Element Remains the Weak Link” →

LevelBlue Research Finds Manufacturing Organizations are at Risk and Underprepared for Cyber Threats

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

  • As part of a larger global cross-industry study, LevelBlue surveyed executives in 220 manufacturing companies to gauge the state of their cyber resilience strategies in the era of AI-driven threats and other risks
  • Awareness is high but also so are concerns, with 37% saying they are seeing a significantly higher volume of attacks; just 30% said their organization is prepared for deepfake attacks, even as 47% are anticipating them

Threat actors are savvy when choosing their targets. Manufacturing holds a strong appeal to cyber criminals because the profit potential associated with intellectual property is high and, thanks in part to supply chain vulnerabilities, there are plenty of points of exposure. A recent LevelBlue survey of 220 manufacturing executives found that while awareness about the threat environment is high, preparedness, especially for AI-driven attacks, is not.

Continue reading “LevelBlue Research Finds Manufacturing Organizations are at Risk and Underprepared for Cyber Threats” →

Verizon Frontline Research Shows an Uptick in the Use of Advanced Technology by First Responders on the Horizon

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Though just 12% of public safety workers currently use AI everyday, 46% anticipate it will become part of their daily work by 2030.

• With an increasing emphasis on using network-dependent technologies like connected cars and drones, network reliability – or the lack thereof – is the top concern of 67% of those surveyed.

As essential as first responders are, public safety officials aren’t necessarily known for deploying leading-edge technology. But results from the fifth annual Verizon Frontline Public Safety Communications Survey suggest this may be changing. The survey results of 1,028 first responders – i.e., EMS, fire, police, emergency management, public safety, and emergency communications workers – find that while advanced technologies like AI and drones are broadly used today, they expect wider implementation through 2030.

Continue reading “Verizon Frontline Research Shows an Uptick in the Use of Advanced Technology by First Responders on the Horizon” →

OpenText Survey Shows AI is Driving MSP Growth but a Skill Deficit Remains an Issue

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• In its annual Global Managed Security survey of 1,019 managed services providers (MSPs) in the US, Canada, and the UK, security vendor OpenText uncovered a big delta between the desire to exploit SMB demand for AI-driven solutions and the capability of these providers to deliver the essential support.

• Approximately 92% said they are seeing growth driven by client interest in AI but only half have the adequate resources and expertise to help clients deploy these solutions.

Organizations of all sizes are boarding the AI bandwagon. For smaller businesses lacking internal AI expertise, adoption often requires the support of an external provider. Unfortunately, that same resource limitation also plagues many of the MSPs SMBs seek out for AI support. In a recent OpenText survey of 1,019 security practitioners, IT managers, and customer relationship managers, in the coming year 96% expect to see growth in demand driven by interest in AI. However, half said a combination of factors leaves them under-prepared to support SMB AI needs, including a lack of internal expertise, too many disparate tools to manage, and the lack of standardization across different client environments.

Continue reading “OpenText Survey Shows AI is Driving MSP Growth but a Skill Deficit Remains an Issue” →

Ransomware Spikes as Threat Actors Leverage AI to Launch Campaigns

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Fueled both by its lucrative results and AI-driven toolkits that lower the barrier of entry for enterprising yet inexperienced bad actors, ransomware incidents are soaring.

• In 2024, ransomware drove 44% of data breaches around the world and accounted for 54% of those in APAC, according to the 2025 Verizon Data Breach Investigations Report (DBIR).

As is the case with any IT security breach, it is no longer a question of if but when an enterprise might be hit with ransomware. Motivated in large part by profit potential, cybercriminals are drawn to ransomware as a mechanism to extort money. As a result, ransomware incidents are on the rise with the 2025 Verizon DBIR finding the number has increased 37% in 2024 versus the prior year.

Continue reading “Ransomware Spikes as Threat Actors Leverage AI to Launch Campaigns” →

Reality Check: Accenture Research Shows Enterprises Face a Security Deficit in the AI Era

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

  • In a survey of 2,286 technology and security-focused executives, Accenture reports that only 34% have a mature cybersecurity strategy.
  • Just 20% say they are confident in their ability to protect their generative AI (GenAI) models from a breach.

Artificial intelligence (AI) presents as a double-edged sword for many enterprises. The technology has the potential to revolutionize business processes and drive further innovation but is protecting the model from advancing threats that could compromise the integrity of data output. This is a daunting challenge that few organizations have a handle on today. Add threat actors harnessing AI for their own nefarious purposes to the mix, and the situation becomes much more daunting for the enterprise.

Continue reading “Reality Check: Accenture Research Shows Enterprises Face a Security Deficit in the AI Era” →

Enterprises Take Up Arms Against Perilous Threats but Still Struggle with Unwieldy Security Tools

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

  • Enterprises are under constant threat with no signs of abatement. The Verizon 2025 Data Breach Investigations Report (DBIR) notes a 37% rise in ransomware versus 2024.
  • Cisco’s May 2025 State of Security Report found that 59% of the 2,058 security professionals surveyed spend excessive resources maintaining tools and affiliated workflows.

The nature of cybersecurity is dynamic, as the threat landscape is in constant flux, making the discipline a daunting exercise environment for security practitioners. Even well-resourced organizations struggle to manage risk effectively as bad actors apply a combination of advanced technology and sophisticated techniques to exploit enterprise vulnerabilities. Verizon’s 2025 Database Investigations Report (DBIR), an examination of 22,052 security incidents, 12,195 of which were verified to be data breaches, found that in 20% of all breaches, vulnerabilities were the entryway for a breach. This makes it the second most common initial avenue for a breach, just behind credential abuse.

Continue reading “Enterprises Take Up Arms Against Perilous Threats but Still Struggle with Unwieldy Security Tools” →

Facing an Exodus of Healthcare Workers, Providers Turn to AI but are Overlooking Important Strategic Elements

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

  • With the demographic that represents the biggest healthcare consumer spiking at the same time hundreds of thousands of healthcare workers are leaving the sector in droves, the industry is looking to artificial intelligence (AI).
  • An Accenture survey of healthcare provider executives found that while most are piloting AI projects, the ad hoc approaches many are taking may find them coming up short of their full potential.

There is a perfect storm hitting the healthcare industry. The population of 60- to 90-year-olds, the largest users of healthcare services, is projected to spike by 45% over the course of the next 20 years. This comes as a post-pandemic flight of healthcare workers is happening. The National Council of State Boards of Nursing (NCSBN) projects that 900,000 nurses in the US will leave their positions by 2027.

Continue reading “Facing an Exodus of Healthcare Workers, Providers Turn to AI but are Overlooking Important Strategic Elements” →

US Federal Government Demands IT Consulting Firm “Defends the Spend” in a Bid to Take Back Some of the $65 Billion Committed to Contracts

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• The US administration is making clear its aim to improve government efficacy and slash expenses across the board.

• In IT, the General Services Administration (GSA) singled out its 10 largest consulting partners, demanding they justify their contracting value to reduce the current $65 billion public sector spend.

Change is inevitable with administration transitions, but the sharp pendulum swings the Trump US presidency brought with it have been swift and dramatic. There is no surprise that cuts were coming, but the shock is the speed and scale at which it is happening, and the profound impact these moves are having on IT specifically.

Continue reading “US Federal Government Demands IT Consulting Firm “Defends the Spend” in a Bid to Take Back Some of the $65 Billion Committed to Contracts” →