Cybersecurity AI: what is getting real adoption now?

Last updated: 11 September 2026
market research pitch 2026 statistics cybersecurity market

In our cybersecurity market deck, you will find everything you need to understand the market

SUMMARY

Cybersecurity AI: what is getting real adoption now? Threat detection, phishing triage and incident investigation already have strong production adoption, while routine response is moving quickly and broader autonomous security remains much earlier.

The biggest change is happening after an alert fires. Detection was already heavily automated; newer generative and agentic systems are increasingly taking over the manual investigation work that used to sit between an alert and an analyst decision.

Production scale is becoming hard to dismiss. Individual deployments now process tens of thousands of alerts, remove hundreds of analyst hours each month and run thousands of autonomous investigations every day.

The strongest cybersecurity AI use cases share the same shape: huge volumes, repetitive decisions, rich internal telemetry and an output that humans can check. Adoption gets thinner as the AI receives broader authority or faces ambiguous situations.

Phishing triage is probably the cleanest current example. The workflow is repetitive enough for AI to gather most of the evidence itself, while uncertain cases can still be escalated without giving the system dangerous levels of control.

Security copilots are also changing form. The products gaining traction increasingly sit inside endpoint, identity, cloud and SIEM platforms, where they can retrieve evidence and take actions rather than simply answer cybersecurity questions in a chat window.

Autonomous cybersecurity is already real at the workflow level. Some organizations automate most routine investigations or case resolution, but high-consequence actions such as major containment and sensitive identity changes still tend to carry stricter approval thresholds.

The economics improve sharply when AI removes cases from human queues rather than merely making analysts slightly faster. Several production deployments report major reductions in false positives, resolution times and Tier 1 workload, although platform consolidation and conventional automation contribute to those gains too.

Two newer markets are forming around the AI boom itself: securing AI applications and controlling AI-agent identities. Prompt injection, agent permissions, unmanaged credentials and access to sensitive company systems are becoming ordinary security problems as enterprises deploy more AI.

The dividing line is increasingly clear. Cybersecurity AI gets adopted when it eliminates a measurable queue of repetitive work inside boundaries security teams understand; claims become much harder to support when vendors move toward the idea of an AI independently protecting an entire company.

Market map chart showing top companies and startups in the cybersecurity market

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market

Is cybersecurity AI actually getting real adoption right now?

Cybersecurity AI is already getting real adoption today, especially in threat detection, phishing triage, incident investigation and repetitive SOC work.

The broad adoption numbers have become hard to dismiss. In its latest survey of 536 cybersecurity and IT practitioners, SANS found that 78% were using AI in cybersecurity, up from 50% a year earlier. The World Economic Forum reached almost exactly the same level in a separate survey: 77% of organizations said they had adopted AI for cybersecurity.

Those figures still need some unpacking. They include everything from mature machine-learning detection to new generative-AI assistants and autonomous agents. Only 27% of respondents in the latest SANS research described their AI deployment as mature production. Plenty of companies are therefore using AI without having redesigned their security operations around it.

The stronger evidence comes from what is happening inside actual SOCs. Microsoft says St. Luke’s University Health Network now saves nearly 200 analyst hours every month because an AI agent handles thousands of false-positive security alerts. Palo Alto Networks says one Fortune 500 bank turns roughly 19,000 daily alerts into 17 actionable incidents with Cortex XSIAM. SentinelOne says its agentic investigation system is now running more than 8,500 critical autonomous investigations every day.

Those workloads are large enough to move the debate beyond pilots.

We can already draw a line through the market. AI works best today when security teams have huge amounts of data, repetitive decisions and a clear way to check whether the system got the answer right. Adoption becomes much thinner once the AI is asked to make high-impact decisions with little supervision.

Cybersecurity AI use case Adoption today What companies are actually doing
Threat and anomaly detection High Scoring endpoint, network, identity and cloud activity continuously
Phishing detection and triage High Classifying messages and closing obvious false positives
SOC investigation High and rising fast Gathering evidence, correlating alerts and building incident timelines
Threat intelligence High and rising Summarizing and connecting intelligence with internal telemetry
Automated incident response Moderate to high Closing routine cases and running predefined response actions
Vulnerability prioritization Moderate Ranking findings and recommending fixes
Autonomous pentesting Early Testing selected systems with human validation
Broad autonomous SOC Early Running bounded investigations and responses under human rules
Security for AI agents Early, growing quickly Discovering agents, governing access and testing AI applications

What should count as “real adoption” in cybersecurity AI?

Real cybersecurity AI adoption starts when the technology handles production security work repeatedly enough to change how people spend their time, how incidents are processed or what companies buy.

That definition gives us a much cleaner test than simply asking whether a company has “implemented AI.”

An endpoint platform that uses machine learning on every device clearly qualifies. An AI system that automatically investigates thousands of alerts also qualifies. So does a phishing agent that removes hundreds of analyst hours every month.

A security team experimenting with ChatGPT prompts tells us far less. The same goes for a vendor announcing an autonomous agent without showing whether customers are actually using it in production.

We therefore look for several kinds of evidence together: recurring workloads, customer attach rates, measurable reductions in manual work, faster incident resolution, automatic actions taken in production and security budgets moving toward AI-enabled platforms.

This stricter definition explains why cybersecurity AI can look mature in one part of the market and surprisingly immature in another. Machine-learning detection has been part of enterprise security products for years. Generative investigation is much younger. Autonomous response is younger again.

Those layers are often mixed together under the same AI label, which can make the market look more advanced than it really is in some areas and more experimental than it really is in others.

If you want more recent data on this point, please see our latest cybersecurity market report.

Google Trends chart showing rising interest in cybersecurity

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward

Where is cybersecurity AI being used the most today?

Cybersecurity AI is currently used most heavily in threat detection, phishing, anomaly analysis and the first stages of incident investigation.

The World Economic Forum gives us a useful map of the market. Its latest Global Cybersecurity Outlook found that phishing detection was the most common AI security use case at 52% of organizations, followed by intrusion and anomaly response at 46% and user-behavior analytics at 40%.

That order makes sense once we look at the work involved.

Security products can inspect millions of endpoint events, authentication attempts, network connections and messages far faster than humans. They can also compare those events against historical patterns continuously. Traditional machine learning has been doing versions of this for years, so adoption already had a large installed base before generative AI arrived.

Generative models are now moving one step further into the workflow. Instead of simply flagging an event, security platforms can gather related evidence, explain why the activity looks suspicious, reconstruct an attack path and suggest what the analyst should do next.

This is where the market has changed recently. Detection itself was already heavily automated. Investigation was still full of manual searching, tab switching and repetitive queries. The new wave of cybersecurity AI is increasingly attacking that second problem.

Investigation can consume much more human time than generating the original alert. The biggest adoption opportunity today sits between the detection engine and the human analyst.

Is AI really taking over phishing triage?

AI phishing triage is one of the clearest examples of cybersecurity AI already doing production work at meaningful scale.

The numbers are unusually concrete here.

At St. Luke’s University Health Network, Microsoft’s Security Alert Triage Agent autonomously handles and closes thousands of false-positive alerts. The organization says that saves its security team nearly 200 hours every month.

Microsoft also ran controlled studies around the same workflow. Security professionals using the agent triaged user-reported phishing alerts up to 78% faster, produced 77% more accurate verdicts and identified 6.5 times more malicious emails.

Another Microsoft deployment gives us a sense of the volumes involved outside email. A large telecommunications company used a Data Security Triage Agent to process more than 40,000 data-loss-prevention alerts over 90 days and surface the roughly 10% that deserved investigation.

Phishing is a particularly good fit because analysts keep asking the same basic questions. Who sent the message? Does the sender make sense? Where does the link go? Has the domain appeared before? Did other employees receive it? Did anyone click?

An AI system can collect most of those answers automatically and leave the ambiguous cases to people.

That combination of high volume, repetitive reasoning and easy escalation makes phishing one of the strongest AI adoption areas in cybersecurity today. We have both broad survey adoption and individual production deployments showing thousands of alerts disappearing from human queues.

Chart illustrating yearly VC funding for cybersecurity startups

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups

Are AI security copilots becoming part of everyday SOC work?

AI security copilots are increasingly becoming part of everyday SOC work, although the products gaining traction are usually built directly into platforms analysts already use.

The commercial evidence is starting to catch up with the product announcements.

SentinelOne reported that Purple AI was included in more than 50% of the licenses it sold during its fiscal fourth quarter of 2026. The company says Purple AI has already been used across thousands of customer environments.

That attach rate tells us something customer counts alone cannot. More than half of licenses sold during the quarter included the AI product. Customers were actively buying the capability as part of the security platform.

The way people use these tools has also changed. Early security copilots were heavily conversational. Analysts could ask for a query, request an incident summary or have technical findings translated into plain English.

Today the products increasingly gather the evidence themselves. Purple AI can assemble information across endpoint, identity, cloud and third-party telemetry. Microsoft Security Copilot works across Defender, Sentinel, Entra, Intune and Purview. CrowdStrike has been pushing Charlotte AI deeper into the Falcon platform.

The platform connection is central to adoption. A general-purpose LLM may understand cybersecurity, but it cannot investigate an organization properly without access to its alerts, devices, identities, cloud activity and security history.

Security teams are therefore buying AI most readily when it appears inside the tools that already hold that context. The standalone cybersecurity chatbot is becoming less important than the AI layer built into the SOC platform.

What are SOC teams actually letting AI do by itself now?

SOC teams are currently letting AI investigate alerts and handle routine responses on its own, while humans keep tighter control over actions that could seriously disrupt the business.

The autonomy level has moved quite quickly.

In August 2026, SentinelOne said Purple AI Agentic Investigation was handling more than 8,500 critical autonomous investigations every day. More than one third of the customers eligible for the capability had already enabled it. Across that group, the system was investigating nearly three times as many alerts as analysts could reach manually.

The same product can now feed its verdict into automated response workflows. Security teams decide in advance which situations the system can handle alone and which require human approval.

Customer deployments from other vendors show the same pattern from a different angle. PassportCard says 80% of its security-operations work is now automated with Cortex XSIAM. HiBob says 50% of its incident responses are fully automated. Pima Community College reports that automatic case resolution went from zero to 96%.

These are vendor customer stories, so they tell us that the workflows exist in production rather than giving us an industry average. Still, three organizations reaching automation rates of 50%, 80% and 96% shows that fairly deep SOC automation is already technically and operationally possible.

Routine investigations, known false positives, enrichment, evidence collection and familiar response actions are the obvious first candidates. A decision that could shut down an important service or lock out a sensitive account usually carries a higher approval threshold.

The current model looks increasingly like bounded autonomy: the AI can move quickly inside limits the security team has already defined.

SOC task How much autonomy we see today
Alert enrichment Very high
Evidence collection Very high
Incident timeline creation High
False-positive closure High
Routine response playbooks High in more advanced SOCs
Endpoint isolation Moderate
Sensitive identity actions More tightly controlled
Major incident containment Usually human-led

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart showing CrowdStrike’s playbook in the cybersecurity market

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity

Is cybersecurity AI actually cutting analyst workload and security costs?

Cybersecurity AI is already cutting large amounts of analyst work in the best deployments, but the biggest gains come when companies automate whole workflows instead of simply giving analysts a chatbot.

The differences between deployments make this obvious.

St. Luke’s removes nearly 200 hours of monthly phishing-triage work. HiBob reports a 50% increase in analyst productivity and a 60% drop in false positives. PassportCard says its security productivity doubled while three employees were moved from routine operations to more strategic work.

At the more aggressive end, Pima Community College reports a median resolution time of 26 seconds after automating 96% of cases. A Fortune 500 oil and gas company using Cortex XSIAM cut the number of incidents requiring investigation from around 1,000 a day to 250 and brought median resolution time down from multiple days to 59 minutes.

The common thread is more useful than any single percentage. These organizations are reducing the number of cases humans need to touch.

That is where the economics get interesting. Village Roadshow says its broader security platformization effort saves about 5,500 working hours every month and has cut costs by 23%. Xerox has reported $10.2 million in savings after redesigning its security operations around an AI-driven platform and removing traditional Tier 1 analyst roles.

Those savings cannot be credited entirely to AI. Tool consolidation, automation and architecture changes contribute too. In practice, though, that is often how cybersecurity AI creates value: several manual steps and disconnected tools disappear together.

IBM's latest Cost of a Data Breach research points in the same direction at a much broader level. Across 602 breached organizations, extensive use of security AI and automation was associated with $1.93 million lower average breach costs than having no such deployment.

We should avoid turning that correlation into a clean causal claim. More mature security organizations may be better at several things at once. The production examples still show the mechanism clearly enough: fewer alerts reach people, investigations finish faster and Tier 1 work shrinks.

Are autonomous AI SOCs already real?

Autonomous AI SOCs are becoming real at the workflow level, but very few companies currently appear ready to hand an entire security operation to AI.

Recent evidence has pushed this category further than it was even a few months ago.

As seen above, SentinelOne now reports thousands of autonomous critical investigations every day, with more than a third of its eligible customers using the capability. Some Palo Alto Networks customers are also automating the majority of routine cases. Autonomous investigation has clearly moved beyond demonstrations.

The jump from autonomous investigations to an autonomous SOC is much larger.

The latest SANS research captures that gap well. AI use across cybersecurity reached 78%, yet only 27% of practitioners described their deployments as mature production. Some 63% had also experienced significant shortcomings in AI-based threat detection or response, up from 45% a year earlier.

Confidence and governance are still catching up. In the World Economic Forum survey, 54% of organizations named inadequate AI skills as a barrier, 41% pointed to the need for human oversight and 39% were uncertain about AI-related risk.

Security makes full autonomy unusually difficult because mistakes can create their own incidents. A bad summary wastes time. A bad containment decision can disconnect a production system, block a legitimate executive or interrupt an important customer service.

So the autonomous SOC is arriving piece by piece. Investigation is moving first. Routine response is following. High-consequence decisions remain the part where companies are most reluctant to remove people.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart showing the projected CAGR of the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups

Is AI vulnerability management and autonomous pentesting actually working?

AI is beginning to work in vulnerability management and autonomous security testing, but adoption remains much earlier than AI detection or alert triage.

The gap shows up directly in IBM's latest breach study. Half of the organizations studied had deployed AI agents somewhere in threat hunting, response or containment. Only 18% were using agents for vulnerability scanning and management.

Finding vulnerabilities is only the beginning of the job.

Security teams need to decide whether a vulnerability is reachable, whether attackers can actually exploit it, whether the affected asset matters and whether fixing it could break something else. Then another team may need to patch the application or infrastructure.

AI is currently making progress on the parts that can be automated cleanly. Palo Alto Networks has added AI-assisted remediation guidance, risk scoring and exposure graphs to Cortex vulnerability management. Other tools are using AI to rank findings and connect vulnerabilities with exploitability and asset context.

Autonomous testing goes one step further by letting software actively attempt attacks.

HackerOne now combines agentic testing with its human researcher network. The company says 64% of reports in this workflow can be handled before a human touches them and that time to a validated fix is 56% faster. Its own results also show why human expertise remains valuable: combined agent-plus-human fix verification reached 88% accuracy, more than twice the model-only result.

AI pentesting is therefore real today, especially for continuous testing and narrow attack surfaces. Human researchers still have a sizeable advantage when the environment becomes messy, novel or ambiguous.

Is securing AI itself becoming a real cybersecurity market?

AI security has quickly become a real cybersecurity category because companies are connecting models and agents to valuable data, applications and business actions faster than security controls are catching up.

The attack surface has changed surprisingly fast.

HackerOne reported a 540% year-over-year increase in validated prompt-injection vulnerabilities on its platform. That is especially important because modern AI applications increasingly retrieve private information and call external tools. A successful prompt injection can therefore reach much further than the model's text output.

IBM’s latest breach research found that more than one fifth of studied organizations had experienced a breach targeting AI models or applications. The same research put the average cost of an AI model-inversion breach at roughly $6 million.

Meanwhile, SANS says 76% of cybersecurity teams now have some responsibility for enterprise AI governance. More than half of respondents still lacked a formal audit framework to support that responsibility.

We can see vendors moving quickly into the gap. Security products now cover AI application discovery, prompt-injection testing, model red teaming, runtime protection, data controls and agent permissions. CrowdStrike, Palo Alto Networks, Microsoft, SentinelOne and several younger AI-security companies are all competing here.

The category remains younger than endpoint security or SIEM, so we should expect a lot of consolidation and changing terminology. The underlying need is already clear: companies are putting sensitive data and real permissions behind AI systems, and security teams have inherited the job of controlling the resulting risk.

Chart comparing business model options for XDR and MDR cybersecurity vendors

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors

Is identity becoming the biggest security problem for AI agents?

Identity is currently emerging as one of the hardest security problems around enterprise AI agents because an agent becomes dangerous very quickly once it has credentials and permission to act.

Okta's latest enterprise data makes the scale of the mismatch unusually visible.

Its Businesses at Work research found that 91% of surveyed organizations were already using AI agents, while only 10% had a well-developed strategy for governing them. At the same time, 82% described their actual agent adoption as limited or moderate, which suggests many companies are still spreading agents cautiously rather than running them everywhere at scale.

The governance picture has improved somewhat in newer Okta research. In a global survey carried out in March 2026, 53% of executives said their organization had established a strategy guiding AI deployment. That still leaves a large group building governance while AI use is already happening.

The access problem is very practical. An AI agent might need to read Salesforce, send an email, query a database, open a support ticket or change a cloud resource. To do that, it needs an identity, credentials and permissions.

Existing identity systems were mostly designed around employees and conventional service accounts. Agents can act continuously, use several systems and make decisions without waiting for a person.

Companies have started responding. Okta says the number of service accounts centrally managed through its platform grew 650% year over year. Its 2026 report also found that 58% of leaders considered AI governance and identity/access management their top agent-related security concern.

This part of cybersecurity AI is therefore moving into production through fairly basic work first: finding agents, assigning identities, limiting permissions and removing unmanaged credentials. More sophisticated real-time governance can come later.

Are AI-powered attacks happening often enough to force defenders to adopt AI too?

AI-assisted attacks are now common enough to influence defensive security spending, even though AI has yet to reinvent every stage of cybercrime.

SANS found that 78% of organizations had seen confirmed or suspected AI-enabled attacks during the previous year, while 95% of respondents believed threat actors were using AI.

IBM's breach data provides a more conservative view tied to investigated incidents. It found a 56% year-over-year increase in AI-driven attacks, with deepfake impersonation and AI-enabled malware among the main categories.

The broadest survey numbers need a little caution because “AI-enabled” can cover a huge range of activity. An attacker using a model to improve a phishing email and an autonomous system discovering and exploiting a vulnerability are very different events.

The practical effect is clearer than the taxonomy. Attackers can create convincing social-engineering content faster, modify malware more cheaply, automate reconnaissance and scale impersonation attempts. Defenders still need to inspect the resulting volume.

That strengthens the case for AI on the defensive side because security already has a capacity problem. If an attacker can cheaply generate more variations of an attack, asking human analysts to manually process the corresponding increase in alerts becomes even less realistic.

AI-driven attacks help explain the urgency around defensive AI, but operational workload remains the bigger adoption driver today. Security teams already had too much data and too many alerts before generative AI gave attackers another accelerator.

Chart illustrating revenue distribution by customer segment in the cybersecurity market

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market

Which cybersecurity AI products still look overhyped?

Fully autonomous SOCs, broad autonomous pentesters and generic security copilots currently look further ahead in the marketing than in average enterprise deployment.

The contrast with mature use cases is quite sharp.

Threat detection has years of deployment behind it. Phishing triage can already remove hundreds of analyst hours. Automated investigation is processing thousands of real alerts. Those categories have production evidence we can measure.

A system that can independently run an entire SOC faces a much higher bar. It needs reliable reasoning across incomplete evidence, access to many security systems, permission to take consequential actions, strong resistance to manipulation and an audit trail that humans can understand afterward.

The latest SANS survey is useful here because adoption and disappointment are rising at the same time. AI security use jumped sharply, while 63% of practitioners reported significant shortcomings in AI-based threat detection and response. Rapid adoption clearly has not removed reliability problems.

Generic copilots have another issue. Security analysts gain the most value when AI has access to the organization's own telemetry. A standalone conversational tool sitting outside the endpoint, identity, cloud and SIEM stack has far less context and fewer actions available.

Autonomous pentesting faces a different constraint. AI agents can already attack structured environments and automate large parts of testing, but HackerOne's own results show a large accuracy gap when human researchers are removed from validation.

The pattern is pretty simple: AI adoption is strongest where the task is narrow enough to measure and control. Claims get shakier as the system's authority and scope expand.

If you want more recent data on this point, please see our latest cybersecurity market report.

What separates cybersecurity AI that gets adopted from cybersecurity AI that stays in pilot mode?

Cybersecurity AI gets adopted when it removes a painful chunk of repetitive work without forcing the security team to trust the model blindly.

The successful production examples share more than their use of AI.

They have clear inputs. An alert, an email, an incident or a vulnerability enters the workflow. The AI has access to relevant internal data. Its task is narrow enough to evaluate. The output can be checked. Routine actions can be reversed or escalated.

That description fits St. Luke’s phishing triage, the Fortune 500 bank reducing 19,000 alerts to 17 incidents and the growing number of automated investigations inside modern SOC platforms.

The weaker use cases usually ask the AI to operate with incomplete context or give it a much wider decision space. Investigating one endpoint alert using available telemetry is manageable. Protecting a company autonomously opens thousands of possible decisions and failure modes.

Integration also matters more than impressive demos. Security teams need the AI inside the workflow where the data and permissions already live. This helps explain why Microsoft, CrowdStrike, Palo Alto Networks and SentinelOne have an advantage: they already control major pieces of the security stack.

So far, cybersecurity AI adoption follows a very practical rule. The closer a product gets to eliminating a queue of repetitive human work, the easier its value is to prove.

Chart showing how identity verification platform technology has evolved over time

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time

So what cybersecurity AI is getting real adoption now?

Cybersecurity AI is getting real adoption today in detection, phishing triage, incident investigation, threat intelligence and increasingly routine response; autonomous security is real too, but only inside much tighter boundaries.

That is the clearest conclusion once product announcements are separated from actual workloads.

The deepest adoption remains the least glamorous layer. Machine learning continuously scores endpoint, network, email and identity activity across huge enterprise environments. That technology is already part of everyday cybersecurity.

The fastest change is happening above it. Generative and agentic systems are starting to absorb the investigation work that used to sit between an alert and a human decision. Microsoft has a customer saving nearly 200 analyst hours a month in one workflow. SentinelOne's autonomous investigation product is now processing more than 8,500 critical investigations daily. Palo Alto Networks customers show that half or more of routine incident handling can already be automated in some SOCs.

The next frontier is response. Companies are increasingly comfortable letting AI close known false positives, collect evidence and run familiar remediation steps. They become much more cautious when an action could interrupt a business service, disable an important identity or create a difficult-to-reverse consequence.

AI security itself is also turning into a serious market. Prompt-injection vulnerabilities are rising, AI applications increasingly touch private company data, and agents need identities and permissions. The extraordinary 650% increase in centrally managed service accounts reported by Okta gives us a useful glimpse of the infrastructure companies are now putting around those agents.

The winners in cybersecurity AI today are fairly easy to describe. They process a lot of boring work, have access to proprietary security context, produce answers that can be checked and operate within boundaries humans understand.

That is already enough to change a SOC. We do not need the fantasy of a completely human-free security operation to call the adoption real.

If you want more recent data on this point, please see our latest cybersecurity market report.

OUR METHODOLOGY

This analysis tests what cybersecurity AI is actually getting real adoption today. We separate broad AI usage from production adoption by looking at how widely the technology is used, how deeply it has entered security workflows, the scale of the workloads it handles, how much autonomy companies allow and whether deployments produce measurable operational results.

We broke cybersecurity AI into distinct layers because the AI label covers technologies at very different stages. Established machine-learning detection, newer generative-AI investigation tools and agentic or autonomous security systems are assessed separately rather than treated as one market with one adoption level.

We prioritized the freshest useful evidence available across each part of the question. Large practitioner surveys help measure breadth, while production workloads, customer deployments and commercial disclosures give us a better view of depth. Reported reductions in manual work, incident volumes and resolution times help show whether AI is actually changing security operations.

We assessed the evidence point by point rather than letting one large adoption percentage or one impressive customer deployment define the market. Conclusions are stronger where several kinds of evidence converge, particularly when production usage, customer uptake and measurable operational impact all point in the same direction.

Vendor customer stories are used carefully. They are useful for proving that a workflow is running in production and showing what level of automation is technically possible, but we do not treat one customer's result as an industry average.

The same principle applies to cost and productivity claims. Security-platform consolidation, conventional automation and architecture changes often happen alongside AI deployment, so reported savings are treated as evidence of the broader operating model rather than attributed entirely to AI.

Key sources used for the market-wide adoption picture include SANS Institute's latest AI cybersecurity research and the World Economic Forum's Global Cybersecurity Outlook. Production evidence comes from Microsoft's St. Luke's Security Copilot deployment, Microsoft's Security Copilot agent research and deployment examples, SentinelOne's autonomous investigation disclosures, and Palo Alto Networks' Cortex XSIAM customer deployments.

For the broader economics, attack trends and newer AI-security categories, we also used IBM's Cost of a Data Breach research, HackerOne's autonomous pentesting data, HackerOne's prompt-injection research, Okta's Businesses at Work research, Okta's newer AI-agent governance research, and Palo Alto Networks' Cortex vulnerability-management documentation.

Table scoring and prioritizing the main pain points faced by companies in the cybersecurity market

In our cybersecurity market deck, we identify pain points entrepreneurs should prioritize

Who is the author of this content?

NEW MARKET PITCH TEAM

We track new markets so founders and investors can move faster

We build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.

Back to blog