Skip to content

AI Attacks Push 88% of Orgs to Boost Offensive Security Spending

Omdia research finds AI-powered attacks and faster vulnerability exploitation are driving enterprises toward continuous offensive security, agentic AI and increased security spending.

Artificial intelligence is accelerating cyberattacks and vulnerability exploitation quickly enough that enterprises are rethinking how they test their defenses, with 88% planning to increase spending on offensive security technologies in 2026.

New research from Omdia finds that AI-powered automated attacks have become the single biggest influence on organizations' offensive security strategies, cited by 32% of respondents. Another 25% pointed to the increased speed at which threat actors exploit vulnerabilities.

The findings point toward a shift away from periodic penetration tests and other point-in-time assessments and toward continuous security validation capable of keeping pace with attackers.

"The world is moving at the speed of AI," said Theresa Lanowitz, principal analyst at Omdia. Everything is getting faster, she said, including the time required to detect vulnerabilities and the time available to remediate them.

The implication for defenders is straightforward: Security teams increasingly need AI to fight AI.

That requires security organizations to become more proactive and offensive, Lanowitz said, giving defenders the ability to use AI at the same speed attackers are beginning to use it.

Offensive security is intended to validate whether defensive security controls actually work when subjected to real-world pressure. The discipline encompasses techniques including penetration testing, red teaming, vulnerability assessment and social engineering exercises designed to expose weaknesses before attackers exploit them.

Traditional penetration testing struggles to keep pace

Omdia's research illustrates why that model is changing.

Just 25% of respondents said they have complete real-time visibility into their organization's data and assets. More significantly, 53% said traditional offensive security approaches provide a static view that is obsolete by the time a report is delivered.

Another 48% said testing is too infrequent to keep pace with technology growth and change, while 46% said existing approaches fail to adequately test security controls against real-world threats, tactics and procedures.

That does not mean penetration testing is disappearing. Omdia found 59% of organizations use penetration testing-as-a-service, 58% use automated vulnerability management platforms, 57% use continuous threat and exposure management platforms, 56% rely on external consultants and 53% still conduct traditional point-in-time penetration testing.

The emerging difference is continuity.

Security teams increasingly want offensive security capabilities integrated with the defensive tools they already use. Sixty percent of respondents feed offensive security findings directly into SOC detection engineering and rule tuning, while 56% integrate them with centralized risk-based exposure management platforms. Another 54% use the findings to establish application development policies and guardrails.

Agentic AI moves into offensive security

AI is emerging as a potential engine for making that continuous model possible.

Forty-two percent of respondents identified autonomous AI security agents as the technology with the greatest potential to reshape offensive security strategies in 2026, well ahead of cloud-native attack surface management at 24%.

The enthusiasm is even clearer when organizations look ahead. Sixty percent said agentic AI will be "very important" to bolstering their offensive security posture during the next 24 months, while another 34% called it "critical."

But enthusiasm for agentic AI does not yet translate into a willingness to give agents free rein. Only 7% of organizations currently allow AI agents to operate with full autonomy within predefined policy boundaries. Thirty-four percent keep humans in the loop for approval, 27% allow autonomous operation with human intervention and oversight, and 33% use AI in an advisory capacity.

Organizations also see risks in giving agents greater authority. Lanowitz said the leading concerns include agents being hijacked through prompt injection or adversarial inputs, cited by 23%; unpredictable or unintended agent decisions, at 22%; and high computational costs and resource requirements, at 21%.

Those concerns aren't stopping companies from identifying work they believe agents can perform. Continuous reconnaissance and asset discovery led the list at 24%, followed by autonomous alert triage and investigation at 22% and automated vulnerability exploitation at 18%.

Omdia argues that organizations ultimately need to move from periodic to continuous attack-surface discovery and validation, with AI helping defenders find and remediate vulnerabilities before adversaries exploit them. The firm also recommends feeding offensive security findings directly into defensive operations and engineering workflows rather than treating offensive testing as a separate function.

Offensive security budgets are rising

Organizations appear prepared to spend to make the transition.

Omdia found that 88% expect their offensive security technology budgets to increase in 2026, with 23% anticipating a significant increase and 65% expecting a moderate increase.

And buyers are emphasizing measurable security outcomes over technology for technology's sake.

The top considerations when selecting offensive security technology are a proven ability to reduce measurable risk and the ability to provide a unified view across IT, cloud and OT environments, each cited by 26% of respondents. Ease of integration with existing SOC technologies such as SIEM, SOAR and EDR followed at 21%.

The research suggests offensive security is becoming less about periodically proving that vulnerabilities exist and more about continuously determining whether an organization can withstand the attacks that matter.

For Lanowitz, AI makes that transition more urgent. Attackers can use automation to move faster, meaning defenders have to compress their own cycles for discovery, validation and remediation.

The objective isn't simply to deploy more AI. It's to use AI to give security teams the speed and continuous visibility they increasingly need to fight attackers operating at machine speed.

HOU.SEC.CON CTA

Latest