Security leaders must use AI to defend their organisations from increasingly sophisticated attackers who themselves are leveraging new technology.

Research shows that while 80% of security leaders think AI agents could improve security, almost the same number (79%) think this technology poses risks.1

These findings from Salesforce’s Inside the State of IT, Fourth Edition: Security Report show AI as a double-edged sword, boosting capability for attackers and defenders. To stay secure, CIOs and CISOs need a clear view of how AI is accelerating each side of that equation.

The attacker: AI is accelerating threat speed, variability and reach

Three-quarters of leaders now believe AI-driven cyber threats will outpace conventional defences, a trend which highlights the growing gap between attacker innovation and enterprise controls.2 Adversaries are already using AI to scale reconnaissance, vary phishing content and automate payload development. They can also mimic normal activity more effectively, making malicious behaviour harder to distinguish from legitimate workflows.

The rise of AI-specific risks adds further pressure. Data poisoning, adversarial attacks and model manipulation can compromise the integrity of the AI systems many organisations now depend on. These challenges are intensified by weak data foundations, misconfigured access and inconsistent governance, which create openings that become more exposed in an AI-driven environment.

CIOs and CISOs must assume attackers will iterate at machine speed. This requires faster detection cycles, continuous monitoring and clearer visibility across high-value systems so teams can act before an intrusion becomes material.

The defender: AI is strengthening detection, response and operational resilience

The defensive opportunities offered by AI are equally significant. All security leaders say AI improves at least one dimension of their security posture, from quicker incident response to more accurate analysis.3 Meanwhile new Foundry research found demand for AI is rising accordingly with 73% of security buyers more likely to consider AI-enabled tools, up from 59% in 2024.4 These tools have also seen the greatest increase in planned spending, signalling confidence in their ability to strengthen enterprise resilience.

What value does the technology bring in reality? AI agents can detect abnormal patterns, automate routine checks and coordinate remediation, enabling teams to focus instead on high-value risks. Strong AI security, however, begins with trustworthy data and clear governance. Only 48% of leaders feel confident in the data supporting their AI agents, which shows where vulnerabilities may emerge.5

IT leaders are well advised to embed strong data, access and model validation controls into every AI deployment to ensure their defences perform reliably. Many organisations are turning to platforms that provide unified governance and continuous monitoring. Salesforce embeds these controls natively, helping teams scale AI securely.

What this means for IT leaders

AI is reshaping both sides of the security equation. The same systems that improve detection, analysis and response can introduce vulnerabilities if data, access and governance are not controlled with equal rigour. CIOs and CISOs that recognise this duality and modernise their security models accordingly will be better placed to stay ahead of fast-moving threats.

Inside the State of IT, Fourth Edition: Security Report offers deeper insight into how leaders are balancing these pressures and where the next wave of AI-driven security innovation is emerging.


[1] Salesforce, Inside the State of IT, Fourth Edition: Security Report, https://www.salesforce.com/blog/4th-state-of-it-security/

[2] Ibid

[3] Ibid

[4] Foundry, Security Priorities Study, https://foundryco.com/research/security-priorities/

[5] Salesforce, Inside the State of IT, Fourth Edition: Security Report, https://www.salesforce.com/blog/4th-state-of-it-security/


Share
Share