Organizations know they have a cyber risk problem. Actually doing something about it? That is where things fall apart.
Bitdefender’s 2026 Cybersecurity Assessment surveyed 1,200 IT and security professionals across six countries. The results reveal a painful gap between awareness and resilience.
Take AI. Nearly 52% of respondents believe they have full visibility into employee AI usage. But 47% admit they have only partial or no visibility. The disconnect is worse between managers and practitioners — 58% of managers think they have full visibility, but only 46% of frontline staff agree.
That means strategic decisions are being made on incomplete data.
Attack surface reduction is another area where talk beats action. Everyone agrees it matters. Few can pull it off. The biggest obstacles? Maintaining hardening policies (38%), fear of breaking business operations (35%), and limited resources (35%). Another 34% said they just do not know which legitimate tools their users actually need.
Then there is the AI distraction problem. Security pros ranked AI threats — self-mutating malware, LLM data leakage, AI-driven evasion — as their top three concerns. Meanwhile, one of the most effective attack methods today gets ignored.
Bitdefender Labs found 84% of high-severity attacks used Living off the Land (LOTL) techniques. Abusing legitimate tools already inside the network. Only one in five respondents ranked LOTL among their top three concerns.
The takeaway? AI matters. But adversaries are using it to improve existing attacks, not invent brand new ones. Don’t let the shiny new threat distract you from the one already in your network.
Transparency after a breach is still a sore spot. Many professionals report pressure to stay quiet, even when disclosure is legally required.
