CFOtech US - Technology news for CFOs & financial decision-makers
United States
Executives & staff split on AI cyber risk at DNSFilter

Executives & staff split on AI cyber risk at DNSFilter

Mon, 21st Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

DNSFilter has published survey findings showing a gap between executive and practitioner views of AI and cybersecurity risk. The study points to a divide over resilience, incident reporting and governance.

The survey of 400 IT and cybersecurity professionals at manager level and above found that 73.9% of executives believe their organisations could maintain critical operations during a 72-hour cyberattack. That compares with 47.5% of IT managers and 50% of cybersecurity professionals.

It also found a sharp difference in views on whether incidents are being detected and reported. Nearly half of IT managers, 45.8%, said their organisation had experienced unreported security incidents, while only 17.4% of executives believed that was the case.

On detection, 52% of IT managers said incidents had been downplayed because of limited detection capability. Among executives, 39.1% said the same.

The gap also extends to the pace of AI adoption by attackers. Between 69% and 71% of IT managers and network and cloud professionals said attackers are adopting AI faster than their own teams can keep up, compared with 43% of executive leaders.

More than a quarter of executives, 26%, said their own teams were ahead in that race. The findings suggest senior leaders and operational teams are working from different assumptions about the same threat landscape.

Ken Carnesi, Chief Executive Officer at DNSFilter, said the issue was less about misplaced confidence than about visibility. "Organisations aren't overconfident so much as disconnected. Executives and practitioners are looking at two different pictures of reality - the people closest to the systems see incidents going unreported and downplayed, while the people signing the budgets don't. Money is flowing to AI governance, but it's aimed at the wrong picture. That disconnect is exactly where AI-driven threats are finding room to operate," Carnesi said.

Budget split

Spending is rising, but the survey suggests the extra money is not always targeting the same priorities across an organisation. Overall, 74.5% of respondents said budgets had increased over the past year.

Executives put AI security governance first, with 52.2% naming it as the top spending priority, followed by network security at 26.1%. Practitioners wanted more investment in endpoint detection, cited by 22.8%, followed by security training at 19.3% and incident response at 18.4%.

AI governance stood out in two ways. It was identified as the largest security gap by 36.25% of respondents and as the top investment priority by 40.25%.

Kasey Best, Senior Director of Threat Hunting at DNSFilter, said increased spending had not closed the gap. "More budget and 'good enough' policies haven't closed the gap on their own. Some of the most mature, best-resourced organizations we surveyed also report the highest rate of shadow AI incidents. Governance maturity and actual safety are turning out to be two different things that organizations are not currently equipping their teams to handle," Best said.

Shadow AI

The findings point to growing concern over shadow AI, where staff use AI tools or connect services outside approved channels. The largest organisations in the survey used six to 10 AI tools at nearly double the rate of smaller peers, 47.5% compared with 25.2% overall.

Those larger organisations also reported the highest shadow AI incident rate of any size band, 32.5% against an overall rate of 20.1%. Across the full sample, 40% of organisations said they had suffered a security incident tied to a third-party SaaS or AI tool in the past year.

One in five organisations, 20%, said an unauthorised AI connection had directly caused an incident. The survey also found that 36.8% of organisations notify IT about new AI connections only after access has already been granted, while 6.5% provide no notification at all.

Executives appeared to recognise that this blind spot exists, even where they could not confirm it. Some 21.7% said they suspected unauthorised AI connections had occurred but could not verify them, the highest share among the roles surveyed.

Policy gaps

The study found weaker alignment on the rules around access and approval. Among executives, 73.9% said new AI tools require administrator approval before access is granted, compared with 58% to 60% of practitioners.

Only 49% of organisations said they had formal, consistently enforced policies governing autonomous AI agents. Another 8.7% of executives said they saw no emerging AI risk at all, more than double the overall rate across other groups.

The survey also suggested industry differences in how AI tools are viewed. Respondents in finance and healthcare were about twice as likely as those in IT and telecoms to flag AI models such as Kimi K2 and Mistral as risks, which the report linked to data sovereignty and compliance concerns.

DNSFilter surveyed organisations with 150 to 5,000 employees across North America. The results indicate that the internal divide over AI risk is not confined to technical teams or frontline security staff, but extends to decisions on budget, governance and whether incidents are recognised at all.