A new ISACA survey says only 21% of Indian organisations regularly test their response to AI-driven cyber threats. The headline sounds alarming. The buried comparison is more interesting: globally, that figure is 8%. India tests its AI incident response at more than double the world’s rate — and still leaves nearly half its enterprises untested. The 12th annual State of Cybersecurity report, sponsored by Wolters Kluwer TeamMate, surveyed more than 1,800 cybersecurity professionals, including 147 in India.
Why the AI Incident Response Story Broke Now
Three pegs hold the timing.
A news hook about rogue AI
The release cites “recent news revealing several instances of rogue AI model behavior”. That references a real and unsettling 2025-26 cycle of incidents. The World Economic Forum’s 2026 outlook documents Anthropic’s November 2025 disclosure of an AI-enabled espionage operation that ran across the entire attack lifecycle — reconnaissance to exfiltration. AI misbehaving is no longer hypothetical, and ISACA’s framing leans on that fear.
Cybersecurity Awareness Month calendar mechanics
The report lands in late September, ahead of October’s global Cybersecurity Awareness Month. ISACA is promoting a 20 October webinar and Foundation scholarships timed to the month. Certification bodies run on this calendar; the report is both research and marketing infrastructure.
India’s AI deployment curve
Indian security teams are not dabbling. Per the survey, only 10% avoid AI in security operations. Automating routine security tasks jumped from 34% to 53% of teams in a year. Threat detection automation rose from 42% to 52%. The gap between deployment speed and rehearsal discipline is the survey’s central tension — and it widens every quarter.
The Competitive Picture Around AI Incident Response Data
ISACA is one of several bodies mining this territory, and each has a commercial stake. ISC2 runs a parallel universe of workforce studies and is building its own AI security certification. DSCI and SANS reported in May 2026 that 83% of Indian organisations call AI security skills critical, while 73% struggle to find skilled candidates. DSCI and BCG found Indian BFSI firms suffer attacks at 1.6 times the global average. Every certifying body that measures the AI-skills gap also sells the remedy — ISACA’s release promotes its AAISM credential and a new December certification.
The sponsor matters too. Wolters Kluwer TeamMate sells audit-management software, and its executive’s quote steers neatly toward “AI-powered integrations” in audit and compliance platforms. Sponsored research is not invalid research. It deserves reading with the sponsor’s product roadmap in mind.
What the Data Shows About India’s AI Incident Response
The AI incident response numbers repay careful reading — including one the release underplays.
India outpaces the world
Globally, 64% of enterprises have never run an AI-related incident exercise. In India, 49%. Globally, 48% lack AI incident playbooks or don’t know if they exist. In India, 35%.
Indian teams also show more confidence: 54% trust their organisation’s ability to detect and respond, versus 42% globally. Whether that confidence is earned is a separate question.
The attack-expectation puzzle
Only 23% of Indian respondents expect a cyberattack on their organisation in the next year. That number sits awkwardly beside DSCI-BCG’s finding that Indian financial institutions face attacks at 1.6 times the global average, with incidents more than doubling from 1.4 million in 2021 to 2.9 million in 2025. Either Indian respondents are unusually secure, or optimism is doing the reporting. The survey offers no reconciliation.
Stress, staffing and the retention trap
Fifty-seven percent of Indian respondents find work more stressful than five years ago, with 71% blaming the increasingly complex threat landscape. Forty-two percent call their teams understaffed, and 66% report retention struggles. High work stress now tops the reasons people leave, at 46%. The cruellest detail: 46% of teams are turning to more AI and automation to close skills gaps — adding governance burden to the same stretched people.
What’s New vs. What’s Repackaged
New this year: the AI-specific incident-response questions, the LLM SecOps skills-gap finding (34%, up 10 points), and the India-versus-global comparison the release itself rarely surfaces. Repackaged: stress, understaffing and retention complaints, which have anchored this survey for years. The AI adoption numbers follow a trendline ISACA has tracked since 2024 — 27% of Indian respondents were involved in implementing AI solutions then, 46% in 2025, 51% now. The survey evolves; the worry is perennial.
The Question the Press Release Doesn’t Answer
What does “regularly” mean? The survey never defines the testing frequency behind the 21% figure — quarterly drills and annual tabletops both qualify. Nor does the release disclose the India sample’s margin of error, which at 147 respondents is wide enough to swallow several headline findings. Respondents are ISACA members — credentialed professionals skewed toward organisations that invest in training. That likely flatters the numbers.
And the striking claim that only 23% expect an attack goes unreconciled with external evidence of India’s elevated attack rates. Precision is available here; the release prefers alarm.
What the AI Incident Response Findings Mean for You
If you run security for an Indian organisation, the to-do list writes itself: an AI-specific playbook, a rehearsal schedule, and LLM SecOps training for the team. Treat the boardroom-priority framing from ISACA’s ambassador as useful — this is a rare gap where a slide, not a budget line, starts the fix.
If you hire or retain security talent, note that stress now outranks promotion ceilings as the reason people quit. Wellness perks help at the margin; workload design and headcount help more.
If you sell security training or tooling, India is your most receptive market on this data — highest AI adoption in security operations, highest confidence, and the widest gap between AI deployment and governance. The buyers already know they are behind.

Editor’s Note
This article draws on ISACA‘s India press release and global counterpart of 22 September 2026, ISACA’s related 2026 AI Pulse Poll releases, the World Economic Forum’s Global Cybersecurity Outlook 2026, DSCI-SANS and DSCI-BCG India reports from May 2026, and ISC2’s 2026 workforce commentary. Survey figures are self-reported and carry sample-size limitations, particularly for the 147-respondent India subset. Nothing here is investment advice.

