Splunk survey: Only 34% of enterprises have deployed protective measures against generative AI threats
A Splunk survey of 1,650 executives shows that although 93% of cybersecurity leaders' organizations have deployed generative AI, only 34% of users have established protective measures against security threats. About two-thirds of respondents (65%) admitted they do not fully understand the risks of generative AI, and 44% prioritize it above cloud security.

Key Findings
- 93% of cybersecurity leaders say their organizations have deployed generative AI, but a Splunk survey found that only 34% of these users have established safeguards to address security threats.
- About two-thirds of respondents (65%) said they do not fully understand the risks of generative AI, while 44% ranked it belowcloud securityin priority. Splunk reached these conclusions after surveying 1,650 executives.
- Audra Streetman, a security strategist at Splunk SURGe, noted that organizations adopting generative AI across as many as 16 industries "want to ensure they follow best practices, but due to the need for rapid action, some have overlooked potential consequences."
In-Depth Analysis
Moody's Investors Service last month cited University of Maryland data showing that the number of cyberattacks increased by an average of 26% annually between 2017 and 2023. "This figure is likely underestimated, as companies are typically not required to report cyberattacks."
As cybersecurity risks rise, Moody's said generative AI could, in the short to medium term,benefit attackers more。
In the Splunk survey, 45% of respondents believed generative AI gives an advantage to malicious actors, while 43% said the technology benefits cybersecurity defenders.
"Which side gains the upper hand depends largely on an organization's cybersecurity strategy," Streetman said in an email response.
"Organizations that implement foundational controls such as asset inventories and account management often achieve the highest return on investment, making it easier to stay ahead of adversaries—many of whom still rely on proven traditional tactics," she added.
She pointed out that collaboration across departments is an important defense measure. 87% of security teams involve multiple company departments, with 54% partnering with software engineering teams to implement security-by-design practices.
Overall, generative AI "creates new opportunities for enterprises to streamline processes, boost productivity, and reduce employee burnout," Streetman said. "Defenders are optimistic about the use cases for generative AI."
The technology aids in data mining and in identifying and analyzing cybersecurity risks. In the Splunk survey, 55% of respondents said that with generative AI, they can detect disruptive events within 14 days or less, compared to 28% in a survey completed early last year.
"As security teams continue to integrate generative AI, they must remember to keep humans involved in decision-making," Streetman said. "AI is a powerful tool, but when defending against threats, human decisions related to generative AI are crucial."
The Splunk survey covered security executives from the United States, Japan, the United Kingdom, France, Germany, and four other countries.