April 29, 2026

78% of Indian CIOs and CISOs Still Exploring AI in Cybersecurity Without Mature Strategy, Finds Infopercept Survey

New report reveals growing trust gaps, unclear decision boundaries and rising security risks as enterprises accelerate AI adoption

AHMEDABAD, India, April 29th , 2026 — A newly released survey report by Infopercept has found that while artificial intelligence is rapidly gaining attention in enterprise cybersecurity, most Indian organizations remain in the early stages of adoption, with limited governance, unclear operational models and growing concerns over trust, cost and security risks.

The report, titled “The State of AI in Cybersecurity: India CIO & CISO Survey Report (October 2025– March 2025),” surveyed 500 CIOs and CISOs from large enterprises across India and highlights a widening gap between AI ambition and execution. 

According to the findings, 78% of CIOs and CISOs said they are still exploring AI use cases in cybersecurity, while only 16% have clearly defined AI-driven security workflows. In addition, 61% admitted they are experimenting with AI without a structured strategy. 

“AI has become a boardroom priority, but most enterprises are still figuring out how to operationalize it securely and effectively,” said Jaydeep Ruparelia, Founder and CEO of Infopercept. “The opportunity is real, but organizations need disciplined execution, governance and measurable outcomes. AI in cybersecurity must strengthen existing operations, not become another unmanaged layer of risk.”

The survey found that enterprises are more comfortable using AI for defensive functions such as threat detection, alert triage and log analysis. Seventy-two percent of respondents expressed confidence in these use cases. However, 67% said they are not confident using AI for exposure validation, including breach simulation, attack path validation and risk verification. 

The report also revealed uncertainty around human and machine decision-making. Seventy-four percent said they lack clarity on what decisions should be made by AI, humans or automation, while 69% are uncomfortable allowing AI to make autonomous security decisions. Only 12% have defined AI decision boundaries or human override mechanisms. 

Trust remains another major barrier to adoption. Seventy-one percent of respondents said large language models produce inconsistent results for the same query, and 63% said this reduces trust in AI for critical cybersecurity workflows. More than half said teams spend additional time validating outputs, reducing expected efficiency gains. 

“The challenge is no longer access to AI tools. It is trust, control and alignment with security operations. Enterprises need AI systems that are accountable, integrated and measurable if they want to scale beyond experimentation,” Ruparelia said.

The survey further highlighted concerns over return on investment. Sixty-six percent said AI costs are rising faster than measurable security outcomes, while 54% said they are unable to justify ROI on AI investments in cybersecurity. Nearly half worry that uncontrolled AI adoption could lead to budget overruns. 

At the same time, 76% of respondents said AI adoption has introduced new attack surfaces, including prompt injection, data leakage and model manipulation. Only 18% said they have implemented formal security controls for AI usage, such as governance frameworks or LLM gateways. 

The findings suggest enterprises increasingly view AI as an enhancement rather than a replacement for existing cybersecurity programs. Eighty-one percent said AI should improve current security tools and workflows, not replace them. 

Top Priorities for CIOs and CISOs in 2026–27

  1. Defining AI use cases in cybersecurity beyond experimentation 
  2. Establishing decision boundaries between AI, humans and automation 
  3. Using AI for exposure validation with confidence 
  4. Managing AI cost versus measurable outcomes 
  5. Securing AI systems and LLM usage 
  6. Integrating AI into existing security operations 

About the Survey

  • Sample Size: 500 CIOs and CISOs 
  • Industries: BFSI, Healthcare, Telecom, Manufacturing, Technology, Energy and Public Sector 
  • Company Size: Large enterprises across India 
  • Methodology: Mixed online and telephonic interviews conducted between October 2025 and March 2026 

About Infopercept:

Infopercept is a global, platform-led managed security services company serving enterprises across defensive security, offensive security, detection and response, governance and compliance. Its cybersecurity platform, Invinsense, integrates security operations, threat exposure management and governance capabilities to help organizations continuously assess, validate and reduce cyber risk. For more information, visit www.infopercept.com

Welcome to the single source of truth you need for cybersecurity.

Discover complete cybersecurity expertise you can trust and prove you made the right choice!

invinsense logo