Skip to content

CISOs Are Waiting on Liability, Not Budget

Fifty-two percent of CISOs name trust as the barrier to automating remediation. Budget ranks fifth. What that gap describes is a legal vacuum.

Analysis of Kai's 2026 State of Autonomous Defense Report on why CISOs hesitate to expand security automation
Published:

Fifty-two percent of chief information security officers name a lack of trust in automated decisions as the biggest obstacle to expanding automation in their vulnerability programs. Twenty-one percent name budget. That gap, more than two to one, is the most useful finding in Kai's 2026 State of Autonomous Defense Report, and it is not the one the report leads with.

Disclosure. InfoSec Relations received this report under embargo. Kai did not sponsor or review this analysis. Full disclosure at the end.

The conventional story about security automation runs through procurement. Tools cost money, budgets stay flat, and adoption follows the funding. This data says something different. Security leaders are not waiting for money. They are waiting for someone to answer a question that no vendor agreement and no regulator currently answers, which is who carries the consequence when a machine changes production and gets it wrong.

Read that way, the survey describes a legal vacuum rather than a technology gap. The capability already exists. Thirty-two percent of these organizations let systems take remediation actions without human approval today. What is missing is the instrument that would let a CISO delegate that authority without personally absorbing everything that follows from it.

What the survey measured and what it left out

Wakefield Research fielded the study between June 15 and June 29, 2026, surveying 500 chief information security officers at private-sector companies with a minimum annual revenue of 500 million dollars. The report describes the sample as global. The accompanying press release describes it as four markets, and neither document names them.

That distinction matters for anyone reading these percentages as a worldwide picture. The revenue floor also excludes the mid-market entirely, where security teams run smaller and the manual burden falls harder per head.

Every operational figure here is a leadership estimate. The backlog question asks respondents what happens in their environment to their knowledge, which is a different instrument from telemetry. Remediation times, backlog percentages, and burnout attribution describe what CISOs believe about their organizations rather than what their systems record.

Defense still runs on people, and the delay is measurable

Sixty-five percent of respondents say at least half of vulnerability and exposure management happens manually. Six percent describe their approach as primarily machine-led, with humans intervening by exception. Automation sits inside most of these programs and works as an assistant rather than as the engine.

The delay shows up in the remediation bands. Forty-four percent of organizations close a critical vulnerability eight to fifteen days after identifying it, and another 14 percent take sixteen to thirty. Only 16 percent resolve one inside three days. Kai renders this as 60 percent taking longer than a week, which reads as a fair summary, though the underlying bars sum to 99 and the derived figure runs a point ahead of them.

Backlog compounds from there. Forty-eight percent estimate that a quarter or more of known vulnerabilities in their environment stay open past thirty days, and 17 percent put it at half or more. These are not undiscovered weaknesses. They sit cataloged, scored, and waiting.

The human cost registers in the same data. Seventeen percent of CISOs call vulnerability management a major contributor to burnout on their teams and 61 percent call it a moderate one. Kai's executive summary reports that combined figure as 77 percent while its own chart supports 78, and the press release carries the lower number forward. Small discrepancies like that travel further than the charts they came from.

Burnout belongs in the operational analysis rather than in a wellbeing aside. Teams running permanently behind make different decisions than teams that are not, and triage quality degrades in ways no dashboard captures.

The labor argument underneath all of this holds up against its primary source. ISC2's 2025 Cybersecurity Workforce Study, drawing on 16,029 respondents, found that 88 percent experienced at least one significant cybersecurity consequence tied to a skills shortage, and 33 percent said their organizations lack the resources to staff teams adequately. Hiring alone does not close a gap of that shape.

Trust outranks budget by more than two to one

Asked what prevents them from expanding automation, CISOs put lack of trust in automated decisions first at 52 percent. Governance and compliance concerns follow at 43 percent. Skills gaps and integration complexity tie at 38 percent. Budget constraints land at 21 percent, and unclear return on investment at 15.

Read the barrier list beside the confidence list and the picture sharpens considerably. Fifty-two percent say auditability and explainability would increase their willingness to let systems remediate without approval. Fifty-one percent say vendor accountability and liability protections would. Forty-six percent say regulatory clarity would.

Only the first of those three sits inside a vendor's control. A security team can buy explainability, in the sense that it can demand logging, decision traces, and reasoning that survives an audit. It cannot buy regulatory clarity. It cannot buy a liability transfer, because no standard commercial agreement in this category offers one.

That is the constraint this survey actually measured. CISOs are describing a governance problem in the vocabulary of trust, and the vocabulary obscures what they are asking for. They are asking who signs.

Governance frameworks are moving in the same direction without arriving anywhere. Eighty-one percent describe their approach as human-led and being adapted for greater machine-led operation, and 10 percent say theirs is already designed for it. More than nine in ten are heading somewhere they have not reached, which describes a frontier well and a control badly.

The structural point follows from there. An organization that permits a system to change production without human approval has made a decision about accountability, whether or not it has written one down. When that action takes down a payment system, or misses an exposure that later matters, the question of who answers gets resolved afterwards by lawyers, regulators, or a board. Thirty-two percent of these organizations already operate in that condition.

Public scoring infrastructure is thinning as demand rises

None of this happens against a stable backdrop. On April 15, 2026, NIST changed how the National Vulnerability Database works, and the change has drawn less attention than it deserves. In its own announcement, the agency says it will enrich CVEs appearing in CISA's Known Exploited Vulnerabilities catalog, the federal registry of flaws confirmed under active attack, along with CVEs affecting federal government software and CVEs covered by Executive Order 14028 as critical software. Everything else stays listed and marked lowest priority.

The numbers behind that decision deserve stating plainly. NIST reports that CVE submissions grew 263 percent between 2020 and 2025, that first-quarter 2026 volume ran nearly a third higher than the year before, and that it enriched close to 42,000 CVEs in 2025, up 45 percent, without keeping pace. Unenriched records published before March 1, 2026 move into a Not Scheduled category.

One procedural change inside that announcement matters more than the backlog. NIST will stop issuing its own severity score where the CVE Numbering Authority has already supplied one. The independent second opinion on severity, produced by a federal institution with no commercial stake in the answer, disappears for most vulnerabilities.

Volume explains the decision. Jerry Gamblin's 2025 CVE Data Review counts 48,185 published CVEs for the year, a 20.6 percent increase over 39,962 in 2024. Even that number carries dispute. Dark Reading's analysis of the same period notes the NVD showing 48,173, an independent count of 48,177 after removing rejected and reserved entries, and Flashpoint arriving at 44,146 once it deduplicates variants of the same software.

Kai's report cites 48,185 and attaches the 263 percent growth figure to it inside a single sentence. Those are two different measures from two different publishers, and the second belongs to NIST's submission counts rather than to published CVE totals.

Put the NIST decision beside the survey and the shape of the problem becomes clear. Prioritization judgment is migrating from a public, federally funded layer toward private tooling at exactly the moment security leaders say they do not trust private tooling to exercise judgment.

Parts of the report's framing outrun its own data

Kai's introduction moves from CVE volume to the FBI's 2025 Internet Crime Report across two sentences, citing more than 20 billion dollars in reported losses and a 26 percent year-over-year increase. Both figures check out. The placement implies those losses represent the financial consequence of the exploitation gap, and the Bureau's own data does not support that reading.

Roughly 85 cents of every dollar lost in 2025 came from cyber-enabled fraud rather than from malware or exploitation. The AI-related category Kai references, which the FBI tracked separately for the first time, logged 22,364 complaints and 893 million dollars, and its largest component is investment fraud at 632 million. Business email compromise accounts for 30 million. Voice cloning and impersonation drive those figures, not unpatched software.

Kai also describes the IC3 report as having a nearly 25-year history. The 2025 edition is the 26th.

Three other framings deserve scrutiny. The headline movement, from 35 percent machine-led today to 45 percent within 12 to 18 months, compares answers to two questions built on different response scales. Figure 3 runs a manual-to-automated spectrum. Figure 13 runs a narrative one, from human analysts as primary operators through to autonomous operations as the primary model. That is expressed intent, not measured change.

The 89 percent preparedness figure rests almost entirely on a 61 percent somewhat prepared band. Very prepared sits at 28. A survey that offers a somewhat option and reports the combined total measures the absence of alarm rather than the presence of readiness.

The press release inverts Figure 7 outright. That chart asks which activities systems can perform without human approval, and remediation validation scores 40 percent. The release reports that 60 percent or more say remediation validation and automated actions still require human intervention, which is arithmetically derivable and rhetorically backwards.

None of this makes the survey unreliable. It makes it a document with a thesis, produced by a company that sells autonomous remediation, and the underlying figures hold up considerably better than the packaging around them.

Liability is the product nobody sells

Three things would move the numbers in this survey, and two of them are not products.

Contractual liability allocation comes first. A vendor that sells autonomous remediation and accepts no defined exposure when that remediation causes harm asks customers to buy capability and absorb risk inside the same transaction. Fifty-one percent of these CISOs named that arrangement as the thing standing in their way.

Auditability standards specific enough to test against come second. Explainability as a marketing property means a log file. Explainability as a governance property means a decision record that survives an incident review, a regulator, and opposing counsel, and the industry has not agreed on what that record contains.

Regulatory clarity comes third and will arrive last. No jurisdiction has stated clearly who bears responsibility when an autonomous security system acts within its authorization and causes damage, or fails to act and permits it.

Until those three exist, the 32 percent already permitting autonomous remediation are running an experiment with undefined downside, and the 68 percent who are not are making a rational choice that looks like caution and works like risk management. The survey reads that hesitation as a trust deficit. It sits closer to an unanswered question about who signs.


Disclosure

InfoSec Relations received the 2026 State of Autonomous Defense Report from Kai under embargo ahead of publication. Kai did not sponsor, commission, review, or approve this analysis. An executive from Kai previously appeared on InfoSec Relations in a feature on Five Eyes warning on AI Speed. That engagement was not sponsored and carried no conditions on coverage.

Shant Ebenezer Jena

Shant Ebenezer Jena

Shant E. Jena is a technical writer who contributes to a wide range of industry publications. His work spans software engineering and cyber politics.

All articles

More in InfoSec Leadership

See all

More from Shant Ebenezer Jena

See all