Companies Are Spending More on Cyber 'Attack Drills' to Keep Up with AI-Powered Hackers
New research from Omdia finds 88% of organisations plan to increase spending on offensive security, as AI gives attackers a dangerous speed advantage that traditional defences can no longer match.

Key points
- 88% of organisations said they are willing to spend more on offensive security strategies, according to Omdia research published in 2026.
- Traditional practices such as penetration testing and red teaming, where security professionals simulate attacks to find weaknesses, are no longer keeping pace with AI-assisted attackers.
- AI agents used defensively carry real risks: they can act unpredictably, be manipulated by outside inputs, and run up significant computing costs.
- 99% of organisations told Omdia they are investing in software supply chain security, treating it as a board-level business concern.
- Speed is now the single biggest worry for security teams, as AI allows attackers to find and exploit flaws faster than humans can respond.
The cybersecurity industry gathered at Black Hat USA 2026 in Las Vegas this summer, and one theme dominated the conversations: attackers are now using artificial intelligence to move faster than defenders can track. Research from Omdia, a technology analysis firm, suggests companies have taken notice and are opening their wallets in response.
Theresa Lanowitz, principal analyst at Omdia, presented findings from a study called Offensive Security Strategies: Granting the Same AI Advantages to the Defender, speaking at the Dark Reading News Desk. The core message was blunt: the old playbook is broken.
What exactly is 'offensive security', and why does it matter?
Offensive security means hiring experts to attack your own systems before the real criminals do, so you can fix the gaps first. Methods include penetration testing (experts attempt to break in using the same tricks real hackers use), red teaming (full simulated attacks on people and technology alike), and vulnerability assessments (systematic scans for weaknesses in software).
Lanowitz told the audience that all of these methods are falling short. "Those traditional cybersecurity practices that we've been using in offensive security, they're no longer working," she said. AI has shortened the time between a flaw being discovered and criminals exploiting it from weeks to hours in some cases, and human-speed testing simply cannot keep up.
The answer, her research suggests, is to deploy AI on the defender's side too: software agents, meaning programs that act independently to complete tasks, constantly scanning for exposed weaknesses, cataloguing every device and system a company runs, and flagging which problems carry the greatest real-world risk.
Should organisations worry about AI defenders going rogue?
Yes, and most already do. Lanowitz said survey respondents raised three honest concerns about using autonomous AI agents for security work.
| Concern | Plain-English meaning |
|---|---|
| Prompt injection | A hacker tricks the AI with a carefully worded input, hijacking what it does next |
| Unintended actions | The agent, acting autonomously, does something its operators did not expect or want |
| Resource costs | Running AI agents continuously burns computing power and can be expensive |
The second concern is the trickiest. Unlike a script that runs the same steps every time, an AI agent makes its own decisions. That flexibility is also a vulnerability.
"You want to limit the blast radius of what that agent is actually able to do," Lanowitz said, using a phrase borrowed from explosives terminology to mean: make sure a misbehaving agent cannot cause damage beyond a tightly defined area. Practically, that means running agents inside sandboxes, which are sealed-off digital environments where a program can operate without touching the wider network.
What should ordinary people take from this?
For most people, the direct impact is indirect but real. When a company's defences lag behind attackers, customer data, financial records, and personal information are what end up exposed. Faster, AI-assisted attacks mean breaches that once took months to unfold can now happen over a weekend.
If you work for a large organisation, the practical upshot is straightforward: security questions and unusual login prompts are not bureaucratic nuisances. They are the human layer of a defence that no AI agent can fully replace. Lanowitz's research noted that AI is now embedded in HR, accounting, and finance systems, which means every department is part of the attack surface, not just the IT team.



