There's an old saying that technology is neither good nor bad; it's how you use it that matters. If there's any tool to prove this point, it's AI. On the other hand, AI enables malicious actors to create new threats and launch attacks of unprecedented scale. Second, it provides security teams with completely new capabilities to strengthen their cyber defenses.
The 2025 Trend Micro Defenders research report delves into these two aspects of AI. Our analysis of more than 3,000 responses from 88 countries highlights the risks of AI that are keeping cyber defenders awake at night, and the opportunities cybersecurity teams are recognizing to use AI tools to strengthen their security posture.
Below are some highlights.
Counterfeiting and fraud are considered the biggest risks of AI
When it comes to AI risk, more than a quarter (26%) of survey respondents said protecting against fraud and AI-enabled impersonation is their top priority. Other major areas of focus include preventing AI application attacks, avoiding data and intellectual property leakage through AI tools, and gaining deeper insight into employee usage of AI solutions, whether in sanctioned apps or “shadow AI.”
It's no exaggeration to say that all of these priorities reflect a general concern about organizations' ability to understand and respond to AI-based attacks.
The good news is that you can do something. 15% of respondents said they have already received training and education to increase AI risk awareness. More than 10% say blocking the use of unapproved apps is a priority. Additionally, 7% are focused on preventing over-privileged access to information.
Many are looking to other tactics and actions to manage AI responsibly and minimize potential risks.
defender is fighting back
Zero trust architectures, data security posture management (DPSM), and encryption have all been reported as ways for organizations to protect themselves from AI-related threats. Unfortunately, proactive testing is less common, with only 6% of respondents saying they regularly conduct AI audits or work with red teams to ensure their cyber protections are as effective as possible.
That said, a positive sign is that more organizations seem to be engaging their cybersecurity teams early in the AI adoption process, with 23% engaging security in the discovery phase and 25% engaging security in the pilot phase.
This “shift left” is encouraging, even if there is still work to be done. Clearly, 17% only engage with security during implementation, when it may be too late. 10% don't know when security will be involved, and 6% say it's never involved.
Another obvious area where security teams can benefit from AI threats is through the deployment of AI tools. While that starts happening, some obstacles need to be removed.
Trust in AI in Cybersecurity
Just under 20% of survey respondents said their organizations have not yet started using AI-based cybersecurity tools. Roughly the same proportion said they had persistent concerns about AI's accuracy and reliability, and slightly fewer cited privacy risks as a reason for refraining from using it.
Admittedly, teams thinking about deploying AI defenses and then taking a long coffee break should feel anxious. AI tools need to be monitored and trained. But the most important thing is the training, and the sooner you start using and learning, the more effective it will be.
Another key to success is ensuring that the use of AI cybersecurity tools and strategies is aligned with business needs. 19% of survey respondents said their biggest challenge was identifying relevant and valuable use cases. This requires at least two things. One is to have technology and cybersecurity leaders have business-centric conversations with executives to uncover where security and business goals overlap. The second is to develop strategic, organization-wide practices for cyber risk management that can inform where and how AI tools are needed.
AI risk is at the heart of cyber risk management
In case you missed it, our previous blog on the 2025 Trend Micro Defender Research Report put these issues of AI risk into the broader context of cyber risk as a whole and how organizations are addressing it. Please check it out and of course download it. complete report.
This year’s results make it clear that AI is and will continue to be a key part of the future of cyber risk management. The question is not “Is AI our friend or foe?” The question is: “Where are the biggest AI risks we face, how can we respond to them, and how can we use AI to reverse the bad guys?”
As shown in this brief summary of our findings, the answer includes increasing awareness and training, maturing corporate policies, engaging security teams in AI adoption as early as possible, and leveraging the new advanced cybersecurity capabilities that AI provides.
In our next blog, we'll shift perspective and look at how organizations are maturing their approach to cloud risk management. stay tuned.
next step
To learn more about how to manage cloud risk, check out these additional resources:
