Edition Comparison
AI Security & AI Governance

Accenture State of Cybersecurity Resilience 2025 vs 2023: What Changed?

Accenture's 2025 State of Cybersecurity Resilience report reframes the series around a central question: whether organizations have the strategy and technical capabilities to operate securely in an AI-driven environment. This article compares the 2025 and 2023 editions.

By Cyntari Research Team·13 July 2026· 9 min read
Share
Accenture State of Cybersecurity Resilience 2025 vs 2023: What Changed? cover image

Accenture's 2025 State of Cybersecurity Resilience report reframes the research series around a central question: whether organizations have the strategy and technical capabilities to operate securely in an AI-driven environment. This article compares that edition with the 2023 report, using 2025 as the anchor.

The 2023 edition focused primarily on cybersecurity as an enabler of digital transformation. It examined a group Accenture called "cyber transformers": organizations that embedded security into transformation programs, aligned it with business objectives and applied stronger operational practices.

By 2025, the emphasis has moved from enabling transformation in general to securing AI adoption in particular. Business alignment remains important, but the newer report places more weight on AI governance, data and model security, cloud foundations, Zero Trust, proactive testing and AI-specific incident response.

The comparison may be useful to CISOs, security strategy leaders, AI governance teams, transformation executives and researchers studying how enterprise cybersecurity priorities have changed since 2023.

Short answer

The 2023 report presented cybersecurity as a way to improve the effectiveness and business outcomes of digital transformation. The 2025 edition retains that principle but applies it more directly to generative AI, arguing that most organizations lack the strategy and capabilities required to secure AI-enabled change. AI security, secure cloud foundations, model resilience and AI-assisted security operations receive much greater attention in 2025. Because Accenture also changed its survey population and maturity framework, figures from the two editions should not be treated as a direct year-over-year measurement.

What this report series covers

Accenture's State of Cybersecurity Resilience series examines how organizations structure, operate and align their cybersecurity programs.

In 2023, the report concentrated on the relationship between cybersecurity and enterprise transformation. Its main comparison was between "cyber transformers" and other surveyed organizations. Cyber transformers were defined as organizations that had accelerated digital transformation and planned to continue accelerating it.

The report argued that these organizations performed better because they involved security teams earlier, aligned cybersecurity with business objectives, embedded controls into transformation programs and supported those efforts with stronger operational practices. It reported that cyber transformers were 5.8 times more likely to experience more effective digital transformations and had 26% lower breach and incident costs than the rest of the surveyed group.

The 2025 report introduces a different analytical structure. It evaluates organizations across two dimensions:

  • Cyber strategy maturity: the ability to design and operationalize cyber-risk strategies.
  • Cyber capability: the technical ability to deliver cyber protection, resilience and cyber-physical security.

Organizations are then placed in one of three security posture zones: Reinvention-Ready, Progressing or Exposed. Only 10% of surveyed organizations were classified as Reinvention-Ready, while 63% were placed in the Exposed Zone.

This revised model gives the 2025 edition a broader maturity perspective. Rather than identifying a group based mainly on its transformation trajectory, it assesses whether strategic intent is matched by operational and technical capability.

What changed across editions?

AI moved from an emerging consideration to the organizing theme

The clearest change is the role of artificial intelligence.

In 2023, generative AI appeared mainly as an emerging opportunity and risk. The report suggested that it could support threat detection, analysis, response, automation, governance and fraud prevention. It also recognized that generative AI could create new attack vectors.

In 2025, AI is no longer a secondary development. It structures the report's problem statement, maturity assessment and recommendations.

The newer edition examines risks including:

  • Prompt injection.
  • Data poisoning.
  • Model manipulation and inversion.
  • Sensitive-data leakage.
  • AI-enabled phishing and deepfakes.
  • Adversarial prompts and self-replicating AI worms.
  • Security weaknesses in external models and AI suppliers.
  • Unauthorized or poorly governed AI use.

Accenture reports that 77% of surveyed organizations lacked foundational data and AI security practices, while only 20% expressed confidence in their ability to secure generative AI models. It also found that only 37% assessed the security of AI tools before deployment.

The difference is therefore more substantial than simply adding AI to the existing cybersecurity agenda. The 2025 edition treats AI systems, their data and their supporting infrastructure as a distinct security environment requiring dedicated controls.

The maturity model became more capability-focused

The 2023 report used the "cyber transformer" category to show how early security involvement and business alignment could support transformation outcomes.

Its differentiating practices included:

  • Involving cybersecurity in business planning.
  • Aligning cybersecurity with business objectives.
  • Using automation.
  • Protecting suppliers and ecosystem partners.
  • Using managed security services.
  • Integrating cyber risk into enterprise risk management.

The 2025 edition retains several of these practices but organizes them within a more formal assessment of strategy and capability. It evaluates 94 practices across cyber strategy, cyber protection, cyber resilience and cyber-physical security.

This creates a sharper distinction between having a strategy and being able to implement it. Accenture found that 34% of organizations had a mature cyber strategy, but only 13% possessed advanced cyber capabilities.

The newer report therefore places greater emphasis on execution gaps. An organization may recognize AI risk and establish policies without having the monitoring, testing, identity controls, cloud security or incident-response capability needed to manage that risk.

Secure transformation remained important but became more AI-specific

Both editions argue that cybersecurity should be built into transformation initiatives from the outset.

The 2023 report found that 35% of respondents embedded security controls in all transformation initiatives from the beginning, while 18% introduced controls only after transformation work was complete and vulnerabilities were found. It positioned early security involvement as a way to reduce rework and improve transformation outcomes.

The 2025 report shows that this concern remains unresolved. It reports that only 28% of organizations embed security in transformation initiatives from the outset and that less than half balance AI development with the security investment needed to protect it.

The underlying principle has not changed: security added after deployment is less effective than security designed into the program. What has changed is the scope. In 2025, secure transformation includes the complete AI stack, covering data, models, applications, identities, cloud infrastructure and third-party services.

Automation developed into a generative AI operating model

Automation was already one of the strongest differentiators in 2023. Accenture reported that 89% of cyber transformers relied heavily on automation, compared with 57% of other organizations. Respondents also associated automation with reducing the effects of cybersecurity talent shortages.

The 2025 edition expands this argument into a more detailed model for AI-assisted security operations. It discusses generative AI security assistants, automated alert triage, case enrichment, anomaly detection, threat modelling, vulnerability classification, patching and identity-risk analysis.

Accenture estimates that 71% of security analyst tasks could be augmented using generative AI. The report presents this as a way to improve efficiency and detection while emphasizing that AI-driven processes must remain explainable, monitored and validated.

Automation has therefore moved from being a sign of operational maturity to becoming part of a proposed reinvention of cybersecurity work.

The digital core became more technically specific

The 2023 report described the digital core as infrastructure and security, data and AI, and applications and platforms. It argued that cybersecurity was essential to building a digital foundation that could support continuing transformation.

The 2025 edition develops this concept through detailed recommendations for securing AI-enabled environments. These include:

  • Infrastructure-as-Code controls.
  • Cloud-native monitoring and policy enforcement.
  • Segmented environments for AI experimentation.
  • Centralized identity and access management.
  • Zero Trust principles.
  • Passwordless and risk-based authentication.
  • Data classification, encryption and tokenization.
  • AI-system inventories.
  • DevSecOps and software bills of materials.
  • Continuous model observability and adversarial testing.

Cloud, data, identity and application security are not new topics in the series. The difference is that the 2025 report connects them more explicitly to the development, deployment and operation of AI systems.

Resilience became more proactive and AI-specific

The 2023 edition discussed business continuity, incident response and ecosystem coordination, particularly in relation to geopolitical instability and third-party exposure. It found that cyber transformers were more likely to include ecosystem partners in incident-response plans and impose security standards on them.

The 2025 report continues this focus but adds AI-specific resilience practices. It recommends:

  • AI threat modelling.
  • Red-team exercises against prompt injection and model attacks.
  • Continuous monitoring of model behaviour.
  • AI-focused incident-response playbooks.
  • Executive crisis simulations.
  • Testing of third-party models.
  • Real-time monitoring of AI supply-chain risks.

The report notes that only 17.5% of organizations fully used threat intelligence and industry data to prioritize security decisions. It contrasts this with Reinvention-Ready organizations, which were more likely to conduct continuous monitoring, testing and structured incident-response planning.

Geopolitical and supply-chain risk remained consistent

Geopolitical instability and third-party exposure are prominent in both editions.

The 2023 report examined the consequences of Russia's invasion of Ukraine, reporting increased threats and concern about supply chains, physical infrastructure and external networks. More than half of respondents saw third parties and external networks as their most susceptible areas for attack.

The 2025 edition discusses a broader environment of tariffs, trade restrictions, shifting regulations and international instability. Its focus is on how organizations may introduce cyber risk when they change suppliers, data flows, sourcing models or regional operations without reassessing their security posture.

The specific geopolitical context has changed, but the recurring conclusion is similar: operational and supply-chain changes can create security exposure when third-party assessments, threat intelligence and governance do not keep pace.

Themes that became more prominent

AI Security & AI Governance

This is the largest thematic expansion in 2025. The report covers AI policies, executive accountability, model testing, data security, prompt injection, adversarial attacks, AI supply chains and responsible deployment.

In 2023, generative AI was presented as an emerging development. By 2025, it had become the report's main lens for evaluating enterprise security maturity.

Data Security & Privacy

The 2025 edition gives more attention to the data lifecycle supporting AI systems. It addresses classification, encryption, access controls, anonymization, synthetic data, training-data integrity and model-related data leakage.

Data protection appeared in 2023, but it was not developed as extensively or linked as closely to model security.

Cloud Security

Cloud security becomes more specific in 2025 because AI workloads frequently rely on cloud infrastructure. The report emphasizes secure cloud foundations, automated configuration, cloud-native security tooling and integration with DevSecOps.

Identity, Phishing & Access Security

The 2025 report connects identity security to AI and cloud operations through centralized IAM, continuous authentication, least privilege and context-aware access controls. It also addresses AI-enabled impersonation, phishing and deepfake fraud.

SOC, Detection & Response

Although automation and incident response were present in 2023, the 2025 report develops a more detailed vision for AI-assisted SOC operations, model monitoring, threat detection and automated investigation.

Software & Supply Chain Security

The scope expands from ecosystem protection and partner standards to include AI models, external AI services, software components, SBOMs, procurement controls and continuous vendor assessment.

Themes that remained consistent

Cyber Risk & Resilience

Both editions argue that cybersecurity should support business resilience rather than operate only as an incident-response function.

The 2023 report connects resilience to more effective transformation and lower incident costs. The 2025 edition connects it to the ability to protect AI-enabled operations, respond faster and maintain trust.

Emerging Technology & Digital Transformation

Cybersecurity remains closely tied to enterprise transformation. The primary difference is that digital transformation in 2025 is increasingly interpreted through AI adoption and the systems required to support it.

Governance, Regulation & Compliance

Both reports call for stronger integration between cyber risk, enterprise governance and business leadership.

The 2025 edition adds more emphasis on adaptive AI governance and changing regulatory expectations, but the core need for clear ownership and alignment remains consistent.

Cyber Workforce, Awareness & Collaboration

Talent shortages are a continuing constraint across both editions. Both recommend automation, external support, training and closer collaboration between security and business teams.

The 2025 report adds AI-focused awareness training and the development of security skills for AI systems.

Threat Actors, Geopolitics & Intelligence

Geopolitical disruption, changing attacker behaviour and threat intelligence remain important in both reports. The 2025 edition extends this theme to AI-assisted attacks and country-specific risks created by changing sourcing arrangements.

What this means for security teams

The comparison suggests that the security principles emphasized in 2023 remain relevant, but they now need to be applied to a broader and more technically complex environment.

Security teams still need early involvement in transformation planning, alignment with business objectives, strong operational practices and coordination with third parties. The 2025 report does not replace those priorities. It argues that they are insufficient unless they also cover AI systems and the infrastructure on which those systems depend.

For security leaders, this creates several practical priorities.

First, AI governance must connect to operational controls. Policies and accountability structures need to be supported by system inventories, access controls, testing, monitoring and incident-response procedures.

Second, security teams should treat AI as an end-to-end architecture rather than an isolated application. Model security depends on the protection of data pipelines, identities, cloud services, APIs, applications and external providers.

Third, resilience programs need AI-specific scenarios. Conventional incident playbooks may not adequately address data poisoning, prompt injection, model manipulation or compromises involving autonomous AI agents.

Finally, generative AI can assist security teams, but defensive AI also creates governance and validation requirements. Automation should be introduced with clear oversight, measurable outcomes and controls for accuracy and explainability.

Which edition should you read?

Read Accenture — State of Cybersecurity Resilience — 2025 for a current framework focused on AI security maturity, secure AI adoption and the relationship between cyber strategy and technical capability.

It is particularly relevant for:

  • CISOs developing an AI security strategy.
  • AI governance and responsible AI teams.
  • Security architects protecting cloud and AI environments.
  • SOC leaders evaluating generative AI-assisted operations.
  • Risk leaders assessing model and third-party AI exposure.
  • Boards seeking a maturity-based view of cybersecurity readiness.

Read Accenture — State of Cybersecurity Resilience — 2023 for its analysis of cybersecurity's role in digital transformation and its comparison between cyber transformers and other organizations.

It is particularly relevant for:

  • Transformation leaders trying to involve security earlier.
  • CISOs building stronger links with business strategy.
  • Enterprise-risk teams integrating cyber risk into broader governance.
  • Organizations evaluating automation and managed security services.
  • Researchers examining the development of Accenture's resilience framework.

Reading both editions provides the clearest view of the series' progression. The 2023 report establishes cybersecurity as a transformation enabler. The 2025 edition builds on that premise and asks whether organizations have the strategy and capabilities needed to secure AI-driven reinvention.

The quantitative findings should nevertheless be compared cautiously. The 2023 research included 3,000 respondents: 2,500 security executives and 500 business leaders across 14 countries and 15 industries. The 2025 research surveyed 2,286 CISOs and CIOs across 17 countries and 24 industries and applied a different maturity methodology.

The reports therefore show a change in Accenture's research emphasis and analytical model, but they do not provide a directly comparable time series for every metric.

Enjoyed this article? Share it.

Share

Reports mentioned in this article

Primary subject
Accenture· 2025

Accenture — State of Cybersecurity Resilience 2025

The report highlights the growing cybersecurity threats driven by the rapid adoption of generative AI, the widening security maturity gap, and the urgent need for organizations to adopt a Reinvention-Ready Zone approach to build resilience. It emphasizes the importance of integrating security into AI strategies, enhancing cyber capabilities, and addressing talent shortages to safeguard against modern threats.

AI Security & AI Governance
Identity, Phishing & Access Security
Cyber Risk & Resilience
Governance, Regulation & Compliance
Compared
Accenture· 2023

Accenture — How cybersecurity boosts enterprise reinvention to drive business resilience

Accenture's annual State of Cybersecurity Resilience research surveys 3,000 respondents across 14 countries and 15 industries to identify how a top group of "cyber transformers" use cybersecurity as a differentiator. They align security with business objectives, embed it early in transformation, build a strong digital core, lean on automation and managed services, and protect their wider ecosystem — and as a result are 5.8x more likely to run effective digital transformations and report 26% lower breach costs.

AI Security & AI Governance
Threat Actors, Geopolitics & Intelligence
Software & Supply Chain Security
SOC, Detection & Response

More reports by the sources mentioned