Key facts
- Over 75% of AI-first businesses took an average of 80 days longer to recover from security incidents.
- Nearly half of surveyed businesses reported AI was directly exploited in their most recent security incident.
- AI-first businesses experienced an average of 54 known security breaches per year.
- 53% of security teams admitted lacking specialized AI expertise.
- AI tools often receive extensive automated permissions, becoming privileged parts of infrastructure.
- Shadow AI use is 31% higher among employees at AI-first organizations.
Accountancy firms are increasingly integrating artificial intelligence into their core processes, but this rapid adoption of AI is leaving them exposed to significant cybersecurity risks, according to a report by software company Fastly. These 'AI-first' organizations are taking, on average, 80 days longer to recover from security incidents compared to their peers.
The report found that nearly half of businesses surveyed identified AI as being directly exploited in their most recent security incident, a stark contrast to the seven percent of non-AI-first organizations. Furthermore, these AI-focused businesses are battling an average of 54 known security breaches annually.
Marshall Erwin, chief information security officer at Fastly, highlighted that cybercriminals specifically target accounting firms due to their privileged access to sensitive financial data. This vulnerability is exacerbated by a lack of specialized AI expertise within many security teams, with 53% admitting this deficit. The issue is compounded by AI tools often being granted extensive automated permissions, effectively making them privileged components of an organization's infrastructure and creating exploitable pathways.
The rise of 'shadow AI'—unauthorized AI tools adopted by employees without IT approval—is also a significant concern, running 31% higher in AI-first organizations. This uncontrolled usage further complicates security efforts and can negatively impact a business's bottom line. Erwin emphasized the need for security measures to keep pace with innovation, stressing the importance of understanding where AI is being used, what data and systems it can access, and establishing clear lines of responsibility.
This trend aligns with previous warnings, as Holly Waszak, head of cyber claims advocacy at Marsh, noted in June that professional services firms were a prime target for cyberattacks.
