N-able Survey: AI is amplifying Complexity in Security Environments

N-able’s survey of 595 cybersecurity decision-makers and practitioners revealed that MSPs have the highest rate of operational complexity and policy exceptions.

Written By
Jordan Smith
Jordan Smith
Aug 4, 2026
4 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

N-able delivers end-to-end cyber resilience by unifying endpoint security, threat detection and response, and data recovery. The company’s recently released survey aims to understand how organizations adapt security operations as AI becomes increasingly embedded across technology stacks.

N-able’s AI Fog Report: MSPs facing greater AI challenges

The AI Fog Report: Finding Clarity Through Context is a survey of 595 cybersecurity decision-makers and practitioners across the US and UK, representing managed service providers (MSPs), small and medium-sized businesses (SMBs), and midmarket organizations.

According to the survey, frontier AI has accelerated adoption in complex security environments, adding complexity and increasing security alerts while weakening context and eroding trust, making it more difficult to convert detection into confident action.

MSPs reported the greatest operational burden, with 86.8% experiencing increased alert volume, 61% saying alert noise frequently disrupts response, and 83.5% encountering AI-assisted attacks.

MSPs face added complexity

According to Brendan Griffin, the director of threat research at N-able, MSPs manage many different clients with diverse needs, while supporting numerous AI tools and environments simultaneously. 

“MSPs are often handling a wide diversity of environments. They don’t necessarily always have that level of familiarity with every single environment,” said Griffin. 

“They’re going to be relying on the tools and the visibility that those tools will give them. One of the reasons that MSPs have been particularly burdened by AI adoption is because there’s so much diversity in the different business needs and the different types of AI tooling that might be applicable,” he added.

MSPs also reported the highest operational complexity after AI adoption (56.7%) and the highest rate of policy exceptions (88.5%), highlighting the governance burden of deploying AI across multiple customer environments.

Advertisement

Survey confirms pre-existing assumptions regarding AI adoption

Overall, Griffin explained that the survey results confirm existing assumptions about AI adoption in cybersecurity, but highlight the tension between rapidly adopting AI and maintaining strong security practices.

According to Griffin, the increase in security tools is a natural consequence of evolving technology, particularly cloud computing and identity management. AI is another layer of this evolution that could eventually simplify security operations by making sense of increasing volumes of alerts.

“The growth of the technology stack has organically forced us to have to look at more things, more planes of attack, more planes of defense,” said Griffin. 

“AI is now kind of coming in over on top of that. One of the things that rapid adoption of AI makes us do is ask how we respond to it in a way that still maintains those core security principles. I see it as a requirement for optimism around it, that this AI capability that we’re adopting in the security space will help us tell better stories about the things that are happening across all of these planes,” he added.

Alert fatigue: Which alerts should organizations prioritize?

In terms of the alert fatigue signaled in the survey, Griffin emphasized that organizations should prioritize protecting their most critical assets instead of attempting to address every alert equally. Security decisions should always support business objectives rather than exist independently.

“If I’m an organization that’s highly reliant on a cloud collaboration platform, and that’s where all of my core assets are, I would start to prioritize there,” Griffin explained. 

“Security is not there for itself. It’s there to support the business interests and to manage business risks. I think the core question for me is: What’s the most important aspect of our security posture?”

Advertisement

N-able’s advice for CISOs 

Griffin detailed two priorities for CISOs: deeply understanding the business and maintaining complete visibility into organizational assets.

Effective cybersecurity begins with knowing what needs protection and why it matters to the organization.

“I’ve had really great experiences working with CISOs who understand their business and are really invested in being able to serve those business needs,” Griffin mentioned. 

“Before you ever start asking, ‘How do we protect things?’ we kind of need to understand what we have to protect. We need to understand our own business and those needs, and then also know what we have. You can’t defend it if you don’t know it’s there. And if you don’t know why it’s there, it becomes harder to defend it in the right ways,” he added.

This threat research extends beyond studying attackers — it provides an opportunity to support smaller organizations through cybersecurity.

How N-able improves cybersecurity resilience

Rather than focusing solely on attackers, N-able’s work here influences product development and helps improve the resilience of nonprofits, schools, governments, and small businesses.

“One of the things that I’m really excited about with our unique approach is that we’re not just asking what the adversary is doing. We’re advising the ways that N-able is going to develop product features and the way that we implement certain things with the MDR services,” Griffin added.

Jordan Smith

Jordan Smith is an enterprise technology and cybersecurity journalist with nearly a decade of experience covering B2B IT, federal technology, artificial intelligence, cybersecurity, cloud computing, and emerging digital trends. His reporting helps business and technology leaders understand how new technologies, security challenges, and infrastructure decisions affect modern organizations. Jordan has reported on enterprise and public-sector technology for TechnologyAdvice, HCLTech, MeriTalk, and Channel Insider. His background spans cybersecurity, cloud infrastructure, AI adoption, digital transformation, and federal IT initiatives, giving him a broad perspective on the tools, policies, and innovations shaping today’s technology landscape. Before joining TechnologyAdvice, Jordan served as a Senior Technology Reporter at MeriTalk, where he covered the federal IT space, and later worked as a US Regional Reporter and Copy Editor/Writer for HCLTech. His experience across reporting, copyediting, podcasting, and event moderation allows him to translate complex technical topics into clear, timely, and useful insights for business audiences. Jordan holds a Master of Arts in Journalism from the University of Nebraska–Lincoln and a Bachelor of Science in Criminal Justice and Psychology from Edgewood University. Through his work, he helps readers stay informed about cybersecurity developments, enterprise technology trends, and the business impact of emerging IT solutions.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.