Fifty-nine percent of UK CISOs say attackers currently hold the advantage as artificial intelligence accelerates cyber threats, even as 94% describe their organizations as prepared to exploit AI-driven vulnerabilities, according to new research from cybersecurity company Kai.
That confidence contrasts with the pace of remediation on the ground. Kai found that 67% of respondents take more than a week to remediate critical vulnerabilities, while 54% said at least a quarter of their known vulnerabilities remain unresolved for more than 30 days.
UK CISOs report slow vulnerability remediation
Kai found that 67% of respondents take more than a week to remediate critical vulnerabilities. Another 54% said at least a quarter of their known vulnerabilities remain unremediated for more than 30 days.
At the same time, 59% of CISOs surveyed said attackers currently have the advantage because of AI adoption and advancement. Meanwhile, only 13% said defenders hold the advantage.
Kai said the findings point to a growing mismatch between the speed of AI-enabled attacks and security teams’ ability to respond.
“Artificial intelligence has changed the economics of cyber conflict in the UK, and the security leaders responsible for defending the enterprise are feeling the effects firsthand,” Kai said.
The company added that CISOs remain reliant on human labor for much of their vulnerability and exposure management work, potentially contributing to slower remediation and growing security backlogs.
Manual security processes widen the AI defense gap
More than half of respondents said their vulnerability and exposure management processes remain at least 50% manual, according to Kai.
The research suggests organizations are interested in moving toward more automated security operations, but trust remains a significant obstacle. Fifty-one percent of CISOs cited a lack of trust in automated decisions as a major barrier to greater automation.
Kai highlighted trust, governance, explainability, and accountability as central challenges organizations will need to address as they adopt more machine-led security operations.
“The next phase of enterprise defence will be defined less by whether organisations adopt automation and more by how quickly they can build the trust to let it act,” the company said in the report.
“The organisations that meet those conditions first will be the ones that close the gap between the speed of the threat and the speed of the response. “
According to Kai, most surveyed security leaders expect machine-led operations to play a larger role as organizations become more comfortable validating and governing automated security decisions.
What the AI defense gap means for UK MSPs and MSSPs
The gap between AI-driven threats and slower remediation could create a larger role for UK MSPs and MSSPs in helping customers operationalize security automation. Organizations dealing with large vulnerability backlogs may need more support to prioritize exposures, accelerate remediation, and reduce reliance on manual workflows.
At the same time, Kai’s findings suggest that adoption will depend on more than simply deploying additional automation. With CISOs citing a lack of trust in automated decisions as a major barrier, service providers may need to help customers establish clearer governance and oversight around machine-led security processes.
That could shift the conversation for MSPs and MSSPs from simply offering automation to showing customers how automated actions are monitored, explained, and controlled.
Providers that pair faster response with clear oversight and validation processes may be better positioned to support organizations adopting more machine-led security operations.
UK organizations also face tighter cyber reporting rules under the proposed Cyber Security and Resilience Bill. A VinciWorks survey found just 10% are confident they could meet the proposed 24-hour requirement. Read more about what the rule could mean for MSPs and critical suppliers.




