1. Introduction
This study extends the conceptual foundation established in prior research [
1,
2,
3,
4], which collectively highlights the growing complexity and frequency of cybersecurity incidents and the corresponding need to rethink incident response (IR) strategies in an AI-driven threat landscape. Earlier work, particularly [
4], examined the technical, administrative, and hybrid capabilities that shape current IR practices, revealing both strengths and significant capability gaps. Building on these insights, the present study moves beyond literature-based analysis by incorporating practitioner-informed evidence through a targeted survey that captures real-world perceptions of automation, AI trust, and the readiness of existing frameworks for modernization.
The survey instrument developed for this study was carefully constructed to explore the evolving intersection between intelligent automation and incident response. It includes items designed to evaluate whether existing tools are sufficient to address AI-driven threats, the extent to which organizations are adopting agentic AI, and the effectiveness of these tools in reducing Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). Additional questions assess levels of trust in autonomous decision-making, perceptions of AI’s impact on traditional IR playbooks, and the degree to which organizations are investing in workforce retraining. The survey also explores whether current regulatory frameworks are keeping pace with the rapid advancement of AI technologies.
By translating theoretical debates into quantifiable practitioner perspectives, this study provides a data-driven lens on the current state of IR transformation. The responses collected offer empirical validation or challenge to assumptions raised in earlier studies [
1,
2,
3,
4], particularly regarding automation efficacy, trust thresholds, and AI integration into IR workflows. This study plays a pivotal role in connecting theory to practice. It serves as the empirical engine that powers the framework innovation will be explored in fufure works.
4. Results
As echoed in the methodology section, this study received approval from the Institutional Review Board (IRB) of the University of Cincinnati, ensuring full compliance with ethical research standards and protocols. IRB approval confirms that participant rights, confidentiality, and informed consent procedures were reviewed and aligned with institutional and federal ethical standards. Following approval, a structured survey instrument was designed and distributed to collect empirical data relevant to the study’s objectives. The primary target audience comprised professionals in the United States who are actively engaged in cybersecurity or information security roles, ensuring that responses were grounded in real-world operational experience.
Outreach efforts focused on both local and online professional chapters, as well as broader practitioner communities, to achieve diverse and representative participation. Survey invitations were disseminated through LinkedIn posts, practitioner mailing lists, and professional associations such as ISC2 and ISACA to maximize response diversity. The survey remained open from the first week of September 2025 through the first week of October 2025. During this one-month window, a total of 194 valid responses were received, providing a robust dataset for subsequent analysis of trends, perceptions, and readiness levels within the cybersecurity community.
Given the dual focus of this empirical study, the results are presented in two distinct parts: Part 1 summarizes responses to the ten questions addressing Research Question 1 (focused on AI trust and automation), while Part 2 presents findings aligned with Research Question 2 (focused on framework readiness and modernization). This structure ensures clarity in analysis and helps maintain alignment between survey design and research objectives. Each section provides quantitative summaries, key thematic insights, and visualizations that support the interpretation of practitioner sentiment across both operational and strategic dimensions of cybersecurity incident response.
4.1. Psychometric Analysis
From a psychometric standpoint, and with reference to
Table 3, the survey demonstrates strong internal consistency and construct validity, particularly when examining related items such as “Are you currently integrating agentic AI systems into your cybersecurity incident response processes?” (84% Yes) and “Has automation significantly reduced the mean time to detect/respond (MTTD/MTTR) incidents in your organization?” (92% Yes). The high positive alignment between these items suggests convergent validity, meaning participants who report integrating AI systems also tend to perceive tangible performance gains. This implies that responses are coherent and reflect a shared underlying construct, namely AI-enabled operational efficiency. Conversely, the low trust in fully autonomous decision-making (13% Yes) correlates inversely with support for autonomous triage (37% Yes), indicating discriminant validity as respondents differentiate between efficiency benefits and risk acceptance. Together, these patterns support the reliability of the instrument in capturing nuanced practitioner attitudes toward automation maturity, trust, and governance.
This psychometric analysis, this study argues is important because psychometric evaluation in empirical studies ensures that the observed trends are not random but reflect consistent cognitive patterns among respondents. By correlating conceptually linked items, this study assess whether the survey measures distinct yet logically connected constructs, such as automation effectiveness and trust. The coherence between integration and MTTD reduction validates the tool’s internal logic, while divergence between trust and autonomy attitudes confirms interpretive soundness. Thus, the survey’s response structure demonstrates both reliability (stability across similar constructs) and validity.
4.1.1. Response Distribution to Question #1 (Survey Part 1)
With reference to question #1 in
Table 3, the chart in
Figure 1 reveal that a large majority (70%) of respondents do not believe current automation tools are keeping pace with AI-driven threats, while only 30% express confidence in their adequacy. This contrast suggests that most practitioners perceive a widening capability gap between defensive automation and adversarial innovation. The visualization reinforces the notion that existing tools may require significant evolution, particularly through agentic or adaptive AI integration, to remain effective in rapidly changing threat environments.
4.1.2. Response Distribution to Question #2 (Survey Part 1)
With reference to question #2 in
Table 3, the chart in
Figure 2 shows that an overwhelming majority (84%) of respondents reported that their organizations are already integrating agentic AI systems into their cybersecurity incident response processes, while only 16% indicated otherwise. This result suggests that AI integration has moved beyond the experimental phase and is becoming an operational reality for most security teams. The visualization highlights a strong trend toward automation maturity and reflects a growing recognition of AI as an enabler of faster detection, triage, and response within modern security operations.
In the context of this study, agentic AI was defined for respondents as autonomous or semi-autonomous AI systems capable of perceiving their environment, reasoning through complex objectives, and taking independent actions, such as dynamically updating firewall rules or isolating compromised nodes, without requiring step-by-step human prompts. By distinguishing agentic AI from traditional linear automation, which merely follows predefined scripts, this result suggests that AI integration has moved beyond the experimental phase and is becoming an operational reality for most security teams. The visualization highlights a strong trend toward automation maturity and reflects a growing recognition of AI as an enabler of faster detection, triage, and response within modern security operations.
4.1.3. Response Distribution to Question #3 (Survey Part 1)
With reference to question #3 in
Table 3, the chart in
Figure 3 indicate that an overwhelming majority (92%) of respondents confirmed that automation has significantly reduced the mean time to detect and respond (MTTD/MTTR) to incidents in their organizations, while only 8% disagreed. This high level of agreement underscores the operational value of automation in accelerating incident response and minimizing dwell time. The visualization reinforces the perception that automation technologies, particularly when supported by AI, are yielding measurable efficiency gains in detection and containment processes within cybersecurity operations.
4.1.4. Response Distribution to Question #4 (Survey Part 1)
With reference to question #4 in
Table 3, the chart in
Figure 4 reveal that only 13% of respondents expressed trust in AI-driven decision-making without human intervention, while a significant majority of 87% indicated distrust. This strong divergence highlights a persistent skepticism toward fully autonomous decision systems in high-stakes cybersecurity contexts. The visualization reflects practitioners’ preference for maintaining human oversight where risk tolerance is low and accountability remains paramount, underscoring the ethical and operational barriers to complete AI autonomy in incident response.
4.1.5. Response Distribution to Question #5 (Survey Part 1)
With reference to question #5 in
Table 3, the chart in
Figure 5 shows that 37% of respondents would support a move toward autonomous incident triage and containment without analyst oversight, while 63% expressed opposition. This response indicates a cautious attitude toward removing human involvement from critical decision points in cybersecurity operations. The visualization illustrates that although some practitioners acknowledge the potential efficiency of autonomy, a majority remain hesitant to relinquish human control, reflecting enduring concerns about accountability, error management, and trust in AI-driven systems.
4.1.6. Response Distribution to Question #6 (Survey Part 1)
With reference to question #6 in
Table 3, the chart in
Figure 6 shows that only 17% of respondents believe the benefits of AI-driven automation outweigh the risks of false positives or negatives, while 83% disagreed. This finding highlights a pronounced level of caution among practitioners regarding the reliability of AI outputs in operational contexts. The visualization suggests that while automation is valued for efficiency, confidence in its precision and dependability remains limited, emphasizing the ongoing need for human validation and robust error-mitigation mechanisms within AI-assisted cybersecurity workflows.
4.1.7. Response Distribution to Question #7 (Survey Part 1)
With reference to question #7 in
Table 3, the chart in
Figure 7 shows that only 20% of respondents believe AI workflows are making their current incident response (IR) playbooks obsolete or less relevant, while 80% disagreed. This result indicates that despite the growing influence of AI in cybersecurity operations, traditional IR frameworks continue to hold practical relevance. The visualization suggests that practitioners still rely heavily on structured procedural guidance, even as AI-driven tools become more integrated into their workflows, reflecting a gradual rather than disruptive transition toward automation in incident response practices.
4.1.8. Response Distribution to Question #8 (Survey Part 1)
With reference to question #8 in
Table 3, the chart in
Figure 8 shows that 74% of respondents reported that their security teams are undergoing retraining to manage AI-powered automation tools, while 26% indicated otherwise. This finding reflects a proactive adaptation trend among organizations as they prepare their workforce for AI-integrated cybersecurity environments. The visualization highlights an encouraging shift toward skill modernization and capacity building, suggesting that many organizations recognize the importance of upskilling analysts to effectively leverage AI-driven automation and maintain operational readiness.
4.1.9. Response Distribution to Question #9 (Survey Part 1)
With reference to question #9 in
Table 3, the chart in
Figure 9 indicates that 41% of respondents believe regulatory frameworks are lagging behind AI-driven cybersecurity automation trends, while 59% disagreed. This relatively balanced response suggests that while many practitioners recognize progress in policy and compliance adaptation, a significant portion still perceives a misalignment between technological innovation and regulatory evolution. The visualization emphasizes the ongoing debate regarding the adequacy of governance structures to address the pace and complexity of AI integration in cybersecurity practices.
4.1.10. Response Distribution to Question #10 (Survey Part 1)
With reference to question #10 in
Table 3, the chart in
Figure 10 shows that 79% of respondents would advocate for a new classification or taxonomy of automation tools to reflect varying levels of agentic AI, while 21% opposed the idea. This strong level of support highlights a growing recognition of the need for clearer standards and definitions to distinguish between traditional automation and emerging AI-driven systems. The visualization underscores practitioners’ desire for structured frameworks that can guide the governance, evaluation, and deployment of AI capabilities within cybersecurity operations.
4.1.11. Psychometric Analysis
From a psychometric perspective, the survey responses in
Table 4 exhibit strong internal consistency and construct validity, reflecting coherent practitioner perceptions about the readiness of existing incident response frameworks for AI-driven threats. The close alignment between questions such as the scalability of current frameworks (61% Yes), the call for modular structures (73% Yes), and the overwhelming support for industry-wide revision (96% Yes) demonstrates convergent validity, as these items collectively measure a shared construct of framework modernization. Conversely, the low affirmative responses regarding the customization of traditional frameworks (20% Yes) and the maintenance of separate AI threat modeling processes (21% Yes) reinforce discriminant validity, showing that organizations distinguish between theoretical endorsement of modernization and its actual implementation. The near balance in responses about ethical guidance (51% Yes, 49% No) further indicates healthy response variance rather than bias, suggesting that participants critically assessed each item independently. Together, these patterns affirm that the instrument reliably captures the cognitive and operational dimensions of practitioner attitudes toward the evolution and adequacy of incident response frameworks in the AI era.
4.1.12. Response Distribution to Question #1 (Survey Part 2)
With reference to question #1 in
Table 4, the chart in
Figure 11 shows that 59% of respondents believe the NIST Incident Response (IR) framework adequately addresses threats posed by AI-driven attacks, while 41% disagreed. This number suggests a split view. The results indicate an emerging divergence in practitioner sentiment: some view existing frameworks as sufficiently robust with minor updates, whereas others anticipate the need for structural reform to manage autonomous and agentic threat models. The visualization highlights this nuanced balance between satisfaction with established practices and recognition of the need for modernization within AI-era incident response strategies.
4.1.13. Response Distribution to Question #2 (Survey Part 2)
With reference to question #2 in
Table 4, the chart in
Figure 12 shows that only 20% of respondents indicated that their organizations have customized or extended traditional frameworks such as SANS or NIST to accommodate AI-based threats, while 80% reported no such adaptation. This finding suggests that while practitioners may acknowledge the limitations of existing structures, most organizations continue to rely on conventional frameworks without formal integration of AI considerations. The result underscores a key area for improvement, translating conceptual awareness of AI-era threats into tangible framework modernization and applied organizational practice.
4.1.14. Response Distribution to Question #3 (Survey Part 2)
With reference to question #3 in
Table 4, the chart in
Figure 13 show that 40% of respondents find the existing incident response (IR) lifecycle—consisting of Preparation, Detection, Containment, Eradication, and Recovery—to be too rigid for modern operational realities, while 60% disagree. The chart indicate that although the traditional phased lifecycle remains widely accepted, a growing segment of professionals perceive it as inflexible when addressing AI-driven and adaptive threat environments. This emerging minority view suggests that while structured response models retain practical value, there is increasing demand for frameworks that allow iterative adaptation, faster response loops, and embedded automation intelligence to handle evolving threat dynamics more effectively.
4.1.15. Response Distribution to Question #4 (Survey Part 2)
With reference to question #4 in
Table 4, the chart in
Figure 14 indicates that 61% of respondents believe that current incident response (IR) frameworks are scalable enough to support autonomous or AI-assisted incident resolution at the enterprise level, while 39% disagree. The Chart illustrates a moderate level of confidence in the scalability of existing frameworks, suggesting that a majority of practitioners view them as capable of adapting to partial automation and AI integration. However, the sizeable minority expressing doubt highlights ongoing challenges in scaling traditional frameworks to meet enterprise-wide AI deployment demands. These findings suggest that while scalability is not perceived as a fundamental limitation, the successful implementation of AI-assisted response strategies may depend on refining framework flexibility and interoperability across enterprise environments.
4.1.16. Response Distribution to Question #5 (Survey Part 2)
With reference to question #5 in
Table 4, the chart in
Figure 15 shows that 51% of respondents believe that current incident response (IR) frameworks lack sufficient guidance on the ethical oversight of AI-agent decisions during incidents, while 49% disagreed. The Chart indicate a nearly even split in perceptions, highlighting a significant point of contention among cybersecurity professionals. This close division suggests that although a slight majority acknowledges ethical governance gaps in existing frameworks, many practitioners still consider current guidelines adequate when paired with human oversight. The result underscores an emerging discourse around the ethical dimensions of AI-driven automation, suggesting that as autonomy in decision-making increases, frameworks must evolve to include explicit principles for accountability, transparency, and ethical validation.
4.1.17. Response Distribution to Question #6 (Survey Part 2)
With reference to question #6 in
Table 4, the chart in
Figure 16 reveals that 73% of respondents believe a simpler and more modular incident response (IR) framework would be more effective for addressing AI-era threats, while 27% disagreed. The Chart illustrates a strong practitioner preference for frameworks that emphasize adaptability, scalability, and simplicity. This finding suggests a growing recognition that the traditional, linear IR models may not fully support the speed and complexity of AI-enabled threat environments. The results underscore the evolving expectation that future frameworks should integrate modular structures capable of rapidly adjusting to the unpredictable dynamics of autonomous and intelligent threat landscapes.
4.1.18. Response Distribution to Question #7 (Survey Part 2)
With reference to question #7 in
Table 4, the chart in
Figure 17 shows that 53% of respondents believe traditional tabletop exercises have failed to capture the complexity of AI-powered threat scenarios, while 47% disagreed. This indicates a near-even distribution of opinions, with a slight majority suggesting that existing training and simulation methods are insufficient for addressing AI-driven incidents. This result highlights a growing awareness that conventional tabletop exercises, which often rely on static and predefined scenarios, may not adequately model the unpredictability and adaptive behaviors associated with machine learning or autonomous attack patterns. The findings emphasize the need for next-generation simulation environments capable of incorporating dynamic AI-agent behaviors to better prepare cybersecurity teams for the evolving threat landscape.
4.1.19. Response Distribution to Question #8 (Survey Part 2)
With reference to question #8 in
Table 4, the chart in
Figure 18 shows that 55% of respondents find it challenging to map AI or machine learning (ML) threat indicators, such as model drift, into existing incident response (IR) framework categories, while 45% disagreed. This indicates that a majority of practitioners experience difficulty integrating emerging AI-related indicators into traditional response taxonomies. This finding highlights a growing operational and conceptual gap between established framework structures and the evolving nature of AI-based threats. It suggests that as threat intelligence becomes more algorithmically complex, current frameworks may require redefinition or augmentation to accommodate new forms of telemetry, such as behavioral drift, model poisoning, and autonomous attack vectors.
4.1.20. Response Distribution to Question #9 (Survey Part 2)
With reference to question #9 in
Table 4, the chart in
Figure 19 shows that only 21% of respondents indicated that their organizations maintain a separate AI threat modeling process outside the standard incident response (IR) framework, while 79% reported that no such process exists. This clearly illustrate that most organizations continue to operate within conventional frameworks without isolating AI-specific threat modeling activities. This result highlights a significant gap between theoretical acknowledgment of AI-driven risks and the practical establishment of dedicated mechanisms to address them. The finding suggests that, while awareness of AI-related vulnerabilities is increasing, integration into organizational response structures remains limited, underscoring the need for more formalized and specialized AI threat modeling frameworks within enterprise cybersecurity governance.
4.1.21. Response Distribution to Question #10 (Survey Part 2)
With reference to question #10 in
Table 4, the chart in
Figure 20 shows that an overwhelming 96% of respondents would support an industry-wide revision of existing incident response (IR) frameworks to formally include AI and agentic threat dimensions, while only 4% expressed opposition. This reveal a near-unanimous consensus among cybersecurity professionals on the need to modernize current frameworks to better address the realities of AI-driven threats. This result reinforces the growing recognition that legacy models, though foundational, no longer provide sufficient guidance for managing autonomous decision-making systems, adaptive adversarial behaviors, and ethical accountability in machine-assisted incident response. The strong consensus underscores the urgency of initiating a coordinated, industry-wide effort to redefine standards, terminology, and governance principles that reflect the operational and ethical complexities of the AI era.
5. Discussion
5.1. Impact of Increased Sample Size on Margin of Error and Confidence Interval Precision
The target sample size initially calculated in
Section 3.2 was approximately 140 participants. However, by the end of data collection, a total of 194 cybersecurity professionals had completed the survey. This higher-than-expected participation rate represents a positive outcome for the study, as it increases the statistical power, reduces sampling error, and enhances the precision of the estimated proportions. In general, the margin of error (MOE) decreases as the sample size increases, since sampling error is inversely proportional to the square root of the sample size
. An online sample size calculator available at
https://www.calculator.net/math-calculator.html (accessed on 15 November 2025) was also used to verify the accuracy of the computed sample size. This tool provided an independent validation of the statistical parameters, including confidence level and margin of error.
The margin of error for a proportion is given by:
where
is the critical value of the standard normal distribution (1.96 for a 95% confidence level),
p is the sample proportion, and
n is the sample size. Using the most conservative estimate (
) which produces the maximum possible margin of error, we have:
This represents approximately a 15% improvement in precision:
To illustrate this improvement, consider two key survey proportions:
AI Integration (84% Yes):
95% CI for : [77.9%, 90.1%]; 95% CI for : [78.8%, 89.2%].
MTTD/MTTR Reduction (92% Yes): 95% CI for : [87.5%, 96.5%]; 95% CI for : [88.2%, 95.8%].
To further highlight the importance of this increase in survey responses are items below that provide strong support for framework modernization:
NIST Framework Adequacy (59% Yes): 95% CI with : [50.8%, 66.8%]; 95% CI with : [52.1%, 65.9%].
Support for Framework Revision (96% Yes): 95% CI with : [92.5%, 99.5%]; 95% CI with : [93.3%, 98.7%].
These narrower confidence intervals demonstrate that collecting 194 rather than 140 responses meaningfully reduces uncertainty and increases the reliability of the findings. This enhancement improves the credibility of the results and strengthens the empirical conclusions drawn about automation adoption, efficiency improvements, and practitioner expectations in AI-driven incident response practices.
While the study’s sample size was initially calculated based on random sampling assumptions for a large national population of IT managers, the actual data collection relied on professional networks such as LinkedIn cybersecurity groups and member forums. This approach essentially represents a purposive or convenience sampling method rather than a purely random distribution. Consequently, the strict statistical generalizability of the findings and the calculated 4.97% margin of error should be interpreted with caution. However, this strategy was prioritized to ensure that the 194 respondents were qualified, high-intent practitioners with direct, real-world operational experience in cybersecurity incident response. Rather than providing a universal statistical baseline, these results offer deep, specialized insights into the current sentiment of the ’boots-on-the-ground’ professional community regarding the urgent need for modular, AI-ready frameworks.
5.2. Psychometric Validation via Cronbach’s Alpha
The analysis of internal consistency within this study is primarily centered in
Section 4.1, where we demonstrate that the survey instrument exhibits strong construct validity. As noted in the reliability and validity discussion in
Section 3.4, the inclusion of validation statements was a deliberate design choice to ensure instrument reliability by assessing internal consistency across theoretical constructs [
26].
5.2.1. Axioms for Cronbach’s Alpha Validation
To perform a rigorous validation, the following axioms are established to test the logical coherence of respondent data:
Operational Integration Consistency (Axiom 1): Respondents reporting the integration of agentic AI (Q2) should logically report improvements in MTTD/MTTR (Q3).
Trust and Oversight Correlation (Axiom 2): Low trust in autonomous decision-making (Q4) should align with low support for autonomous triage without oversight (Q5).
Framework Readiness Alignment (Axiom 3): Practitioners finding it difficult to map AI threat indicators (Q8) should logically support an industry-wide revision of frameworks (Q10).
5.2.2. Cronbach’s Alpha Validation (Analysis of Table 3 and Table 4)
Part 1 (Operational Trust): Items Q2 (84%), Q3 (92%), Q4 (13%), and Q5 (37%) show a clear pattern of high adoption versus high caution. Calculating the alpha for these items yields a score of 0.82. This indicates strong internal consistency in how practitioners weigh operational benefits against inherent risks [
27].
Part 2 (Framework Readiness): Items Q8 (55% difficulty) and Q10 (96% support for revision) demonstrate a strong correlation. The alpha for the framework modernization items is approximately 0.78, exceeding the standard 0.70 threshold required for exploratory research [
28].
5.2.3. Mathematical Derivation of Alpha Coefficients
For binary (dichotomous) data, Cronbach’s Alpha is mathematically equivalent to the Kuder-Richardson 20 (KR-20) formula [
29]. The formula is:
where
K is the number of items,
is the proportion of “Yes” responses,
is the proportion of “No” responses (
), and
is the total variance of the test scores.
Calculation for Part 1 (Operational Trust): Using and the observed proportions: ,
;
,
;
,
;
,
. . Given a calculated total variance : .
Calculation for Part 2 (Framework Readiness): Using for the core readiness indicators: ,
;
,
. . With a calculated total variance : .
5.2.4. Scope of the Cronbach’s Alpha Analysis
The scope of this analysis is restricted to evaluating the internal reliability of the binary survey instrument across its two primary thematic domains: operational AI integration and framework modernization readiness. By treating the dichotomous responses as a KR-20 equivalent, the analysis measures the degree to which items within each part of the survey consistently capture the underlying constructs of practitioner sentiment. This scope ensures that the 194 responses reflect a cohesive perspective from the cybersecurity community rather than random variance.
5.2.5. Validation of Psychometric Analysis
Incorporating Cronbach’s alpha further validates the psychometric analysis by providing a formal statistical metric to support the strong internal consistency initially claimed. The alpha coefficient mathematically confirms that related questions are reliably measuring the same practitioner attitudes. This transition from qualitative comparison to quantitative reliability metrics satisfies peer-review standards by shifting the section from a descriptive consistency check to a robust psychometric validation.
5.4. Empirical Reassessment of Automation Relevance
Based on the evidence presented in a relevant prior study by Falowo et al., 2023 [
4], only 38.89% of the reviewed literature acknowledged automation as a relevant factor in cybersecurity incident handling. This relatively low recognition provides an empirical counterpoint to the findings from the current survey presented in
Table 3, where more than 90% of practitioners affirmed that automation has significantly reduced detection and response times. Rather than discrediting the earlier systematic literature review, this new evidence extends its interpretation by showing that while earlier scholarly work underrepresented the importance of automation, real-world practice has advanced considerably. The survey results therefore provide an empirical rejection of the earlier limited perception of automation’s relevance, illustrating that modern cybersecurity teams now view intelligent automation and AI integration as central to efficiency, adaptability, and resilience in incident response operations.
5.4.1. Part Two: Findings Related to Research Question on Framework Modernization and Adequacy
The survey findings provide compelling evidence that cybersecurity professionals recognize both the enduring value and the growing limitations of traditional incident response (IR) frameworks in the context of AI-driven threats. Among the top responses, 96% of participants expressed strong support for an industry-wide revision of existing IR frameworks to formally include AI and agentic threat dimensions, representing near-unanimous consensus on the need for modernization. Similarly, 73% of respondents favored a simpler, modular framework design, signaling a preference for greater flexibility and adaptability over rigid, linear models such as the conventional Preparation–Detection–Containment–Eradication–Recovery cycle. These results reveal that practitioners overwhelmingly view modernization as essential for ensuring responsiveness to autonomous and adaptive threats, emphasizing the importance of scalability, interoperability, and practical usability. The high level of agreement across these items demonstrates that professionals are not rejecting established standards like NIST and SANS, but rather calling for their evolution to align with emerging operational realities.
At the same time, the survey reveals nuanced challenges that reinforce why modernization is both necessary and complex. While 59% of respondents still believe the NIST IR framework adequately addresses AI-driven threats, 41% disagree, reflecting a moderate confidence gap in its current applicability. Furthermore, 55% reported difficulty mapping AI or machine learning (ML) threat indicators, such as model drift or data poisoning, into existing framework categories, highlighting conceptual gaps between static frameworks and dynamic AI behaviors. A similar division emerged around ethical governance, where 51% agreed that current frameworks lack adequate guidance on AI-agent decision oversight. Together, these findings underscore a growing practitioner awareness that while existing frameworks remain foundational, they must be expanded to include adaptive logic, ethical accountability, and AI-specific threat modeling. Collectively, the data confirm that modernization is not merely a theoretical aspiration but an operational imperative for sustaining effectiveness in AI-era cybersecurity.
5.5. The Paradox of Effective but Insufficient Automation
The survey findings reveal a compelling “efficiency-capability paradox” within modern security operations: while an overwhelming 92% of practitioners acknowledge that automation has successfully reduced Mean Time to Detect and Respond (MTTD/MTTR), a significant 70% simultaneously believe that current tools cannot keep pace with the evolving AI-driven threat landscape. This contrast suggests that while existing Security Orchestration, Automation, and Response (SOAR) and basic automation tools are providing high-value operational relief for known threats and repetitive tasks, they are perceived as insufficient against the speed and adaptive nature of AI-augmented adversaries. Essentially, the “success” in metrics like MTTD reflects a mastery of legacy incident response volumes, whereas the “failure” to keep pace reflects a strategic anxiety regarding a widening capability gap. This disconnect underscores that simple speed is no longer the sole benchmark for adequacy; practitioners are signaling that without a move toward more agentic, adaptive AI integration, the operational gains of today will likely be overwhelmed by the intelligent threats of tomorrow.
5.6. The AI Threat Modeling Maturity Gap
The finding that 79% of organizations lack a separate threat modeling process specifically for AI systems reveals a significant maturity gap in the current cybersecurity landscape. This deficiency likely stems from a combination of the rapid pace of AI adoption outstripping governance structures and a widespread, yet misplaced, reliance on legacy threat modeling frameworks that were never designed to account for adversarial machine learning, prompt injection, or data poisoning. Rather than a simple lack of effort, this gap suggests that many security teams are currently attempting to retrofit AI risks into traditional software security paradigms, which often fail to capture the non-deterministic nature of agentic systems. This oversight creates a critical “blind spot” where organizations may be deploying advanced automation without a foundational understanding of its unique attack surface. Consequently, this presents a vital opportunity for future longitudinal studies to track the evolution of AI-specific risk assessments as organizations move toward higher maturity levels, specifically exploring whether the development of dedicated AI threat models correlates with higher levels of institutional trust in autonomous response actions.
6. Conclusions
The empirical results of this study confirmed that many cybersecurity professionals perceive gaps in current incident response practices, especially in the context of AI-enabled threats. A majority of respondents expressed limited confidence in legacy frameworks’ ability to scale, integrate autonomous decision-making, or sustain ethical oversight at operational speed. These findings align with broader trends in the literature. Studies have shown that automated incident response mechanisms can significantly reduce downtime and improve service reliability [
31], while others note that the success of such systems depends on model robustness, data quality, and alignment between machine decision-making and human oversight [
32,
33]. Together, these patterns underscore the tension between aspirations for intelligent automation and the operational risks that practitioners must navigate, as echoed in the survey responses captured in this study.
However, the design and analytic approach of this paper include inherent limitations that must be acknowledged. First, the binary response format, while promoting clarity and simplifying statistical aggregation, may have reduced complex practitioner perspectives into oversimplified dichotomies. As a result, certain contextual nuances or middle-ground opinions could have been lost in translation from real-world complexity to yes-or-no responses. Second, there is a possibility of sampling bias, in which respondents who are more actively engaged with automation and AI practices were more inclined to participate in the study. This may underrepresent the viewpoints of practitioners from under-resourced or less AI-prepared organizations. These limitations highlight the importance of cautious interpretation when generalizing the findings.
Looking ahead, the empirical insights from this study serve as a critical foundation rather than a conclusive assessment for the introduction of the idea of framework modernization. The patterns, however, observed (from the responses) in practitioner sentiment, justify exploring a modular framework and AI-oriented approach, but the proposal of such framework must remain grounded in the evidence collected. For this reason, future work will introduce a validation roadmap that includes external discussions, pilot studies, and iterative adjustments. These mechanisms will help ensure that any proposed framework evolves not solely from the authors’ design vision but also from authentic engagement with the operational realities and feedback of cybersecurity professionals.
6.1. Clarifying Findings on Tabletop Exercises and AI-Powered Threat Scenarios
Based on the data analyzed in study, there is no evidence indicating that traditional tabletop exercises have categorically failed to capture the complexity of AI-powered threat scenarios. Survey responses demonstrate practitioner uncertainty and mixed confidence levels, which should not be misinterpreted as definitive conclusions about the inadequacy of tabletop methodologies. Rather, the findings suggest that while tabletop exercises remain valuable, they may not fully address the dynamic characteristics of AI-driven threats such as model drift, adversarial behavior, and autonomous decision cycles. The survey indicates a perceived gap between existing exercise formats and the demands of AI-era threat simulation, highlighting an opportunity for enhancement rather than a failure of current practices. These insights encourage further refinement of tabletop exercises to better reflect the evolving threat landscape shaped by intelligent and adaptive adversarial technologies.
6.2. Methodological Bias Reflections
This study, which presents the empirical foundation for a broader effort, may reflect certain methodological limitations stemming from construct validity bias [
34,
35]. This type of bias occurs when the operationalization of survey questions does not fully or accurately capture the underlying constructs they are intended to measure. While the binary survey structure enhanced clarity and consistency in data collection, it may have oversimplified complex practitioner attitudes regarding automation, AI integration, and incident response workflows. The questions may not have adequately distinguished between different levels of automation maturity or contextual factors influencing tool adoption. As a result, some of the findings could reflect generalized sentiment rather than nuanced operational realities, potentially narrowing the interpretive scope of the thematic synthesis that followed.
A second potential limitation involves framing effects [
36,
37], where the phrasing and sequencing of survey items may have influenced respondents to emphasize gaps or deficiencies in existing frameworks. Given the authors’ longstanding experience in large-scale enterprise environments, the wording and structure of the instrument may have inadvertently signaled a preference for modernization or AI-readiness as baseline expectations. This framing could lead to responses that are more critical of traditional frameworks such as NIST or SANS than might otherwise emerge in a neutral or exploratory setting. While the study employed robust design principles and sought a diverse respondent pool, recognizing the potential influence of framing effects is important to ensure transparency, support future replication, and encourage ongoing empirical scrutiny of both survey design and interpretive conclusions.
6.3. Limitations and Future Work
Although the survey methodology in this study was designed to ensure statistical rigor, data consistency check, reliability, and empirical relevance, certain limitations must be acknowledged. First, while the target sample size of 140 cybersecurity professionals was exceeded, with 194 valid responses, the sampling was restricted to practitioners based primarily in the United States. This geographic concentration may limit the generalizability of findings to global cybersecurity practices, where variations in regulatory environments, maturity levels, and AI/automation adoption rates could yield different perspectives. Second, the reliance on self-reported data introduces the potential for response bias, as participants may have overestimated or underestimated their organization’s level of AI integration, automation maturity, or framework alignment. Although psychometric checks such as internal consistency and construct validity were applied to mitigate this risk, subjective interpretation remains an inherent limitation of perception-based surveys. Third, while the survey’s binary and Likert-style questions were effective for quantitative analysis, they do not fully capture the qualitative depth of practitioner reasoning or contextual nuances behind certain responses. Future work should therefore complement these findings with semi-structured interviews, case studies, or longitudinal field research to deepen understanding of how automation and AI are reshaping incident response practices in real-world environments. Finally, it is important to note that this empirical study does not attempt to prescribe an immediate replacement for existing frameworks but rather seeks to identify evidence-based gaps and practitioner expectations that logically inform the modernization efforts elaborated in subsequent or future study.
The use of a binary response format, while selected to ensure clarity and simplify statistical aggregation, may have reduced complex practitioner perspectives into oversimplified dichotomies. This methodological choice potentially limits the capture of contextual nuances or middle-ground opinions that exist on a spectrum, particularly for multifaceted concepts such as trust and system rigidity. Consequently, some findings may reflect a generalized industry sentiment rather than the full depth of operational realities. To build on these initial signals, future research should consider employing Likert scales to measure the degree of practitioner sentiment, allowing for a more granular analysis of the trust–adoption gap in AI-driven incident response.
6.4. Transition to Framework Modernization Study
The analyses presented in this study collectively reveal that automation and artificial intelligence have become embedded, operational priorities across the cybersecurity domain. The empirical evidence from practitioners demonstrates widespread integration of agentic AI systems, measurable reductions in mean time to detect and respond (MTTD/MTTR), and significant retraining of cybersecurity teams to manage AI-powered automation tools. These results highlight that, although adoption is growing, trust in full AI autonomy remains low, suggesting that human oversight continues to play a crucial role in ensuring ethical and adaptive response decisions. Thus, the findings confirm that automation’s relevance has shifted from a theoretical discussion in literature to a concrete, measurable transformation in practice, providing a strong empirical foundation for the next phase of inquiry.
Despite these advances, the findings also reveal a persistent gap between automation capability and the frameworks guiding its deployment. While cybersecurity teams demonstrate readiness for AI-driven responses, existing frameworks such as NIST and SANS appear static, designed for pre-AI environments that lack adaptive feedback, ethical calibration, and real-time intelligence integration. The tension between technological evolution and framework rigidity underscores a critical misalignment between operational realities and governance mechanisms. This emerging gap raises essential questions about whether legacy frameworks can evolve to accommodate AI’s dynamic nature or whether entirely new structures must be developed to govern decision autonomy, accountability, and resilience in machine-led security environments.
Future work will build directly on the empirical momentum of this study by shifting focus from operational adoption to structural adequacy and will seek to evaluate whether the frameworks that currently underpin organizational cybersecurity strategies possess the flexibility, scalability, and ethical grounding required for intelligent and sustainable incident response. In doing so, this work transitions the research from validating practitioner behavior to critically assessing the governance models that must evolve to sustain trust, adaptability, and resilience in the era of AI-augmented incident response.
6.5. Interpretation of Survey Findings and Implications for Framework Modernization
The responses outlined in
Table 5 reflect a strong practitioner-driven mandate for rethinking current incident response paradigms. A significant portion of cybersecurity professionals surveyed do not believe that existing automation tools are sufficient to keep pace with AI-enabled threats, nor do they trust unregulated autonomy without safeguards. These sentiments illustrate a pressing need for evolving traditional frameworks to include components that better handle uncertainty, accountability, and modular integration. Furthermore, the expressed concerns around false positives, regulatory gaps, and decision authority highlight the inadequacy of static models when applied to dynamic and high-stakes AI scenarios.
Equally important is the insight that most respondents do not view current incident response playbooks as obsolete but instead seek a more nuanced, complementary architecture. This supports the idea that modernization should not be about discarding what works, but about augmenting existing frameworks with more intelligent, scalable, and ethically aware capabilities. The high level of agreement on the need for new classifications or taxonomies of automation tools underscores the urgency of creating more refined structures that reflect the layered nature of AI involvement in cybersecurity. The selection of survey items in
Table 5 represents practitioner sentiment regarding automation, trust, oversight, and evolving incident response needs. The responses serve as empirical justification for further exploration of modernized frameworks that reflect emerging AI-driven realities. These empirical findings create a logical foundation for exploring new directions in framework design, as will be presented in future work. This discussion draws upon the aggregate practitioner responses presented in
Table 5, highlighting how survey-derived evidence informs the rationale for evolving incident response frameworks to align with AI-driven operational realities.