Skip to content
TECH CEO Daily

Board security briefing: PwC readiness gap, $1.4B privacy settlements and SOC jobs

Three reports published October 1 to October 5 give directors hard numbers on AI risk, privacy litigation and the security talent pipeline.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1PwC found only 21% of leaders are implementing quantum-resistant security measures.
  • 2Privado AI projects US companies are on track to pay more than $1.4 billion in privacy settlements in 2026, up 36%.
  • 3In a Swimlane survey, 47% of security workers said SOC analyst careers will become harder to obtain.

The news

Three studies published between October 1 and October 5, 2026 give boards a sharper board cybersecurity briefing: PwC on weak AI and quantum readiness, Privado AI on rising US privacy settlements, and Swimlane on how AI is reshaping security operations center (SOC) work.

PwC's 2027 Global Digital Trust Insights report, covered by SecurityWeek on October 1, surveyed nearly 4,000 business and technology leaders in more than 70 countries. Only 21% said they are implementing quantum-resistant security measures, meaning encryption designed to survive future quantum computers. Just 22% said they would let fully autonomous AI run cyber defense without human approval.

PwC found attacks on AI systems themselves are the threat organizations feel least prepared for. According to SecurityWeek's summary, 53% said they were unprepared for an autonomous botnet compromise, 52% for adversarial attacks and 52% for data poisoning, where attackers corrupt the data a model learns from. Accountability is scattered: 29% put AI accountability with the CIO or CTO, 26% with a dedicated AI leader, 17% with the CISO and 11% across several departments.

Money is moving anyway. In the PwC survey, 84% of security and finance leaders expect budget increases, and 58% rank AI as their top cyber budget priority. Morgan Adamski, PwC's cyber, data and technology risk leader, said the fundamentals of cybersecurity have not changed.

On the legal side, Privado AI, a privacy software company, published research on October 5 projecting that US companies are on track to pay more than $1.4 billion in public privacy class action settlements in 2026, a 36% increase over 2025, PYMNTS reported. The analysis covered 116 public settlements. It found 53% of 2026 settlements involved the 1968 Federal Wiretap Act and 43% involved the 1967 California Invasion of Privacy Act, laws now used in claims that websites and mobile apps shared personal data without permission.

Swimlane, an agentic AI security company, surveyed 500 security workers in the United States and United Kingdom in August and September 2026, Cybersecurity Dive reported on October 1. Some 62% said AI was helping them build skills, but 47% predicted SOC analyst careers would become harder to obtain.

The numbers

Leaders implementing quantum-resistant security (PwC)
21%
Projected US privacy settlements in 2026 (Privado AI)
$1.4 billion
Increase vs. 2025 (Privado AI)
36%
Security workers who expect SOC careers to get harder to obtain (Swimlane)
47%
Leaders expecting cyber budget increases (PwC)
84%

Why CEOs should care

For boards, the PwC accountability split is the first question to raise. If AI risk sits with the CIO in one unit and with nobody in another, ask management to name a single owner for AI security, and to report how the company tests its models against data poisoning and prompt injection, which OWASP ranks as the top risk for large language model applications, according to SecurityWeek.

For general counsel and CFOs, the Privado AI numbers point to an old-law, new-tech problem. Privado CEO Vaibhav Antil said most companies facing litigation had a consent management platform in place and were less covered than they thought, as reported by PYMNTS. A practical step: ask for an audit of which pixels, chat widgets and session-replay tools fire on company websites before a visitor consents, and whether that matches the consent banner.

For CISOs and HR leaders, the Swimlane data raises a pipeline question. If AI absorbs much of the alert triage that once trained junior analysts, where will the next generation of senior responders come from? Ask what the plan is for apprenticeships, rotation programs or supervised investigation work that keeps entry-level staff learning.

The bigger picture

Taken together, the reports describe spending outpacing governance. Budgets are rising and AI is the top priority, yet few organizations are ready for attacks on AI itself, and legal exposure from routine web tracking keeps growing. Swimlane's report said analysts are increasingly responsible for validating evidence and making higher-impact decisions, which places more weight on experienced people at the same time that the entry ramp may narrow.

The Swimlane survey also showed a gap between leaders and practitioners: 74% of leaders reported extensive AI deployments versus 49% of practitioners, Cybersecurity Dive reported. Directors hearing only from leadership may get a rosier picture than staff on the floor.

What’s next

Boards heading into 2027 planning can ask management for three items: a named owner for AI security, a website tracking and consent audit, and a staffing plan for junior security roles. The PwC readiness figures, the 36% rise in settlements and the 47% career concern give each request a number to measure against.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

PwCPrivado AISwimlaneBoard governancePrivacy litigation

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.