Accountancy firms are investing millions into AI, but a report by software company Fastly indicates that security systems have not kept pace, leaving them vulnerable to costly cyberattacks. The report, shared with City AM, found that businesses identifying as AI-first, meaning they integrated AI into core processes from the outset, took an average of 80 days longer to recover from security incidents compared to other organisations.
The data also revealed that nearly half of the surveyed AI-first businesses stated AI was directly exploited in their most recent security incident. This contrasts with seven per cent of non-AI-first organisations. These businesses also contended with an average of 54 known security breaches annually.
Marshall Erwin, Fastly's chief information security officer, noted that cyber criminals target accounting firms due to their privileged access to sensitive financial information. A significant issue identified was that over half (53 per cent) of security teams admitted to lacking the specialised AI expertise needed to combat new threats. Even approved AI tools can create vulnerabilities because they often receive extensive automated permissions, becoming "privileged parts of your infrastructure and that's what created the risk," Erwin stated.
The report also highlighted that shadow AI, which refers to unauthorised AI tools adopted by employees without IT approval, was 31 per cent higher among employees at AI-first organisations, impacting business profitability. This situation arises as the accountancy sector rapidly incorporates external capital, such as private equity, to invest in technological upgrades including AI integration.