What 200 CISOs and CTOs Reveal
At A Glance
- Increased service and workload deployments are now a leading driver of AI’s expanding attack surface, according to over half of security leaders surveyed.
- Vulnerabilities in underlying infrastructure is a top security concern, and CTOs are meaningfully more worried about it than CISOs.
- 100% of organizations agree their external attack surface is growing.
- Direct inputs that allow for potential prompt injection are a named concern for a large share of respondents.
Nobody hands a platform team a memo that says “please also become responsible for the company’s attack surface.” It just quietly happens, one shipped agent and one new internet-facing API at a time.
New survey data from 200 CISOs and CTOs confirms what platform teams are already sensing: every service you ship to move AI forward is also a service somebody now has to secure…and increasingly, that somebody is you.
NetFoundry commissioned Global Surveyz Research to survey 200 senior security and technology leaders, CISOs, CTOs, CAOs, and CIOs, at companies with 1,000 or more employees, across finance, healthcare, tech, retail, and industrial sectors, on how they’re navigating the security risks of AI deployment.
Why Does Shipping More AI Services Expand Your Attack Surface?
Deploying more services and workloads is one of the leading contributors to attack surface change cited by security leaders, right alongside the growing requirement for internet-facing APIs. Neither of these is optional if you’re actually building an AI platform. You can’t scale agentic AI without more services, more integrations, and more connections between environments that didn’t previously talk to each other.
That’s the uncomfortable part for platform teams: the very thing your roadmap is optimizing for, shipping more AI capability faster, is the same thing driving the number security leaders can’t stop watching. Every enclave, cloud, edge, and partner environment your services cross is a new connection, and every new connection is a new surface. The platform team isn’t causing a security problem by doing its job well; but doing the job well and expanding the attack surface have become the same activity.
Why Are Infrastructure Vulnerabilities Now a Platform Team Problem?
Vulnerabilities in underlying infrastructure, cloud, networking, and APIs rank as one of the top security concerns tied to AI deployments. And when you break that concern down by role, it isn’t security leadership driving it. CTOs are considerably more worried about it than CISOs, which is a real signal: the people building and maintaining infrastructure are seeing something up close that security teams, one layer removed from the code and the architecture, don’t feel yet.
Infrastructure vulnerability has traditionally been framed as a security team’s domain to flag and a platform team’s domain to fix. But this data suggests platform leads are increasingly the ones raising the flag in the first place.
How Fast Is Your Attack Surface Moving?
Every single organization surveyed agrees their external attack surface is growing, and the average projected increase is double digits over just the next 12 months. That figure only accounts for AI deployments already underway or planned, meaning it’s a floor, not a ceiling, for any platform team with an active roadmap. Layer in that a meaningful share of respondents already flag direct inputs (the kind that enable prompt injection) as a live concern, and the picture is less “emerging risk to watch” and more “current operating condition to build for.”
How to Ship AI Faster Without Expanding Your Attack Surface
The instinct here is usually to slow down: more reviews, more approvals, more friction between “built” and “shipped.” But that’s the wrong lever. The organizations handling this well aren’t shipping less, they’re changing what “exposed” means in the first place.
If every AI agent, MCP server, and workload gets its own verifiable identity and connects outbound-only, with no open inbound ports, adding another service doesn’t have to mean adding another discoverable target. That’s the model behind NetFoundry’s Identity-First Reachability™: the platform team keeps shipping, and the attack surface stops scaling with it.
If you’re the one accountable for what’s on the roadmap and what it’s exposing, the full survey breaks these findings down further by industry, role, and company size — useful context for how your build velocity compares to your peers’ risk tolerance.
Download the Full 2026 State of Secure AI Connectivity Report
Frequently Asked Questions
Why does shipping more AI services increase attack surface?
Each new AI service, agent, or workload typically requires new internet-facing APIs and new cross-environment connections, and each of those connections is a potential point of exposure. According to NetFoundry’s 2026 survey of 200 CISOs and CTOs, increased requirements for internet-facing APIs and workloads, along with more services deployed overall, are among the leading drivers of AI’s expanding attack surface.
Are platform teams responsible for AI security, or is that a security team’s job?
Increasingly, both. Our research found that CTOs, the people building and maintaining AI infrastructure, report higher concern about infrastructure vulnerabilities than CISOs do, suggesting platform and engineering teams are identifying and owning more of this risk directly rather than waiting for security review to catch it.
What is prompt injection?
Prompt injection is a technique where an attacker embeds malicious instructions in the inputs an AI model or agent processes, attempting to manipulate its behavior. It’s a named concern for a meaningful share of the security leaders we surveyed, and one of several reasons direct, unmanaged inputs to AI systems are considered a growing risk.
How can platform teams ship AI faster without increasing security risk?
The most effective approach isn’t slowing down deployment, it’s changing what “exposed” means. We do this through Identity-First Reachability™, which gives every AI agent, MCP server, and workload its own verifiable identity and eliminates open inbound ports, so new services don’t automatically become new discoverable attack surface.
