Cybersecurity Readiness Doesn't Match Confidence Levels

According to a report by ManageEngine, cybersecurity readiness doesn't match security leaders' cybersecurity confidence.
The report analyzed survey results from cybersecurity leaders whose organizations have experienced a cybersecurity incident or breach.
Additional report findings include:
- Confidence does not guarantee lasting focus: 91% of respondents are confident in their organization's cybersecurity posture, yet 8% say cybersecurity becomes a permanent priority after an incident.
- Post-incident urgency has a short shelf life: 80% say heightened attention to cybersecurity lasts one to six months after an incident.
- Business priorities regularly push security aside: 59% say business priorities always or often cause security initiatives to be postponed or downgraded.
- Fear impacts incident handling despite swift reporting: 84% say employees are likely to report a cybersecurity mistake immediately, while 83% say fear of consequences influences how cybersecurity incidents are handled.
- AI adoption is outpacing verification: Among organizations using AI in cybersecurity, 67% always or often act on AI-generated recommendations without additional verification, including 29% that always do so.
Experiencing an incident does not always lead to sustained vigilance. A third (33%) of respondents believe a major cyber incident is inevitable regardless of their defenses, 26% say they accept risks they consider manageable, and 23% say known risks often remain unresolved until an incident or audit creates urgency.
The response after an incident shows a similar pattern. Organizations commonly make immediate technical or operational fixes, but 44% made no structural or strategic change following their most recent incident.
Culture and accountability can also affect what happens once an incident is reported. Eighty-four percent of respondents say employees are likely to report a cybersecurity mistake immediately, while 83% say fear of consequences influences how cybersecurity incidents are handled. One-quarter (25%) say unclear ownership can delay containment, remediation, or other critical actions.
AI is now widely used in cybersecurity, but organizations are still working through how much oversight its recommendations require. Among organizations using AI in cybersecurity, two-thirds (67%) always or often act on AI-generated recommendations without additional verification, and 29% say they always do.
More than half (55%) say AI-enabled security tools have made their organization more willing to accept cyber risk. At the same time, 24% say AI has introduced new risks requiring significant changes to their cybersecurity strategy, while 81% say AI has made cybersecurity decision-making easier overall.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!




