Surprisingly Useful AI Article Enhancements
Almost three quarters of senior cyber security decision makers say their organisation would not be fully ready if a significant cyber attack hit tomorrow, according to a global survey of 600 IT security leaders.
The findings come from Sygnia’s 2026 CISO Survey: The State of Incident Response Readiness, which paints a picture of widespread unpreparedness despite near-universal adoption of formal incident response plans.
Some 73 per cent of respondents indicated their organisation would not be fully ready to withstand a significant cyber attack without disruption – even though 99 per cent have a documented Incident Response (IR) plan in place.
The disconnect between planning and execution is stark. Fewer than 40 per cent of respondents described any individual IR component as “highly effective,” suggesting the tools and processes exist on paper but fall apart under pressure.
Attacks are already landing
The urgency is not theoretical. More than three quarters (76 per cent) of organisations surveyed experienced at least one cyber attack in the past 12 months, with almost a third (32 per cent) hit more than once.
The consequences were severe: 47 per cent reported operational shutdowns, 41 per cent suffered data loss, 41 per cent experienced reputational damage and 40 per cent lost revenue.
Crypto and decentralised finance firms were the most frequently targeted sector at 83 per cent, followed by retail (79 per cent) and manufacturing (76 per cent).
Coordination breakdowns are the core problem
The survey points to organisational friction – not a lack of technology – as the primary obstacle to effective incident response.
A striking 90 per cent of respondents anticipate they would experience difficulty coordinating stakeholders in the event of a significant incident. Meanwhile, 89 per cent cited limited executive or board involvement in IR readiness and decision-making as a challenge.
Three quarters (75 per cent) agreed that delays and uncertainty around legal and communications team involvement slow down decision-making during cyber incidents.
“Incident response must be owned at the security, operational and executive levels, with defined decision-making roles, pre-agreed escalation pathways and regular board-level rehearsal,” Guy Segal, CEO of Sygnia, commented.
“This report puts a spotlight on a troubling reality in that despite most organisations having an Incident Response strategy in place, there is a clear lack of confidence in both the IR playbook itself as well as organisations’ ability to execute in a high-pressure real-world scenario.”
The executive gap
The problem escalates upward. When executive engagement is lacking, security teams spend time re-briefing leadership for approvals instead of taking action – risking longer response times and greater operational disruption when clarity and authority are needed most.
The survey found that when ownership and decision rights are unclear, technical progress and executive decision-making fall out of sync. Evidence accumulates while approvals and disclosures lag, turning incident response into a reactive cycle.
One Senior IT Decision Maker in the insurance sector in the UK told researchers: “A priority for us is to establish clearer integration and communication protocols between our IR team and non-technical business units.”
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
Sector and regional fault lines
Retail emerged as the sector least likely to consider itself ready for a serious cyber attack, followed closely by crypto and decentralised finance.
In retail, tabletop testing (29 per cent), digital forensics (31 per cent) and documented plans (32 per cent) were all the least likely to be rated as highly effective. Crypto and decentralised finance showed under-institutionalised IR across the board, with only 17 to 28 per cent rating any component as highly effective.
For private healthcare, where incidents carry heightened regulatory and reputational stakes, 86 per cent agreed that delays around legal and communications involvement slow decision-making – the highest agreement of any sector.
Regionally, APAC was the most likely to report being unprepared at 85 per cent, compared with 75 per cent in North America and 67 per cent in Europe.
APAC respondents were also the least likely to rate their documented IR plan (26 per cent), tabletop testing (27 per cent), threat hunting (29 per cent) and digital forensics (29 per cent) as highly effective.
Blind spots create repeat exposure
The survey also exposed serious visibility gaps. Some 78 per cent of respondents acknowledged that blind spots in their environment risk persistent attacker access and increase the likelihood of repeat incidents.
Visibility gaps were reported across public cloud (90 per cent), on-premises infrastructure (89 per cent), endpoints (89 per cent), OT/ICS environments (89 per cent) and SaaS platforms (89 per cent).
The stakes are particularly high when threats cross from IT into operational technology environments. Some 84 per cent of respondents expressed concern about attackers pivoting from corporate IT systems into OT/ICS environments.
When activity cannot be reliably detected and validated, threats can move from IT into operational systems before teams can isolate them, magnifying disruption, extending recovery time and compounding financial cost.
Ransomware leads threat concerns
Looking ahead, ransomware remains the leading concern among respondents at 46 per cent, closely followed by cloud environment attacks at 44 per cent.
But the broader picture shows a crowded threat landscape: email compromise and data theft or espionage both registered at 37 per cent, credential and identity compromise at 37 per cent, supply chain compromise at 35 per cent, insider threats at 31 per cent and financial fraud at 29 per cent.
“With AI widening the attack surface, reducing time from initial compromise to impact and expanding breach exposure time, today’s cyber threat landscape demands that organisations be in a continuous state of preparedness,” Segal added.
“Attackers are innovating, scaling and finding new ways to infiltrate, disrupt and extort organisations of all sorts and at all times.”
AI adoption accelerating but not a silver bullet
Almost a third of organisations now report extensive AI use across most or all threat detection and IR activities, up from 25 per cent last year. By 2027, 63 per cent anticipate AI will be embedded across their threat detection and IR activities.
But the survey suggests AI delivers the most value when it strengthens IR foundations rather than replacing them. Organisations with moderate or extensive AI use are more likely to rate their IR elements – including documented plans, 24/7 monitoring and digital forensics – as effective compared to those using AI in a limited way.
For instance, among organisations with extensive AI use, 88 per cent rated their documented IR plan as effective, compared with 75 per cent among those with limited AI use. The gap was even wider for continuous threat hunting: 84 per cent for extensive AI users versus 61 per cent for limited users.
This suggests IR readiness improves when AI is embedded into workflows, not when teams treat automation as a substitute for human judgement.
However, Sygnia warned that the pace of AI adoption often outstrips consideration of security implications, making AI a new and expanding attack surface. Effective AI risk management requires a structured approach spanning governance, regulatory compliance, security oversight, secure adoption strategies and ongoing tool lifecycle management.
Investment is flowing, but so is provider churn
Planned investment over the next 12 months spans the IR stack, led by continuous threat monitoring (85 per cent), 24/7 monitoring or MDR coverage (81 per cent), digital forensics (79 per cent) and tabletop or simulation exercises (75 per cent).
But organisations are also rethinking who they rely on. Some 65 per cent indicated they are likely to switch their IR provider at the conclusion of their current contract.
The top reasons for switching include a desire for more proactive readiness support (50 per cent), broader IT/OT or cloud coverage (48 per cent) and deeper expertise in complex or large-scale incidents (47 per cent).
This churn is underpinned by growing concern about vendor lock-in. Some 79 per cent agreed that relying on IR providers that are not vendor-agnostic could leave critical risks unaddressed.
Retail and private healthcare are the sectors most likely to consider switching providers, while concern about vendor lock-in is strongest in retail and financial services.
What needs to change
Sygnia’s report outlines several practical steps for organisations looking to close the gap between IR planning and execution.
The firm recommends formalising cross-functional governance and executive ownership through structured IR retainers, executive tabletop exercises and clear escalation authority.
It also calls for closing visibility gaps across IT, cloud, SaaS and OT environments through cyber posture assessments, red and purple team engagements and enterprise-scale investigation platforms.
Organisations should treat AI as an accelerator rather than a standalone maturity signal, embedding it into structured workflows that support threat hunting, triage and investigation at scale.
“Strengthening detection and response capabilities alone won’t resolve the visibility and coordination breakdowns we’re seeing stall decision-making and containment,” Segal warned.
“Organisations should consider revisiting their approach on a regular basis to ensure they have a cross-functional, proactive team in place with visibility across IT/OT and cloud environments and deep expertise in complex incidents.”
The survey was conducted by independent research firm Vanson Bourne in January and February 2026 across the USA, Canada, Mexico, the UK, France, Germany, BeNeLux, Australia and Singapore. Respondents represented organisations with 1,000 or more employees and at least US$250 million in global annual revenue.
Last Updated on April 13, 2026 by Nick Ross



