Report by Kroll

Bridging the Cyber Resiliency Gap: Why Aligning Cybersecurity Priorities Is Critical for Business Resilience

18 FINDINGSPublished Mar 18, 2026
View Original Report →

Key Findings

72% of organizations believe they can respond to an incident within 1–24 hours.

Incident ResponseOperational Readiness

51% of organizations cite differing risk tolerance as the leading cause of gaps in threat prioritization.

Risk ToleranceThreat Prioritization

48% of businesses say the CEO now makes the final decision on cyber budgets.

Budget

55% of organizations are cutting or not increasing investment in red and purple teaming.

Security TestingProactive DefenseBudgetInvestmentRed Teaming

94% of organizations view cybersecurity as a primary business risk.

CybersecurityBusiness Risk

59% of organizations are increasing spending on cloud and third-party security.

Cloud SecurityThird-Party SecurityBudgetSpendingInvestment

Organizations face an average annual recovery cost and downtime of $2.2 million from cyber incidents.

Incident Recovery CostDowntime Cost

Only 10% of organizations have achieved very high cyber maturity.

Cyber MaturityRisk Management

43% of organizations report limited cyber literacy among executives.

Executive Cyber Literacy

39% of organizations experience phishing attacks.

Phishing

80% of organizations increased cybersecurity budgets in 2026.

Budget

99% of organizations have an incident response plan.

Incident Response Plan

Organizations with higher cyber maturity experience 50% less financial impact per dollar of revenue when cyber incidents occur.

Cyber MaturityFinancial Impact

52% of organizations are cutting or not increasing investment in identity access management controls and zero-trust architecture.

BudgetInvestmentIdentity Access Management ControlsZero-Trust Architecture

3% of organizations update incident response plans only after a cyber incident.

Incident Response PlanOperational Readiness

72% of organizations report frequent misalignment between cybersecurity efforts and broader business priorities.

CybersecurityBusiness Priorities

36% of organizations acknowledge gaps in how threats are prioritized.

Threat PrioritizationRisk ManagementThreat Prioritization Gaps

28% of organizations experience business email compromise.

Business Email Compromise