Report by Kroll
Bridging the Cyber Resiliency Gap: Why Aligning Cybersecurity Priorities Is Critical for Business Resilience
Key Findings
72% of organizations believe they can respond to an incident within 1–24 hours.
51% of organizations cite differing risk tolerance as the leading cause of gaps in threat prioritization.
48% of businesses say the CEO now makes the final decision on cyber budgets.
55% of organizations are cutting or not increasing investment in red and purple teaming.
94% of organizations view cybersecurity as a primary business risk.
59% of organizations are increasing spending on cloud and third-party security.
Organizations face an average annual recovery cost and downtime of $2.2 million from cyber incidents.
Only 10% of organizations have achieved very high cyber maturity.
43% of organizations report limited cyber literacy among executives.
39% of organizations experience phishing attacks.
80% of organizations increased cybersecurity budgets in 2026.
99% of organizations have an incident response plan.
Organizations with higher cyber maturity experience 50% less financial impact per dollar of revenue when cyber incidents occur.
52% of organizations are cutting or not increasing investment in identity access management controls and zero-trust architecture.
3% of organizations update incident response plans only after a cyber incident.
72% of organizations report frequent misalignment between cybersecurity efforts and broader business priorities.
36% of organizations acknowledge gaps in how threats are prioritized.
28% of organizations experience business email compromise.