Report by ManageEngine
The psychology of being breached
Key Findings
80% of US and Canadian IT and cybersecurity leaders say heightened attention to cybersecurity lasts only one to six months after an incident.
84% of US and Canadian IT and cybersecurity leaders say employees are likely to report a cybersecurity mistake immediately.
83% of US and Canadian IT and cybersecurity leaders say fear of consequences influences how cybersecurity incidents are handled.
55% of US and Canadian IT and cybersecurity leaders say AI-enabled security tools have made their organization more willing to accept cyber risk.
24% of US and Canadian IT and cybersecurity leaders say AI has introduced new risks requiring significant changes to their cybersecurity strategy.
81% of US and Canadian IT and cybersecurity leaders say AI has made cybersecurity decision-making easier overall.
33% of US and Canadian IT and cybersecurity leaders believe a major cyber incident is inevitable regardless of their defenses.
26% of US and Canadian IT and cybersecurity leaders say they accept risks they consider manageable.
23% of US and Canadian IT and cybersecurity leaders say known risks often remain unresolved until an incident or audit creates urgency.
25% of US and Canadian IT and cybersecurity leaders say unclear ownership can delay containment, remediation, or other critical actions.
8% of US and Canadian IT and cybersecurity leaders say cybersecurity becomes a permanent priority after an incident.
91% of US and Canadian IT and cybersecurity leaders are confident in their organization's cybersecurity posture.
59% of US and Canadian IT and cybersecurity leaders say business priorities always or often cause security initiatives to be postponed or downgraded.
Among organizations using AI in cybersecurity, 67% always or often act on AI-generated recommendations without additional verification.
Among organizations using AI in cybersecurity, 29% always act on AI-generated recommendations without additional verification.
44% of US and Canadian IT and cybersecurity leaders report that their organization made no structural or strategic change following their most recent incident.