73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
A recent study reveals that 73% of organizations aren't fully prepared to withstand a major cyberattack, despite having incident response plans and security tools. The core issue isn't simply having these capabilities, but rather the ability to execute them effectively, particularly due to coordination breakdowns between technical teams, executives, legal, communications, and business operations. Key challenges include a lack of executive involvement, delayed decision-making, poor visibility across environments (including OT/ICS), and a reliance on narrow technology ecosystems. Organizations are increasingly adopting AI, but it needs to be integrated into mature workflows, not replace fundamental readiness practices. To improve, companies should define decision rights proactively, test cross-functional coordination, validate visibility across environments, and treat incident response as an ongoing operational discipline.
A recent study, "The State of Incident Response Readiness 2026," conducted by Vanson Bourne for The Hacker News, reveals a significant gap between organizations’ incident response capabilities and their ability to effectively respond to a major cyberattack. The research, based on a survey of 600 senior IT security decision makers, indicates that 73% of organizations would not be ‘fully ready’ if a significant cybersecurity attack occurred tomorrow.
Despite possessing incident response plans, security tools, and technical teams, the study highlights that many organizations struggle to execute these capabilities effectively. The core issue isn’t simply having these resources, but rather the ability to coordinate a robust response across diverse teams and stakeholders.
The research reveals that cyberattacks are a recurring business risk, with 76% of organizations experiencing at least one attack in the past 12 months, and 32% experiencing more than one. Incident response has evolved beyond technical containment, now requiring executive crisis management, legal and regulatory coordination, stakeholder communications, enterprise-wide investigation, remediation, recovery, and post-incident monitoring.
However, many organizations are struggling to bring these elements together in a coordinated way. Fewer than 40% of respondents described key incident response components as ‘highly effective,’ including areas such as documented plans, tabletop exercises, threat hunting, digital forensics, and 24/7 monitoring. The problem isn’t just the existence of these capabilities; it’s the ability to work together when rapid decisions are needed.
Internal friction significantly impacts response efforts, with 90% of organizations expecting difficulty coordinating stakeholders during a major incident. This coordination challenge is particularly problematic when legal, communications, security, IT, and executive teams are not aligned before an incident begins. 75% of respondents agree that delays or uncertainty around legal and communications team involvement slow decision-making during cyber incidents. Furthermore, 89% cite limited executive or board involvement in incident response readiness and decision-making.
This creates a dangerous pattern during a live incident: technical teams investigate and contain the attack, executives require updates before approving major actions, legal and communications teams become involved late, disclosure, customer messaging, and escalation decisions lag, and response teams lose time when containment decisions need speed.
Lack of visibility exacerbates the risk of repeat incidents. 78% of respondents agree that blind spots in their environment create persistent attacker access and increase the risk of repeated incidents. These blind spots span on-premises infrastructure, public cloud environments, endpoints, SaaS platforms, identity systems, and operational technology (OT) environments. Without reliable visibility, responders cannot confidently answer essential questions, such as: where did the attacker enter? which systems were accessed? has the attacker moved laterally? are privileged accounts compromised? has malware or persistence been removed? could the attacker return after recovery?
Operational Technology (OT) and Industrial Control System (ICS) environments add significant business risk. 84% of organizations are concerned about attackers crossing from corporate IT systems into OT/ICS environments. This is particularly serious for sectors like manufacturing, energy, healthcare, and transportation, where cyber incidents can affect physical operations. If attackers move from IT into OT/ICS systems, the impact may extend beyond data theft or business disruption, affecting production, safety, service delivery, and recovery timelines.
Organizations are increasingly adopting AI, with nearly one-third reporting extensive AI use across most or all threat detection and incident response activities – up from 25% last year. By 2027, 63% expect AI to be embedded across these activities. However, AI should not be treated as a replacement for governance, visibility, and disciplined response execution. AI can accelerate triage, threat hunting, and investigation, but it cannot resolve unclear decision rights, fragmented stakeholder coordination, or incomplete visibility on its own.
Many organizations are reconsidering their external incident response and managed detection and response (MDR) relationships, expecting to switch providers at the end of their current contracts. Drivers include the need for more proactive readiness support, better coverage across IT, OT, cloud, and hybrid environments, stronger expertise in complex incidents, improved visibility beyond a single technology ecosystem, and faster support during high-pressure investigations. Overreliance on narrow technology ecosystems during incident response can also constrain investigation and containment.
Organizations should treat incident response readiness as an ongoing operational discipline. Key steps include defining decision rights proactively, testing cross-functional coordination through tabletop exercises, validating visibility across critical environments, and integrating AI into mature workflows with human oversight. Ultimately, the central lesson is that readiness depends on execution – plans, tools, and providers matter, but only when they are connected through tested processes, clear authority, and reliable visibility.
