Even when an organization invests in incident response plans, security tooling, and skilled technical teams, a serious cyberattack can still expose weak coordination. A new report based on a large survey suggests that many organizations are not prepared to execute their response effectively when time is critical—and when multiple departments must move together.
According to The State of Incident Response Readiness 2026, 73% of respondents say they would not be “fully ready” if a significant cybersecurity attack happened tomorrow. The survey polled 600 senior IT security decision makers during January and February 2026, highlighting a recurring mismatch between capability and execution under pressure.
Why incident response readiness still falls short
Most organizations can point to parts of an incident response program: containment procedures, detection tooling, and technical expertise. However, the research emphasizes that modern incident response goes beyond stopping malware or isolating systems.
A mature response also needs coordinated executive crisis management, legal and regulatory involvement, stakeholder communication, enterprise-wide investigation, remediation, recovery, and post-incident monitoring. The problem is that many organizations cannot reliably connect these pieces into one working process during a live event.
Less than 40% of respondents describe key incident response elements as “highly effective,” including documented plans, tabletop exercises, threat hunting, digital forensics, and 24/7 monitoring. In other words, the building blocks exist—but their combined performance under real pressure is not assured.
Organizations expect coordination to be difficult
One of the clearest signals in the report is the expected friction between internal stakeholders. The survey found that 90% of organizations anticipate difficulty coordinating the right groups during a significant incident.
That expectation matters because incident response is not only a technical challenge. Legal teams, communications teams, security operations, IT leadership, and executives often need to agree quickly on actions, messaging, and escalation. When alignment is missing in advance, delays can compound.
In fact, 75% of respondents agree that uncertainty or delays around when legal and communications teams must participate slow down decision-making during cyber incidents. Even more broadly, 89% cite limited executive or board involvement in incident response readiness and decision-making.
The report describes a pattern that can play out during a live attack:
- Technical teams investigate and contain the intrusion
- Executives require updates before approving major actions
- Legal and communications teams get pulled in later than expected
- Disclosure, customer messaging, and escalation decisions lag
- Response teams lose time when containment must be fast
When ownership is unclear, teams can end up spending critical minutes clarifying authority, briefing stakeholders, and waiting for approvals—rather than executing a rehearsed plan.
Visibility gaps increase the risk of repeat incidents
Coordination is only one side of the readiness problem. The report also flags a technical visibility challenge that can turn a “contained” incident into a repeat incident.
Seventy-eight percent of respondents agree that blind spots in their environment create persistent attacker access and increase the likelihood of incidents occurring again. These blind spots can span a wide range of environments, including on-premises infrastructure, public cloud, endpoints, SaaS platforms, identity systems, and—where applicable—operational technology environments.
Without reliable visibility, responders may struggle to answer essential questions, such as: Where did the attacker gain initial access? Which systems were accessed? Did the adversary move laterally? Were privileged accounts compromised? Was malware removed, and can the attacker return after recovery?
The risk is straightforward: if defenders can only confirm part of the activity, they may contain one phase while attacker access remains elsewhere.
OT and ICS exposure adds business and safety risk
Beyond IT systems, the report highlights concerns about attackers moving into operational technology (OT) or industrial control system (ICS) environments. 84% of organizations are concerned about that cross-environment movement.
This concern is especially relevant for sectors such as manufacturing, energy, healthcare, transportation, and critical infrastructure. In these environments, a cyber incident can affect physical operations, not just data.
If attackers move from IT into OT/ICS, the impact can extend to production disruption, safety considerations, service delivery challenges, and longer recovery timelines. The report suggests that organizations recognize the exposure, but many still lack the unified visibility needed to detect and stop cross-environment movement quickly.
Cyberattacks are already happening—and causing damage
The report does not treat cyber incidents as a hypothetical risk. It states that attacks are already recurring business events for many organizations.
In the past 12 months, 76% of respondents experienced at least one cyberattack, and 32% experienced more than one. Among organizations that were hit, impacts included operational shutdowns, data loss, reputational harm, customer loss, lost revenue, and disruption to executives.
The findings vary by sector. For example, retail organizations reported operational shutdowns and lost revenue or profit more frequently. Manufacturing and financial services organizations were more likely to report data loss. Crypto and decentralized finance organizations reported the highest incidence of attacks. Private healthcare organizations expressed particular concern about legal and communications delays.
Regional patterns also appeared. North America reported the highest cyberattack incidence. APAC respondents were most likely to report data loss, reputational damage, and customer loss. Europe reported fewer incidents overall, but when incidents occurred, they were more likely to result in lost revenue or profit.
What organizations fear next: ransomware and cloud attacks
When looking forward, respondents identified a range of threats that could cause serious financial, operational, or reputational disruption. Ransomware ranked as the top concern, with cloud environment attacks close behind.
However, the report emphasizes that incident response readiness cannot focus on a single dominant threat. Organizations are preparing for a crowded landscape that includes cloud compromise, identity abuse, third-party risk, AI-enabled threats, ransomware, and attacks that move across hybrid environments.
This matters because readiness needs to handle multiple attack paths—not just one scenario rehearsed in a plan.
AI adoption is rising, but it won’t fix readiness on its own
The survey also tracks the growing use of AI and machine learning in security operations. Nearly one-third of organizations report extensive AI use across most or all threat detection and incident response activities, up from 25% the previous year. By 2027, 63% expect AI to be embedded across these activities.
The report suggests that AI can strengthen incident response when integrated into mature workflows. Organizations using moderate or extensive AI were more likely to rate incident response components as effective compared with organizations using AI in limited ways.
At the same time, the message is clear: AI should not be treated as a substitute for governance, visibility, and disciplined execution. Even if AI accelerates triage, threat hunting, or investigations, it cannot resolve unclear decision rights, fragmented stakeholder coordination, or incomplete environmental visibility by itself.
Reconsidering internal and external response support
Another notable finding is that organizations are re-evaluating how they use external incident response support and managed detection and response relationships. Many respondents expect to switch providers when current contracts end.
Key drivers include a need for more proactive readiness support, better coverage across IT, OT, cloud, and hybrid environments, stronger expertise for complex incidents, improved visibility beyond a single technology ecosystem, and faster assistance during high-pressure investigations.
The report also highlights concerns about overreliance on narrow technology ecosystems. If response teams are limited to one platform or toolset, investigation and containment may be constrained by what that system can detect, access, or support.
Organizations may benefit from assessing whether their internal teams and external partners can operate across security tools, cloud platforms, identity systems, SaaS applications, and OT environments.
How to strengthen incident response readiness
If readiness is an ongoing discipline, not an annual checkbox, organizations can reduce the chance of delays and breakdowns. The report points to several practical steps.
1) Define decision rights before an incident
Security teams, executives, legal, communications, compliance, and business leaders should agree on roles in advance. Escalation paths, approval thresholds, and communication responsibilities should be documented and rehearsed.
2) Test cross-functional coordination with realistic scenarios
Tabletop exercises should involve both technical and non-technical stakeholders. These sessions help uncover where decisions slow down, where authority is unclear, and where response plans do not match real business dependencies.
3) Validate visibility across critical environments
Organizations should evaluate whether they can investigate activity across endpoints, identity systems, cloud platforms, SaaS applications, on-premises infrastructure, and relevant OT environments. Visibility testing can include threat hunting, attack simulation, red team assessments, or purple team engagements.
4) Use AI to support, not replace, response execution
AI and automation can accelerate alert enrichment, triage, investigation, and threat hunting. Still, embed those capabilities into defined workflows with human oversight, clear escalation criteria, and tested response procedures.
5) Assess internal capacity and external support options
Organizations should decide which response functions they can handle internally and where outside expertise is needed. If external providers are used, evaluate their incident experience, response speed, technical depth, ability to work across environments, communication practices, and support for post-incident improvements.
The bottom line
The research paints a clear picture: organizations are being attacked, yet many do not feel confident that their incident response readiness will hold under pressure. The challenge is no longer only creating a plan or purchasing tools.
Readiness depends on how well teams, technologies, executives, legal stakeholders, communications groups, and business operations work together during a real incident. As attackers move faster across cloud, IT, identity, SaaS, and OT environments, incident response readiness needs to be continuously strengthened—because the cost of delays can show up in systems affected, revenue, reputation, and trust.
Source: https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html
