Cybersecurity attention fades within months after an incident
The 91% of organizations believe they have an adequate cybersecurity posture despite having already suffered a breach, according to a new ManageEngine survey conducted on 700 IT and cybersecurity leaders in the USA and Canada. Only 8% state that cybersecurity becomes a permanent priority after an incident.
Quick Response
Organizations often abandon enhanced cybersecurity measures after an incident within 1-6 months. 45% do not make significant structural changes, while 33% limit themselves to targeted corrections. 20% identify business priorities as the main factor delaying security initiatives.
A confidence that surpasses prevention
A third of respondents believe that a serious incident is inevitable regardless of the defenses implemented. 34% accept risks they consider manageable, maintaining known gaps until an audit or a real incident. Only a minority consistently pays attention to security throughout the year, outside the phase following an incident.
The urgency fades quickly
After an incident, attention to cybersecurity temporarily increases: procedures are discussed, technical solutions such as patches, access reviews, and backup improvements are implemented. However, 80% of respondents say this increased attention lasts only 1-6 months. 45% of organizations maintain existing structures and strategies without significant changes.
Business priorities hinder security
Competitive needs often delay or degrade security initiatives. 20% of respondents indicate this as the main factor behind their last incident. This trend reflects a reactive rather than proactive mindset in managing cybersecurity.
Fear conditions incident management
83% of interviewees admit that fear of consequences influences incident management after reporting. Many describe the organization's response as focused on blame. This climate of fear creates an environment that many employees prefer to avoid, hindering open and honest communication.
Security responsibility remains ambiguous
19% of respondents are unsure whether security, IT, or business teams should be responsible for a given failure. This lack of clarity has tangible consequences: delays in remediation, operational disruptions, and a greater risk of data exposure before a gap is closed.
AI recommendations are often not verified
The use of AI is widespread among these organizations, employed for incident response automation, threat intelligence, penetration testing, and vulnerability scanning. 67% of organizations using AI in cybersecurity often or always act on its recommendations without further verification.
The risks of relying on AI
According to Dr. Erik Huffman, a cyberpsychology researcher, Large Language Models (LLM) are frequent targets for attackers due to the level of trust people place in the information received from AI systems. "We need to move from 'trust but verify' to 'verify, then trust'", says Huffman.
NIS2 compliance and cyber insurance
These results highlight the need for a more structured approach to cybersecurity, aligned with NIS2 compliance needs. Organizations with a more effective incident response could benefit from lower insurance premiums for their cyber insurance, thanks to better risk management.
The need for an effective incident response
Organizations that truly learn from incidents are not just those that respond quickly. They are those that maintain visibility after the crisis, make risk decisions explicit, and transform temporary urgency into lasting discipline. This approach is crucial for building a robust and sustainable security culture.
The importance of a SOC as a Service
Given the rapid decline in cybersecurity attention, many organizations could benefit from a SOC as a Service or an MDR service. These external services can provide continuous vigilance and specialized skills that many organizations struggle to maintain internally after the acute phase of an incident.
The challenge of DORA compliance
In an increasingly stringent regulatory context, such as the DORA regulation, these trends represent a significant challenge. Digital operational resilience requires a constant commitment to risk management and incident preparedness, not just a reactive response.
The cybersecurity market and economic impact
These data emerge in a market context where global spending on cybersecurity is expected to exceed $200 billion by 2025, according to Gartner. A growth driven precisely by the need to address increasingly sophisticated incidents. However, as highlighted by the survey, the effectiveness of investments remains compromised by organizations' reactive attitude.
NIS2 compliance and cyber insurance: costs and opportunities
NIS2 compliance requires organizations to demonstrate proactive risk management. According to a recent Aon analysis, companies with structured cybersecurity programs can reduce the cost of cyber insurance by 20-30%. A significant advantage considering that the average premium for cyber risk policies in Italy increased by 40% in 2023.
The challenge of risk management in the financial sector
Financial institutions, subject to the DORA regulation, must face particularly stringent requirements. According to a Deloitte report, 58% of European banks have already suffered a supply chain-related incident in the last 12 months. Digital operational resilience requires not only investments in technology but also a complete review of processes.
MDR and SOC as a Service: solutions for continuity
In this scenario, Managed Detection and Response (MDR) services represent a strategic solution. According to a Forrester analysis, organizations that implement MDR reduce the average time to detect an incident from 200 to 20 days. A critical advantage in sectors such as healthcare, where every minute of downtime can cost thousands of euros.
Impact on small and medium enterprises
SMEs, often with limited resources, are particularly vulnerable. An ENISA report estimates that 60% of small businesses close within six months of a serious incident. The adoption of Data Loss Prevention (DLP) and enterprise backup solutions could significantly reduce this risk, but adoption remains low.
Crypto taxation and fraud risk
The cryptocurrency sector, subject to complex AML compliance obligations, is particularly exposed. According to a Chainalysis analysis, 2023 saw a 150% increase in exchange-related fraud. Institutional management of crypto requires not only secure custody but also accurate tax planning to avoid sanctions.
The evolution of threats and the importance of penetration testing
Zero-day vulnerabilities are increasing by 12% annually, according to a Mandiant report. Regular execution of penetration tests and vulnerability assessments is therefore crucial. A Ponemon Institute analysis shows that organizations conducting quarterly tests experience 40% fewer incidents.
ISO 27001 certification as a reference standard
ISO 27001 certification has become a key requirement for business partnerships. According to an ISACA survey, 78% of corporate clients prefer to work with certified suppliers. An investment that, despite the initial cost, pays off in terms of market access and business opportunities.
Future forecasts: towards proactive cybersecurity
The future of cybersecurity requires a cultural change. According to Gartner, by 2027 50% of large organizations will adopt zero trust architectures. This transition, supported by identity access management (IAM) solutions, could finally break the cycle of reactivity that characterizes the sector today.
Disaster Recovery as a Service: a strategic option
DRaaS is emerging as a key solution for operational continuity. An IDC analysis predicts that the market will grow by 35% annually until 2028. In critical sectors such as energy and transportation, this solution could make the difference between a managed incident and a catastrophic crisis.
Conclusions: the need for structural change
The ManageEngine survey data highlights a worrying reality: despite investments in cybersecurity, organizations continue to fall into the same reactive trap. The key to reversing this trend lies in the adoption of structured frameworks, such as the DORA regulation and ISO 27001 certification, and the integration of advanced solutions such as MDR and SOC as a Service. Without a radical change, the gap between threats and defenses will continue to widen, with potentially devastating consequences for organizations of all sizes and sectors.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the misuse of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.