Despite implementing incident response plans and deploying various security tools, a significant number of organizations remain ill-equipped to handle major cyberattacks. Recent research indicates that 73% of organizations acknowledge they would not be fully prepared if a substantial cybersecurity incident occurred imminently.
This insight stems from a survey conducted by Vanson Bourne in early 2026, involving 600 senior IT security decision-makers. The findings underscore a critical disconnect between possessing incident response capabilities and effectively executing them under pressure.
Cyberattacks: A Persistent Threat
The survey reveals that cyberattacks are a recurring challenge for businesses. Over the past year, 76% of organizations experienced at least one cyberattack, with 32% facing multiple incidents. This prevalence highlights the pressing need for robust and coordinated incident response strategies.
Challenges in Incident Response Readiness
Effective incident response extends beyond technical containment to encompass executive crisis management, legal coordination, stakeholder communication, comprehensive investigation, remediation, recovery, and post-incident monitoring. However, many organizations struggle to integrate these components cohesively.
Less than 40% of respondents rated key incident response elements—such as documented plans, tabletop exercises, threat hunting, digital forensics, and continuous monitoring—as “highly effective.” This suggests that while these capabilities may exist, their practical application during crises is often lacking.
Coordination and Communication Hurdles
Internal coordination poses a significant challenge during cyber incidents. The report indicates that 90% of organizations anticipate difficulties in aligning stakeholders during a major attack. This misalignment is particularly evident when legal, communications, security, IT, and executive teams are not synchronized prior to an incident.
Furthermore, 75% of respondents agree that delays or uncertainties regarding the involvement of legal and communications teams hinder decision-making during cyber incidents. Additionally, 89% cite limited executive or board engagement in incident response readiness and decision-making processes.
Such coordination issues can lead to a reactive response cycle, where teams spend valuable time briefing stakeholders and awaiting approvals instead of executing a well-rehearsed plan.
Visibility Gaps and the Risk of Repeated Incidents
The survey also highlights a significant technical challenge: many organizations lack comprehensive visibility into their environments, increasing the risk of persistent attacker access and repeated incidents. Specifically, 78% of respondents acknowledge that blind spots within their infrastructure contribute to this vulnerability.
These blind spots can span various domains, including on-premises systems, cloud environments, endpoints, SaaS platforms, identity systems, and operational technology. Without clear visibility, responders may struggle to answer critical questions about the attack’s origin, affected systems, lateral movements, and potential compromise of privileged accounts.
Addressing these challenges requires organizations to move beyond merely having incident response plans and tools. They must focus on ensuring these components function cohesively under pressure, with clear coordination among all stakeholders. Enhancing visibility across all systems is also crucial to detect and mitigate threats effectively. By fostering a culture of preparedness and continuous improvement, organizations can better position themselves to withstand and recover from significant cyberattacks.