Nearly Three in Four Companies Admit They Aren't Ready for a Serious Cyberattack

A survey of 600 senior IT security leaders finds most have the tools but lack the coordination, visibility and boardroom alignment to survive a real incident.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • 73% of organisations say they are not fully prepared for a major cyberattack, according to research published in early 2026.
  • The finding comes from The State of Incident Response Readiness 2026, a Vanson Bourne survey of 600 senior IT security decision makers conducted in January 2026.
  • Most respondents already have incident response plans, security tools and technical staff in place.
  • The gap sits in coordination between teams, visibility across systems, and alignment with executives, not in technology spending.
  • Rehearsal and clear ownership, not more products, are the main fix the research points to.

Most companies have the kit. The plans exist. The people are there. And yet, 73% of those companies don't think they could handle a real cyberattack.

That's the uncomfortable message from The State of Incident Response Readiness 2026, a study by market research firm Vanson Bourne based on 600 senior IT security decision makers surveyed in January 2026. The report was first covered by The Hacker News.

What's interesting is what the gap is not. It isn't firewalls, endpoint tools or written playbooks. Nearly every organisation surveyed had those. What they lacked was the human machinery around them.

What does "not fully ready" actually mean?

It means that when an attack hits, the response falls apart in the seams between teams. Security staff see the alert. Legal, communications and finance find out later, sometimes much later. Decisions that should take minutes take hours.

Three themes run through the survey answers.

First, coordination. Incident response, the set of steps a company takes when it discovers a breach, tends to be owned by the security team alone. When lawyers, PR and customer support only get pulled in mid-crisis, the response slows to a crawl.

Second, visibility. Many respondents said they can't see across all their systems in one place, especially where cloud services, contractors or office networks meet. If you can't see the whole picture, you can't tell how far an intruder has got.

Third, executive alignment. Boards approve budgets but often haven't walked through a realistic breach scenario. When the call comes at 2am, the CEO is meeting the incident for the first time. Our story on how CISOs are quietly absorbing responsibility for business resilience, published 27 July 2026, found exactly this tension playing out in practice.

Why do plans on paper keep failing?

Because a plan that's never been rehearsed is a document, not a capability. Most companies in the survey had written incident response plans. Far fewer had tested them end to end in the last year with the executives who'd actually run the response.

Think of it like a fire drill. Everyone knows there's a fire exit. Nobody knows how long it takes to clear the building until they try.

Survey detail Figure
Respondents not fully ready 73%
Senior IT security leaders surveyed 600
Fieldwork January 2026
Research firm Vanson Bourne

Should you worry?

If you're a customer or employee of a large company, this research is a reminder that breach notification, the legal duty to tell you your data was exposed, often lands late because the company itself was slow to piece events together. Regulators including the US Federal Trade Commission, the UK Information Commissioner's Office and Australia's Office of the Australian Information Commissioner have pushed for faster, clearer notices in recent years.

For individuals, the practical steps don't change. Use a password manager. Turn on two-factor authentication, the second code or prompt on top of your password, wherever it's offered. Treat unexpected "security" emails asking you to log in with suspicion, even when they follow a real breach.

For the companies in that 73%, the fix is less glamorous than a new product. Rehearse. Bring the executives into the room. Write down who calls the regulator, who calls the customers, who decides when systems come back online. Then do it again next quarter.

The uncomfortable truth this survey surfaces is that preparedness gaps aren't usually a budget problem. They're a rehearsal problem, and rehearsals are free.

© 2026 Threat Vectr