Nearly Three in Four Companies Admit They Aren't Ready for a Serious Cyberattack
A survey of 600 senior IT security leaders finds most have the tools but lack the coordination, visibility and boardroom alignment to survive a real incident.

Key points
- 73% of organisations say they are not fully prepared for a major cyberattack, according to research published in early 2026.
- The finding comes from The State of Incident Response Readiness 2026, a Vanson Bourne survey of 600 senior IT security decision makers conducted in January 2026.
- Most respondents already have incident response plans, security tools and technical staff in place.
- The gap sits in coordination between teams, visibility across systems, and alignment with executives, not in technology spending.
- The research points to rehearsal and clear ownership, not more products, as the main fix.
Most companies have the kit. They have the plans. They have the people. They still do not think they could handle a real cyberattack.
That is the uncomfortable message from The State of Incident Response Readiness 2026, a study by market research firm Vanson Bourne that surveyed 600 senior IT security decision makers in January 2026. The report, first covered by The Hacker News, found that 73% of respondents said their organisation is not fully ready for a serious incident.
The interesting part is what the gap is not. It is not a lack of firewalls, endpoint tools or written playbooks. Nearly every organisation surveyed had those.
What they lacked was the human machinery around them.
What does "not fully ready" actually mean?
It means that when an attack hits, the response falls apart in the seams between teams. Security staff see the alert. Legal, communications and the executive team find out later, sometimes much later. Decisions that should take minutes take hours.
Three themes run through the survey answers.
First, coordination. Incident response, in plain terms the set of steps a company takes when it discovers a breach, tends to be owned by the security team alone. When lawyers, PR, finance and customer support only get pulled in mid-crisis, the response slows to a crawl.
Second, visibility. Many respondents said they cannot see across all their systems in one place, especially where cloud services, contractors and office networks meet. If you cannot see the whole picture, you cannot tell how far an intruder has got.
Third, executive alignment. Boards approve budgets but often have not walked through a realistic breach scenario. When the call comes at 2am, the CEO is meeting the incident for the first time.
Why do plans on paper keep failing?
Because a plan that has never been rehearsed is a document, not a capability. Most of the companies in the survey had written incident response plans. Far fewer had tested them end to end in the last year with the executives who would actually run the response.
Think of it like a fire drill. Everyone knows there is a fire exit. Nobody knows how long it takes to get 400 people out until they try.
| Survey detail | Figure |
|---|---|
| Respondents not fully ready | 73% |
| Senior IT security leaders surveyed | 600 |
| Fieldwork | January 2026 |
| Research firm | Vanson Bourne |
What should ordinary customers and staff take from this?
If you are a customer or an employee of a large company, this research is a reminder that breach notification, the legal duty to tell you your data was exposed, often lands late because the company itself was slow to piece events together. Regulators including the US Federal Trade Commission, the UK Information Commissioner's Office and Australia's Office of the Australian Information Commissioner have all pushed for faster, clearer notices in recent years.
For individuals, the practical steps do not change. Use a password manager. Turn on two-factor authentication, the second code or prompt on top of your password, wherever it is offered. Treat unexpected "security" emails asking you to log in with suspicion, even when they follow a real breach.
For the companies in that 73%, the fix is less glamorous than a new product. Rehearse. Bring the executives into the room. Write down who calls the regulator, who calls the customers, and who decides when systems come back online. Then do it again next quarter.



