AI Security AI安全 15h ago Updated 2h ago 更新于 2小时前 46

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack 73%的组织表示他们尚未完全准备好应对重大网络攻击

73% of organizations admit they are not fully ready for a major cyberattack, despite having incident response plans and security tools in place. Coordination breakdowns between legal, communications, IT, and executive teams significantly slow down decision-making during incidents. Visibility gaps across on-premises, cloud, endpoints, and OT/ICS environments increase the risk of persistent attacker access and repeat incidents. Ransomware and cloud environment attacks are the top future concerns a 73%的组织承认,尽管已制定事件响应计划并配备了安全工具,但他们尚未完全准备好应对重大网络攻击。法律、通信、IT和高管团队之间的协调中断显著降低了事件发生时的决策速度。本地、云、端点以及OT/ICS环境中的可见性差距增加了攻击者持续访问和重复攻击的风险。勒索软件和云环境攻击是受访组织最关注的未来问题。行业影响各不相同:零售业面临运营停摆,制造业和金融业面临数据丢失,而加密货币/去中心化金融(DeFi)报告的攻击发生率最高。

65
Hot 热度
70
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • 73% of organizations admit they are not fully ready for a major cyberattack, despite having incident response plans and security tools in place.
  • Coordination breakdowns between legal, communications, IT, and executive teams significantly slow down decision-making during incidents.
  • Visibility gaps across on-premises, cloud, endpoints, and OT/ICS environments increase the risk of persistent attacker access and repeat incidents.
  • Ransomware and cloud environment attacks are the top future concerns among surveyed organizations.
  • Sector-specific impacts vary: retail faces operational shutdowns, manufacturing and financial services face data loss, and crypto/DeFi report highest attack incidence.

Why It Matters

This article highlights a critical gap between having cybersecurity capabilities and effectively executing them under pressure, which is essential for AI practitioners and researchers working on automated incident response systems. The findings underscore the need for integrated, cross-functional coordination and real-time visibility—key challenges that AI-driven security platforms must address to improve organizational resilience. As cyberattacks become more frequent and sophisticated, understanding these readiness gaps helps inform the development of smarter, faster, and more collaborative AI-powered defense mechanisms.

Technical Details

  • Survey conducted by Vanson Bourne in January–February 2026 with 600 senior IT security decision makers globally.
  • Key metrics include self-reported readiness levels (73% not fully prepared), frequency of past attacks (76% experienced at least one, 32% more than one), and effectiveness of IR components (<40% rated as “highly effective”).
  • Identified pain points include stakeholder coordination delays (90% expect difficulty), executive/board involvement gaps (89%), and blind spots in hybrid environments (78%).
  • Threat landscape prioritization shows ransomware and cloud attacks as leading future concerns.
  • Sectoral analysis reveals differential impact patterns: retail (operational downtime), manufacturing/finance (data loss), healthcare (legal/comms delays), crypto/DeFi (highest attack volume).

Industry Insight

Organizations should prioritize unifying incident response frameworks across technical, legal, communications, and executive functions to reduce decision latency during crises. Investment in unified visibility platforms spanning on-prem, cloud, endpoint, and OT/ICS environments is critical to detect lateral movement and prevent recurrence. Proactive tabletop exercises aligned with cross-departmental roles can bridge the gap between capability presence and effective execution, especially as ransomware and cloud-targeted threats continue to evolve.

摘要

73%的组织承认,尽管已制定事件响应计划并配备了安全工具,但他们尚未完全准备好应对重大网络攻击。法律、通信、IT和高管团队之间的协调中断显著降低了事件发生时的决策速度。本地、云、端点以及OT/ICS环境中的可见性差距增加了攻击者持续访问和重复攻击的风险。勒索软件和云环境攻击是受访组织最关注的未来问题。行业影响各不相同:零售业面临运营停摆,制造业和金融业面临数据丢失,而加密货币/去中心化金融(DeFi)报告的攻击发生率最高。

深度分析

简而言之

  • 73%的组织承认,尽管已制定事件响应计划并配备了安全工具,但他们尚未完全准备好应对重大网络攻击。
  • 法律、通信、IT和高管团队之间的协调中断显著降低了事件发生时的决策速度。
  • 本地、云、端点以及OT/ICS环境中的可见性差距增加了攻击者持续访问和重复攻击的风险。
  • 勒索软件和云环境攻击是受访组织最关注的未来问题。
  • 行业影响各不相同:零售业面临运营停摆,制造业和金融业面临数据丢失,而加密货币/去中心化金融(DeFi)报告的攻击发生率最高。

为什么这很重要

本文强调了在压力下有效执行网络安全能力与具备这些能力之间存在的关键差距,这对于从事自动化事件响应系统的AI从业者和研究者至关重要。研究结果突显了跨职能协作和实时可视化的必要性——这是AI驱动的安全平台必须解决的关键挑战,以提升组织的韧性。随着网络攻击变得更加频繁和复杂,了解这些准备不足的情况有助于指导开发更智能、更快、更具协作性的AI防御机制。

技术细节

  • 调查由Vanson Bourne于2026年1月至2月进行,对象为全球600名高级IT安全决策者。
  • 关键指标包括自我报告的准备水平(73%未完全准备好)、过去遭受攻击的频率(76%至少经历过一次,32%超过一次),以及IR组件的有效性(不到40%被评为“高度有效”)。
  • 确定的痛点包括利益相关者

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全