Who we surveyed

In July 2026, we surveyed 700 IT and cybersecurity leaders across the United States and Canada, all of whom had experienced a cybersecurity incident or breach.

Respondent profile

700 total respondents
500 from the US 200 from Canada
350 350
from Mid-sized organizations from Large enterprises

Top industries surveyed

  • Healthcare 34%
  • Education 18%
  • Manufacturing 17%
  • Telecoms 15%
  • Financial services 10%

The cyber confidence paradox

More than nine in 10 respondents (91%) are confident in their organization's current cybersecurity posture, including 47% who are very confident.

At the same time, nearly one-third (33%) believe a major cyber incident is inevitable regardless of their defenses. A further 18% say the growing expectation of cyber incidents has reduced urgency because incidents now feel unavoidable.

Confidence itself is not the problem. It may reflect experience, stronger controls, or faith in the organization's ability to respond. The risk appears when confidence sits alongside a growing acceptance that another incident is simply part of doing business.

91% confident
33%

believe a major incident is inevitable

18%

say incident expectations have reduced urgency

Cybersecurity is not always a year-round priority

The results show that sustained attention is far from universal, even among leaders who feel confident in their security posture.

Cybersecurity shield
29%

Consistent attention throughout the year

25%

Security competes with too many business priorities

24%

Receives attention mainly after incidents

22%

Teams are becoming desensitized because incidents are common

Fixing the incident does not always fix the problem that caused it

Most organizations act after an incident, but the response often focuses on correcting the immediate problem. Technical fixes, process reviews, and renewed urgency do not necessarily change the broader strategy, ownership model, or operating structure.

Closing the immediate gap is not the same as changing the conditions that allowed it to develop.

Immediate reaction after an incident

Process-focused discussions 29%
Increased urgency across the organization 27%
Temporary urgency that faded quickly 15%
Blame-focused discussions 15%
Little noticeable change 13%
29% 27% 15% 15% 13%
Process-focused discussions Increased urgency across the organization Temporary urgency that faded quickly Blame-focused discussions Little noticeable change

Fixing the incident vs. fixing the cause of the incident

30%

Targeted improvements

26%

Broader, long-term improvements

23%

Managed within existing structures

21%

Maintained the existing strategy and operating model

44% Made no structural or strategic change

The post-breach half-life

Urgency is easy to generate after an incident. The harder task is sustaining it long enough to secure funding, assign ownership, complete technical work, and make changes stick.

Once the incident is no longer the loudest issue in the room, competing priorities, limited resources, and security fatigue can quickly erode that commitment.

The post-breach attention curve

Cybersecurity network
Less than one month 4%
One to three months 40%
Four to six months 40%
More than six months 8%
Permanent priority 8%
4% 40% 40% 8% 8%
Less than one month One to three months Four to six months More than six months Permanent priority
80% say increased attention lasts one to six months before competing priorities take over.

What prevents lasting improvement

Competing business priorities
25%
Budget constraints
23%
Security fatigue
20%
Staff shortages
17%
Lack of executive support
16%

When security becomes
a business trade-off

Security decisions are made alongside product deadlines, revenue targets, operating costs, and pressure to move quickly. These trade-offs are routine, and they can push security work down the list even when risks are known.

The same pattern appears in how leaders explain incidents and day-to-day decisions: business priorities take precedence, recommendations are overridden, and unresolved risks linger until an incident or audit creates urgency.

Accepting risk is part of running a business. Leaving the decision informal is where problems begin.

How often business priorities displace security

Always
26%
Often
33%
Sometimes
31%
Rarely
8%
Never
1%

The tension is nearly universal:

Overall 90%

say business priorities take precedence over security.

Why security is deprioritized

28%

Pressure to meet revenue or growth targets

27%

Security risks are perceived as low or acceptable

26%

Pressure to meet product or project deadlines

18%

No clear link between security and business metrics

What contributed to the most recent incident?

Competing business priorities took precedence 20%
Human error that existing controls failed to prevent 17%
Sophisticated and targeted attack beyond the organization's defenses 15%

The tension between
reporting and blame

Fast reporting and fear of blame can exist at the same time. An employee may flag a mistake quickly, then become more guarded as the response widens and questions of responsibility or career impact enter the conversation.

Clear ownership is essential, but accountability should not discourage people from sharing the information needed to contain the incident and understand what happened.

Reporting insight
84%

say employees are likely to report a mistake immediately

83%

say fear of blame or consequences influences incident handling

Fast reporting does not always mean people feel free to speak candidly throughout the response

The cost of unclear ownership

25%
Delayed containment, remediation, or critical actions
20%
Greater business disruption
16%
Higher risk of data loss or exposure
15%
Inconsistent decision-making
13%
Unclear post-incident accountability and lessons learned
12%
Difficulty coordinating across teams

AI confidence is outpacing governance

AI is already embedded in cybersecurity programs, and teams credit it with making decisions faster and improving detection, investigation, and response.

As organizations rely more heavily on AI-generated recommendations, they need clear rules for when human verification is required, particularly when the potential impact is high. Adoption is already here. Governance and verification now need to catch up.

AI strategy growth
81%

say AI has made decision-making easier

67%

always or often act on AI recommendations without additional verification

55%

are more willing to accept cyber risk

24%

say AI introduced new risks requiring significant strategy changes

How AI has changed cybersecurity strategy

27% Strengthened detection, investigation, and response
27% Improved efficiency
24% Introduced new risks requiring significant strategy changes
22% Increased investment in capabilities and controls
27%
27%
24%
22%
Strengthened detection, investigation, and response
Improved efficiency
Introduced new risks requiring significant strategy changes
Increased investment in capabilities and controls
Ownership and accountability
Follow-through and process
Security controls and protection
Technology and governance

Conclusion

The findings do not suggest that organizations are indifferent to cybersecurity. They show how confidence, competing priorities, fear of blame, and new technology can weaken follow-through even after an incident. Organizations may act quickly, but lasting improvement depends on whether security remains a priority once immediate pressure fades.

The practical response is to make risk acceptance explicit, assign clear owners, set deadlines for deferred work, and revisit post-incident commitments over time. Organizations also need clear guidelines for when AI-generated recommendations require human review. Each incident should do more than resolve the immediate problem. It should leave the organization better prepared for the next one.

Get the full story

Download the full report to learn more about how confidence, business pressure, accountability, post-incident behavior and AI are shaping cybersecurity decisions across the United States and Canada.

Download the report
The Psychology of Being Breached report
X

The report has been delivered to your inbox.

Check your spam folder if you have trouble locating it.