Who we surveyed
In July 2026, we surveyed 700 IT and cybersecurity leaders across the United States and Canada, all of whom had experienced a cybersecurity incident or breach.
Respondent profile
Top industries surveyed
- Healthcare 34%
- Education 18%
- Manufacturing 17%
- Telecoms 15%
- Financial services 10%
The cyber confidence paradox
More than nine in 10 respondents (91%) are confident in their organization's current cybersecurity posture, including 47% who are very confident.
At the same time, nearly one-third (33%) believe a major cyber incident is inevitable regardless of their defenses. A further 18% say the growing expectation of cyber incidents has reduced urgency because incidents now feel unavoidable.
Confidence itself is not the problem. It may reflect experience, stronger controls, or faith in the organization's ability to respond. The risk appears when confidence sits alongside a growing acceptance that another incident is simply part of doing business.
believe a major incident is inevitable
say incident expectations have reduced urgency
Cybersecurity is not always a year-round priority
The results show that sustained attention is far from universal, even among leaders who feel confident in their security posture.

Consistent attention throughout the year
Security competes with too many business priorities
Receives attention mainly after incidents
Teams are becoming desensitized because incidents are common
Fixing the incident does not always fix the problem that caused it
Most organizations act after an incident, but the response often focuses on correcting the immediate problem. Technical fixes, process reviews, and renewed urgency do not necessarily change the broader strategy, ownership model, or operating structure.
Closing the immediate gap is not the same as changing the conditions that allowed it to develop.
Immediate reaction after an incident
Fixing the incident vs. fixing the cause of the incident
Targeted improvements
Broader, long-term improvements
Managed within existing structures
Maintained the existing strategy and operating model
The post-breach half-life
Urgency is easy to generate after an incident. The harder task is sustaining it long enough to secure funding, assign ownership, complete technical work, and make changes stick.
Once the incident is no longer the loudest issue in the room, competing priorities, limited resources, and security fatigue can quickly erode that commitment.
The post-breach attention curve

What prevents lasting improvement
When security becomes
a business trade-off
Security decisions are made alongside product deadlines, revenue targets, operating costs, and pressure to move quickly. These trade-offs are routine, and they can push security work down the list even when risks are known.
The same pattern appears in how leaders explain incidents and day-to-day decisions: business priorities take precedence, recommendations are overridden, and unresolved risks linger until an incident or audit creates urgency.
Accepting risk is part of running a business. Leaving the decision informal is where problems begin.
How often business priorities displace security
The tension is nearly universal:
say business priorities take precedence over security.
Why security is deprioritized
Pressure to meet revenue or growth targets
Security risks are perceived as low or acceptable
Pressure to meet product or project deadlines
No clear link between security and business metrics
What contributed to the most recent incident?
The tension between
reporting and blame
Fast reporting and fear of blame can exist at the same time. An employee may flag a mistake quickly, then become more guarded as the response widens and questions of responsibility or career impact enter the conversation.
Clear ownership is essential, but accountability should not discourage people from sharing the information needed to contain the incident and understand what happened.

say employees are likely to report a mistake immediately
say fear of blame or consequences influences incident handling
The cost of unclear ownership
AI confidence is outpacing governance
AI is already embedded in cybersecurity programs, and teams credit it with making decisions faster and improving detection, investigation, and response.
As organizations rely more heavily on AI-generated recommendations, they need clear rules for when human verification is required, particularly when the potential impact is high. Adoption is already here. Governance and verification now need to catch up.

say AI has made decision-making easier
always or often act on AI recommendations without additional verification
are more willing to accept cyber risk
say AI introduced new risks requiring significant strategy changes
How AI has changed cybersecurity strategy
Conclusion
The findings do not suggest that organizations are indifferent to cybersecurity. They show how confidence, competing priorities, fear of blame, and new technology can weaken follow-through even after an incident. Organizations may act quickly, but lasting improvement depends on whether security remains a priority once immediate pressure fades.
The practical response is to make risk acceptance explicit, assign clear owners, set deadlines for deferred work, and revisit post-incident commitments over time. Organizations also need clear guidelines for when AI-generated recommendations require human review. Each incident should do more than resolve the immediate problem. It should leave the organization better prepared for the next one.
Get the full story
Download the full report to learn more about how confidence, business pressure, accountability, post-incident behavior and AI are shaping cybersecurity decisions across the United States and Canada.


