Cisco's survey of 8,000 security professionals found just 8% of organizations in its top tier and only one in five able to deploy a new control within six months of approval. Cisco weighted the delays and turf disputes inside the company most heavily.
Key Takeaways
Security budgets get approved in a meeting. Security controls get switched on months later, if at all. A new Cisco survey puts a number on that delay, and it suggests the bottleneck in most security programmes is not the purchase order or the product. It is the organisation around the tool.
Help Net Security's report on the Cisco survey, published September 30, covers responses from 8,000 security professionals across 30 markets on how well their organisations defend against AI-era threats. Only 8% landed in the top defensive group, and fewer than 10% of respondents said they are confident they can stay ahead of new threats.
The sharpest finding is about speed. Only 21% of organizations can deploy a new security control within six months, and that clock starts after budget and approval have already cleared. In the top group the figure is 52%. Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team down whenever something changes.
One respondent, a chief security officer in India, described how that plays out during an incident: confusion about who had the final authority to shut down the affected systems. The tooling was present. The decision rights were not.
The survey also shows what those teams are doing instead of defending. Forty percent spend more time collecting and reconciling data from different systems than they spend chasing the threat. That is the cost of overlapping tools that each hold a partial picture, and it compounds the deployment problem: every new control has to be connected to the pile before it is useful.
Money helps, but unevenly. Among organizations that raised security spending, 41% saw fewer incidents overall, and among the top-performing group 71% reported fewer incidents from the increase. Spending works best where the organisation can actually absorb it.
The pattern is not new. Cisco's 2025 Cybersecurity Readiness Index, also built on 8,000 respondents in 30 markets, found only 4% of organizations at the mature stage, while 45% lacked the internal resources for comprehensive AI security assessments and 53% had more than 10 cybersecurity positions to fill. Capacity, not awareness, has been the recurring shortfall.
ISACA's 2026 State of Cybersecurity survey, released September 22 and drawing on more than 1,800 professionals, shows the same lag from another angle. Only 8% of organizations conduct regular AI-specific response exercises, 64% have run none, and 48% either do not know whether AI incident playbooks exist or lack them. Meanwhile 41% already use AI to automate threat detection and response.
Staffing sits underneath all of it. ISACA found 58% believe their cybersecurity teams are understaffed, 55% have difficulty retaining qualified professionals, and 45% name LLM security operations as a skill gap, up 12 points from 2025. "AI is quickly becoming embedded in cybersecurity operations, but this research shows that many organizations have not yet matched that adoption," said Jon Brandt, ISACA's senior director of professional practices and innovation.
Read together, the two surveys describe organisations that can buy defences faster than they can operate them. A control that takes more than six months to switch on, run by a team that is short-staffed and reconciling data by hand, is a control that is late to the incident it was bought for.
Threats now move at machine speed, and the gap Cisco measured is human: approvals, ownership, and the time it takes to connect one more system. Closing it will do more for most security programmes than the next product.
Guide
Rollouts stall when nobody owns the sequence. This checklist turns a device management change into planned steps with validation, the discipline that shortens a six-month deployment.
Download
Guide
Forty percent of teams spend more time reconciling data than chasing threats. This guide shows how consolidating detection, response and recovery cuts that overhead and the time to contain.
Download
Guide
Controls that wait six months to go live leave cloud workloads exposed. This guide covers runtime protection and automated response that keep pace without a manual rollout for every change.
Download
Splunk found 46% of security teams spend more time maintaining tools than defending, and 52% have thought about leaving the field.
macOS 27 is the first release that will not run on an Intel Mac, arriving with Apple at 65% of enterprise endpoints.
New research maps the capabilities separating transformation-driving CIOs from those still managing tickets.