Strategy & CIO

Only 21% of Organizations Can Switch On a New Security Control Within Six Months, and Internal Friction Is Why

Cisco's survey of 8,000 security professionals found just 8% of organizations in its top tier and only one in five able to deploy a new control within six months of approval. Cisco weighted the delays and turf disputes inside the company most heavily.

September 30, 2026 · Strategy & CIO
Close-up of blue ethernet patch cables plugged into a network core switch, with red and teal light glowing across the front panel

Key Takeaways

  • Cisco surveyed 8,000 security professionals in 30 markets and placed only 8% of organizations in its top defensive group; fewer than 10% of respondents are confident they can stay ahead of new threats.
  • Only 21% of organizations can deploy a new security control within six months once budget is approved, against 52% of the top group.
  • Forty percent of teams spend more time collecting and reconciling data than pursuing threats, and Cisco weighted internal friction most heavily in its scoring.
  • ISACA's survey of more than 1,800 professionals found just 8% run regular AI-specific response exercises and 58% think their teams are understaffed.

Security budgets get approved in a meeting. Security controls get switched on months later, if at all. A new Cisco survey puts a number on that delay, and it suggests the bottleneck in most security programmes is not the purchase order or the product. It is the organisation around the tool.

The Six-Month Gap

Help Net Security's report on the Cisco survey, published September 30, covers responses from 8,000 security professionals across 30 markets on how well their organisations defend against AI-era threats. Only 8% landed in the top defensive group, and fewer than 10% of respondents said they are confident they can stay ahead of new threats.

The sharpest finding is about speed. Only 21% of organizations can deploy a new security control within six months, and that clock starts after budget and approval have already cleared. In the top group the figure is 52%. Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team down whenever something changes.

One respondent, a chief security officer in India, described how that plays out during an incident: confusion about who had the final authority to shut down the affected systems. The tooling was present. The decision rights were not.

Where the Time Goes

The survey also shows what those teams are doing instead of defending. Forty percent spend more time collecting and reconciling data from different systems than they spend chasing the threat. That is the cost of overlapping tools that each hold a partial picture, and it compounds the deployment problem: every new control has to be connected to the pile before it is useful.

Money helps, but unevenly. Among organizations that raised security spending, 41% saw fewer incidents overall, and among the top-performing group 71% reported fewer incidents from the increase. Spending works best where the organisation can actually absorb it.

The pattern is not new. Cisco's 2025 Cybersecurity Readiness Index, also built on 8,000 respondents in 30 markets, found only 4% of organizations at the mature stage, while 45% lacked the internal resources for comprehensive AI security assessments and 53% had more than 10 cybersecurity positions to fill. Capacity, not awareness, has been the recurring shortfall.

Preparedness Lags Adoption

ISACA's 2026 State of Cybersecurity survey, released September 22 and drawing on more than 1,800 professionals, shows the same lag from another angle. Only 8% of organizations conduct regular AI-specific response exercises, 64% have run none, and 48% either do not know whether AI incident playbooks exist or lack them. Meanwhile 41% already use AI to automate threat detection and response.

Staffing sits underneath all of it. ISACA found 58% believe their cybersecurity teams are understaffed, 55% have difficulty retaining qualified professionals, and 45% name LLM security operations as a skill gap, up 12 points from 2025. "AI is quickly becoming embedded in cybersecurity operations, but this research shows that many organizations have not yet matched that adoption," said Jon Brandt, ISACA's senior director of professional practices and innovation.

Read together, the two surveys describe organisations that can buy defences faster than they can operate them. A control that takes more than six months to switch on, run by a team that is short-staffed and reconciling data by hand, is a control that is late to the incident it was bought for.

Threats now move at machine speed, and the gap Cisco measured is human: approvals, ownership, and the time it takes to connect one more system. Closing it will do more for most security programmes than the next product.

Share

More in Strategy & CIO

All Resources →