73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
A new survey suggests that many organizations lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. Despite having incident response plans and security tools in place, 73% of organizations admit they would not be 'fully read…
Intelligence analysis by Llama

A new survey reveals that many organizations are struggling to bring together the elements of a mature incident response, including executive crisis management, legal and regulatory coordination, stakeholder communications, and enterprise-wide investigation. The findings point to a critical gap between having incident response capabilities and being able to execute them effectively un…
Imagine you're in a big company, and someone tries to hack into your computer system. You need to be ready to stop them quickly and safely. But if you're not prepared, it can take a long time to figure out what's going on and how to fix it. This can cause big problems, like losing important data or even shutting down the whole company.
Analysis
A Critical Gap in Incident Response Readiness
The survey findings suggest that many organizations are struggling to bring together the elements of a mature incident response. This includes executive crisis management, legal and regulatory coordination, stakeholder communications, and enterprise-wide investigation. The critical gap between having incident response capabilities and being able to execute them effectively under pressure is a major concern.
Coordination Breakdowns Slow Response
The report found that 90% of organizations expect difficulty coordinating stakeholders during a significant incident. This coordination challenge becomes especially problematic when legal, communications, security, IT, and executive teams are not aligned before an incident begins. The research found that 75% of respondents agree delays or uncertainty around legal and communications team involvement slow decision-making during cyber incidents.
Visibility Gaps Increase the Risk of Repeat Incidents
The report also highlights a major technical challenge: organizations often cannot fully see where attackers have moved. According to the survey, 78% of respondents agree blind spots in their environment create persistent attacker access and increase the risk of repeated incidents. These blind spots can span on-premises infrastructure, public cloud environments, endpoints, SaaS platforms, identity systems, and operational technology environments.
Key points
- 73% of organizations admit they would not be 'fully ready' if a significant cybersecurity attack occurred tomorrow.
- Fewer than 40% of respondents described key incident response components as 'highly effective'.
- 90% of organizations expect difficulty coordinating stakeholders during a significant incident.
- 78% of respondents agree blind spots in their environment create persistent attacker access and increase the risk of repeated incidents.
- 84% of organizations are concerned about attackers crossing from corporate IT systems into operational technology or industrial control system environments.
If organizations can improve their incident response readiness and coordination, they can minimize the impact of a cyberattack and ensure business continuity. This can be achieved by investing in training and exercises for incident response teams, improving communication and collaboration between teams, and implementing technologies that provide real-time visibility and monitoring.
If organizations fail to improve their incident response readiness and coordination, they risk experiencing significant business disruption and reputational damage. This can lead to lost revenue, customer loss, and even physical harm in critical infrastructure sectors.



