Site navigation

Organisational Friction Hampers Cyber Defences, Cisco Finds

Graham Turner

,

Cybersecurity organisational friction
New report also highlights growing concern around AI agents, despite widespread adoption of AI within security operations.

Internal friction and fragmented ways of working are emerging as major obstacles to effective cybersecurity, with new Cisco research suggesting organisational issues are increasingly limiting companies’ ability to respond to AI-driven threats.

Cisco’s new Relentless Defense report surveyed 8,000 security professionals across 30 markets, examining how organisations are responding to a threat landscape being reshaped by artificial intelligence. Some 27% of respondents were CISOs, while 60% had spent six or more years at their current organisation.

The findings suggest that technological capability alone is no longer the principal constraint on cyber defence. When practitioners were asked what would have made the biggest difference during a recent security incident or near-miss, around six in ten pointed to organisational rather than technical barriers, including disconnected teams, fragmented data and unclear ownership.

The problem comes as cyber incidents continue to affect the overwhelming majority of organisations surveyed. Cisco found that 91% of security leaders had experienced at least one “material disruptive” cyber incident during the previous year, while 35% said an incident had involved an AI-related attack.

Cisco assessed organisations against three areas — security coverage, response speed and organisational friction — producing an average overall score of 64 out of 100. Friction was given half of the weighting after respondents repeatedly identified internal organisational barriers as a major constraint on their ability to defend against threats.

Only 8% of organisations fell into the highest-performing category, which Cisco describes as “Relentless Defenders”. These organisations were found to have stronger security coverage, faster response capabilities and greater alignment between security, networking and IT teams.

Cisco found that 83% of these organisations operate as a single coordinated security function with shared visibility and tools across security, networking and IT, compared with 37% among other respondents.

The wider findings highlight the impact of fragmented systems and processes on security teams. Four in ten respondents said they spend more time manually collecting and correlating information from different systems than dealing with threats themselves, while 39% said critical security insights are being missed because relevant data is inaccessible.

Visibility also remains a challenge. Only 20% of organisations said they have active security protection across at least 95% of endpoints, compared with 51% of Cisco’s top-performing group. Meanwhile, just 41% of organisations have comprehensive controls consistently applied to AI agents, service accounts and automated systems.

AI Creates New Risks and New Opportunities

The findings come as AI increasingly plays a role on both sides of cyber defence.

Almost every organisation surveyed — 98% — has deployed or plans to deploy AI agents within its security operations, although Cisco found that concerns around governance and control are limiting adoption.

Sensitive data exposure was the most commonly cited AI-related security concern, identified by 41% of respondents, followed by the risk of AI systems themselves being compromised at 40%. More than a third, 37%, cited concerns around the security and data handling practices of third-party providers.

Only 54% said they were very confident that their organisation could detect and respond to a compromised AI agent or autonomous system, while 80% believe agentic AI will allow attackers to conduct more persistent and adaptive campaigns with less effort.

Despite those concerns, AI is also delivering significant benefits for security teams. Cisco found that 87% of respondents using the technology said it had improved threat detection speeds by at least 25%, while 85% reported equivalent improvements in response and remediation. Nearly nine in ten also said AI had reduced the operational burden placed on security teams.

Cisco’s research suggests that organisations making the greatest gains from AI are also those placing stronger governance around its use. Among the company’s “Relentless Defenders”, 65% have extensively deployed AI agents within security operations, compared with 30% of other organisations, while 77% are very confident in their ability to detect and respond to a compromised AI agent.


Recommended reading


The report also found that simply spending more on cybersecurity does not guarantee better outcomes. Among organisations that increased security expenditure, 41% reported fewer incidents, while 45% saw incident numbers either rise or remain unchanged. By comparison, 71% of organisations in Cisco’s top-performing group said increased budgets had been accompanied by a reduction in incidents.

Chintan Patel, Cisco Chief Technology Officer for EMEA, said: “Boards have stopped asking whether AI will deliver. They are asking whether their organization is secure enough to use it.

“Regulation accelerated that shift, but it will not finish it. The organizations treating security as a compliance exercise will struggle. Those building it into how they operate are already ahead.”

Cisco said organisations should focus on establishing clear ownership and decision-making responsibilities, creating unified views of security data, regularly practising incident response processes and using constrained automation to handle the earliest stages of an incident.

Graham Turner

Sub Editor

Latest News

Business Diversity Editor's Picks

Female Founders Gather in Edinburgh For Entrepreneurial Summit

Business Cybersecurity Security

Organisational Friction Hampers Cyber Defences, Cisco Finds

Cybersecurity Education

UK Schools Still See Cyber Incidents As An IT Issue

5G AI Editor's Picks

Regional UK Divide Emerges as Connectvity Dictates AI Scaling