Over half of private sector companies experienced a cybersecurity incident in the past year, and their cybersecurity posture might be weakening, according to a new report from Cisco.
Their new Cybersecurity Readiness Index also revealed that only 3% of organisations they surveyed had a mature stage of cybersecurity readiness in 2024. Further, 71% of organisations have fallen in the two least prepared categories.
This lack of robust posture is troublesome, especially since around three quarters (73%) of businesses believe a cybersecurity incident will disrupt their businesses in the next 12 to 24 months.
Despite this actual lack of readiness, 80% of companies feel moderately to very confident in their ability to stay resilient.
Readiness and resiliency was higher among larger and medium sized organisations. Small organisations tended to struggle more, likely due to budgetary constraints and the inability to attract more digitally skilled talent.
Industries boasting the most robust cybersecurity posture were financial services, technology services, media and communications, and manufacturing. Industries requiring the most improvement are personal care, education, and wholesale.
While confidence is high, posture remains low for a number of reasons: nearly half (46%) of organisations have more than ten unfilled cybersecurity roles on their team at the time of the survey.
This points to the devasting toll the cyber skills gap has on the globe as industries struggle to attract and retain those with the essential skills for cyber safety.
Evolving and emerging threats, spurred on by advances in AI technology, has cyber teams confused by their own complex stacks, with 80% of companies admitting that having multiple point solutions is slowing down their team’s ability to detect, respond to, and recover from incidents.
How is the Threat Landscape Evolving?Â
Besides AI advancements, an interesting trend revealed in the survey was the shift from internal to external threat factors.
The majority (62%) of companies now see external actors as their biggest threat, as opposed to 31% saying the same for internal actors. This is a marked shift from 2023, where the two were seen as equal threats, and could be driven by the increased sophistication seen in external threats.
Malware (76%) and phishing (54%) were the top types of attacks experienced in the past year, followed by credential stuffing (37%), supply chain and social engineering attacks (32%), and cryptojacking (27%).
The continuation of hybrid working is also a factor stressing cyber specialists out. 82% of organisations cite remote logins as a heightened threat vector, and nearly one in three (29%) employees move between at least six networks weekly, only increasing the danger.
With these dangers, and a shocking lack of security readiness, it is no wonder that Cisco also found that 97% of companies expect to increase their security budgets, with over half (52%) planning to increase these by 11-30% in 2024.





