Site navigation

How Many Firms Actually Achieve ‘Mature’ Cyber Readiness?

Elizabeth Greenberg

,

cyber readiness
“As AI transforms the enterprise, we are dealing with an entirely new class of risks at unprecedented scale – putting even more pressure on our infrastructure and those who defend it,” said Cisco chief product officer Jeetu Patel.

Only 4% of organisations worldwide have achieved a ‘mature’ level of cyber readiness required to effectively withstand today’s cybersecurity threats, according to Cisco.

The firm released their latest 2025 Cybersecurity Readiness Index, which shows there is a 1% year-on-year increase in the number of organisations displaying mature cyber readiness.

Despite this slight improvement, global cybersecurity preparedness remains low as hyperconnectivity and AI introduce new complexities for security practitioners.

AI is revolutionising security and escalating threat levels, with nearly nine in ten organisations (86%) facing AI-related security incidents last year.

However, only around half (49%) are confident their employees fully understand AI related threats, while about another half (48%) believe their teams fully grasp how malicious actors are using AI to execute sophisticated attacks. This awareness gap can leave organisations critically exposed.

AI is compounding an already challenging threat landscape. In the last year, nearly half of organisations (49%) suffered cyber-attacks, hindered by complex security frameworks with disparate point solutions.

Looking forward, respondents view external threats like malicious actors and state-affiliated groups (58%) as more significant to their organizations than internal threats (42%), underscoring the urgent need for streamlined defense strategies to thwart external attacks.

“As AI transforms the enterprise, we are dealing with an entirely new class of risks at unprecedented scale – putting even more pressure on our infrastructure and those who defend it,” said Cisco chief product officer Jeetu Patel. “This year’s report continues to reveal alarming gaps in security readiness and a lack of urgency to address them. Organisations must rethink their strategies now or risk becoming irrelevant in the AI era.”

The lack of cybersecurity readiness globally is alarming, as seven in ten (71%) respondents anticipate business disruptions from cyber incidents in the next 12 to 24 months.

Still Cisco’s report revealed other trends, such as the deployment of AI and its associated risks, and investment shifts.

Most organisations are using AI in their cyber stack for a range of deployments, including understanding threats better (89%), threat detection (85%), and response and recovery (70%).

Further, GenAI tools are widely adopted, with about half (51%) of employees using approved third-party tools. However, nearly a quarter (22%) have unrestricted access to public GenAI, and 60% of IT teams are unaware of employee interactions with the tech, underscoring major oversight challenges.


Recommended reading


This becomes even more troublesome considering 60% of organisations lack confidence in detecting unregulated AI deployments, or shadow AI, posing significant cybersecurity and data privacy risks.

Even with the advent of AI, other threats persist. Within hybrid work models, 84% of organisations face increased security risks as employees access networks from unmanaged devices, further exacerbated by using unapproved genAI tools.

With all these threats, organisations are reconsidering their priorities.

While 96% of organisations plan to upgrade their IT infrastructure, only 45% allocate more than 10% of their IT budget to cybersecurity, down 8% year-on-year. This emphasises a critical need for more focused investment in comprehensive defence strategies, which is incredibly important as threats are showing no sign of slowing down.

But when it comes to cyber investment, organisations may not know where to start due to over-complexity. Over three quarters (77%) or organisations report that their complex security infrastructures, dominated by the deployment of more than ten point security solutions, are impeding their ability to respond swiftly and effectively to threats.

Compounding all these factors is the talent shortage: a staggering 86% of respondents identify the shortage of skilled cybersecurity professionals as a major challenge, with more than half reporting more than ten positions to fill.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data