Organizations in Cisco's top group: 8% (Source: Cisco survey of 8,000 security professionals in 30 markets, via Help Net Security (September 30, 2026))
A shutdown order needs an owner
When an attack is under way, someone has to order an affected system offline. One CSO in India told Cisco this was the missing piece in a recent incident or near-miss. The CSO described “confusion about who had the final authority to shut down the affected systems.”
That is a single account. But it matches a pattern in the survey's open-ended answers. Practitioners' free-text replies circled the same wishes: named owners, agreed routes for passing information, and quicker handoffs between departments.
The lesson here is that security speed depends on decision rights as much as on purchases. Buying a tool can be quick. Deciding who may use it, and when, is a separate job.
What Cisco measured
Cisco polled 8,000 security practitioners across 30 markets on how ready their organizations are for threats in the age of AI. Help Net Security reported the results on September 30. Just 8% reached the top tier.
The scoring leaned hardest on what Cisco calls internal friction. That is the delay and turf conflict inside a company that slows a security team when conditions change. Friction accounts for half of the 100-point score.
Cisco's starting point is that frontier AI models can uncover software flaws faster, and in greater volume, than a human team working alone. Confidence is thin: under 10% of respondents said they expect to stay ahead of the rising tide of new threats.
Respondents placed the slowdown inside their own companies. They named procurement delays, infrastructure choices owned by IT, and C-suite priorities set elsewhere. Cisco says teams already have the tools.
How the delay works in practice
The survey does not spell out the technical steps behind its figures. The following is our plain-language explanation of what the terms involve.
Deploying a control means switching on a protection, such as a new rule or setting, inside live systems. Only 21% of organizations say they can do that within six months. Cisco notes the clock starts after budget and approval are done. The respondents' reasons fit the picture: if the affected infrastructure belongs to IT, the security team needs that team's time and agreement before anything changes.
Shutting down a system stops an attacker's access. It also stops the business from using that system. Someone must be authorized to accept that trade. If nobody is named, people wait for permission while the system stays exposed. That is the gap the CSO described.
Data adds drag. Each security tool keeps its own records. To see one attack, an analyst has to line up records from several tools. As an illustration of our own, one tool may name a laptop by its hostname while another logs only a network address. The analyst must work out that both entries describe the same machine. In Cisco's data, 40% of teams give more hours to gathering and reconciling records from separate systems than to going after the attacker.
Cisco also recommends “constrained automation” for the first ten minutes of a response. In plain terms, software would carry out a few pre-approved steps within fixed limits. People would then decide the rest. The source does not list which steps Cisco has in mind.
How to read the numbers
The gap between 21% and 52% is consistent with Cisco's view that process drives delay. It does not prove it. Half of the 100 points came from friction. The top group was defined partly by that measure, so it is unsurprising that its members report less of it.
All of these numbers are self-assessments by the people surveyed, not outside measurements.
On spending, Cisco found that 41% of organizations that raised security budgets saw fewer incidents. In the top group the figure was 71%. Cisco does not say whether both percentages come from comparable groups, so do not line them up too neatly. Cisco's takeaway is that the choice of what to buy counts for more than the size of the spend.
Questions to put to your security team
Cisco offers five fixes. The first is to assign decision rights before an incident starts. The remaining four: bring data together in a single view, practise response plans under stress, allow tightly limited automation to cover the opening ten minutes, and make the safe path the easy one.
Leaders can turn those into four questions this quarter:
1. Who has written authority to take a compromised system offline, and does the on-call team know the name? 2. How long did our last new control take from approval to running? 3. How many hours a week do analysts spend matching data across tools? 4. Which first-response steps could run automatically within firm limits?
Cisco's survey is one company's view, built on self-reported answers. Still, its central point is easy to test at home. If a team cannot name the person who can pull a compromised system offline, its purchases will not spare it the lost time.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.





