Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Deloitte Finds Cyber Confidence Is Outpacing Readiness

Deloitte Finds Cyber Confidence Is Outpacing Readiness

By
Key Takeaways
  • Confidence Exceeds Readiness: While 85% of respondents are somewhat or very confident in their cybersecurity strategy, Deloitte found organizations are, on average, 15 percentage points more confident than ready.
  • Executive Support Has Its Limits: Cyber has secured strong relationships with CEOs and the C-suite, but its influence remains less developed across architecture, engineering and other operational functions.
  • Vendor Portfolios Keep Growing: Seventy-four percent of respondents added cybersecurity partners over the past year, while 85% expect their number of partners to increase over the next five years, even as interest in integrated platforms accelerates.
  • Breach Impact Is Declining: Seventy-eight percent publicly reported at least one breach in 2025, but the average share reporting large or very large negative consequences fell from 64% to 52%.
  • Budgets Face an Agility Problem: Eighty-eight percent expect cyber budgets to increase over the next 12 months, but Deloitte warns that conventional budgeting approaches may struggle to keep pace with rapidly changing threats and technologies such as AI.
Deep Dive

Deloitte’s latest global cybersecurity survey begins with a number most CISOs would probably be pleased to see. Eighty-five percent of respondents say they are somewhat or very confident in their organization’s cybersecurity strategy.

Then comes the less comfortable number. When Deloitte asked how extensively organizations had implemented a series of cybersecurity actions, the average was 70% for implementation to a large or very large extent. Confidence, in other words, is running 15 percentage points ahead of readiness.

Deloitte’s fifth Global Future of Cyber Survey draws on responses from 1,058 business and technology leaders across 43 countries, five industries and 23 sectors, along with interviews with nine C-suite executives. Deloitte organizes the findings around five “paradoxes,” each describing an area where the progress organizations have made in cybersecurity has created, or at least exposed, another problem.

The confidence-readiness divide is the first. It is also a useful way of reading much of what follows.

Organizations have spent years putting cybersecurity on the executive agenda, and the survey suggests that effort has worked. Respondents report strong C-suite support and access to funding. A combined 54% say cyber is either fully integrated into broader business and technology strategy or that cyber requirements are being actively incorporated into forward-looking strategy. The question is increasingly what happens after the strategy meeting ends.

Some of the weaker points appear much closer to the machinery of the business. Only 63% of respondents say they have implemented a Business Information Security Office role to a large or very large extent. Third-party cybersecurity risk management came in lower still, with 65% reporting implementation to that degree, the lowest-rated capability among the cybersecurity actions Deloitte examined.

People remain a problem as well. Asked to rank the factors limiting their ability to respond agilely to cyber issues, 10% of respondents put a lack of skilled workers first, the largest share for any of the 15 challenges presented. Adversarial AI followed at 9%. Deloitte uses that term broadly, encompassing threats including social engineering, deepfakes, synthetic identities, misinformation and data poisoning.

Cyber Won Over the C-Suite. The Rest Is Harder.

There was a time when cybersecurity leaders had to fight for access to senior management. Deloitte’s findings suggest that, for many organizations, this is no longer the central problem. Sixty-six percent of respondents say their CISO has a strong relationship with the CEO, while 76% say the same of the C-suite overall. Among Deloitte’s “Frontrunners,” the group scoring highest on both confidence and readiness, relationships with the C-suite, CEO and board exceed 90%.

The influence thins out further down the organizational chart. Cyber is most closely connected with core IT and with risk management and compliance. Its reach is weaker across other parts of the enterprise, including operations and supply chain, legal and human resources. Even in technology development, where the relationship might seem most natural, formal participation does not always amount to shared control.

Seventy-eight percent of respondents say cyber leaders are formally integrated into DevSecOps practices. Only 40% say there is true joint ownership with shared key indicators. The relationships surrounding technology architecture are thinner still. Thirty-seven percent report a deep, trusted relationship between the CISO and chief technology officer. For the chief architect, the figure is 22%.

This is a different problem from persuading a board that cyber matters. It is slower and less glamorous. Security has to become part of how products are designed, systems are built, suppliers are selected and ordinary business decisions are made. Executive sponsorship can make that possible. It cannot do the work by itself.

The Vendor Consolidation That Hasn’t Happened

Cybersecurity leaders have another ambition that the numbers stubbornly refuse to accommodate: fewer vendors. Organizations already have plenty. Among technology infrastructure providers, 38% of respondents work with 11 to 20, and another 29% work with 21 or more. Yet 74% say their total number of cybersecurity partners increased or significantly increased over the previous year. Seventy-nine percent expect the number to increase over the next three years. Over five years, 85% do.

There are practical reasons for the accumulation. Threats change, new technologies appear and organizations buy capabilities to deal with them. AI has accelerated that process. Nearly three-quarters of respondents have updated existing cyber programs to incorporate advanced reasoning capabilities for real-time threat analysis and digital infrastructure monitoring, while 76% say they are engaging cybersecurity vendors that incorporate AI into their services.

At the same time, the industry is moving toward platforms that promise to do more under one roof. In Deloitte’s 2024 survey, 10% of respondents described their organizations’ movement toward integrated cyber platforms as transformational. That rose to 21% in 2025. For 2026, 51% expect the shift to be transformational.

That does not make consolidation straightforward. Some organizations deliberately keep a larger collection of providers because reducing the number too aggressively can create concentration risk and single points of failure. Others are carrying overlapping tools because years of buying solutions for particular threats have left them with poorly integrated architectures. Only about 30% of respondents currently consider cyber highly integrated into the technology stack.

The result is an odd market dynamic. Organizations are buying more vendors while preparing for a future in which they hope platforms will allow them to depend on fewer.

Breaches Are Still Common. The Damage Is Changing.

One of Deloitte’s more encouraging findings requires looking past the breach count. Seventy-eight percent of respondents say their organizations publicly reported at least one cybersecurity breach in 2025. That is down from 91% in 2024. Nearly one-third reported between six and 10 breaches, compared with 40% the previous year. Deloitte notes that the figures cover publicly reported incidents and that some breaches may go unreported, particularly at organizations without sufficient capabilities to identify and report them.

The consequences of those incidents appear to be easing. Across the range of potential effects Deloitte measured, an average of 52% of respondents said cybersecurity incidents had affected their organizations to a large or very large extent, down from 64% the previous year. Operational disruption remains the most frequently reported consequence, with 58% saying incidents caused large or very large disruptions affecting operations, supply chains and partner ecosystems. A year earlier, that figure was 66%.

There is an important wrinkle in the breach numbers. Deloitte’s Frontrunners do not necessarily report fewer incidents. Twenty-six percent reported 11 or more breaches during the previous year, compared with 19% of Followers and 20% of Foundation Builders. Yet Frontrunners were about as likely as Followers to report negative consequences from cyber incidents.

That makes the raw breach count a surprisingly ambiguous measure of cyber performance. A mature organization may find more incidents because it is better at looking for them. A company reporting very few may simply have fewer breaches. It may also be worse at detecting them.

Deloitte argues that organizations should pay closer attention to what happens around an incident: how quickly it is detected, whether the same attack paths keep appearing, how long attackers remain inside systems and how much operational damage follows. Sixty-seven percent of respondents are already conducting scenario-planning exercises intended to connect cyber with business strategy.

For GRC teams, that distinction matters. Counting incidents is easy. Measuring resilience means asking whether the organization can absorb one.

The Budget Is Predictable. The Threats Aren’t.

Money, unusually for cybersecurity, does not appear to be the immediate source of anxiety. Eighty-five percent of respondents say their organizations increased cyber budgets year over year, and 88% expect another increase during the next 12 months. Eight percent anticipate spending will rise by more than 25%, while more than a third expect increases between 10% and 25%.

Nor are organizations simply spending for the next quarter. Only 7% of those surveyed lack multi-year cyber investments. Of the cyber budget allocated to multi-year investments, 35% extends one year beyond the current cycle, 26% extends two years, 21% three years and 19% four to five years. Predictability is useful for finance departments. Cybersecurity has been less cooperative.

Generative AI offers the obvious example. Almost three-quarters of respondents, 72%, have incorporated new generative reasoning approaches into existing AI capabilities across a range of cyber initiatives. Only a few years ago, Deloitte notes, few organizations would have been planning immediate investments around those capabilities.

The threat side changed just as quickly. Misuse of AI did not appear among the threats identified by respondents three years ago. It is now a top-five concern alongside familiar problems such as ransomware, malware and data exfiltration.

Deloitte recommends that organizations consider making their cyber budgets less rigid, including preserving a portion for emerging capabilities or unexpected threats and considering rolling forecasts or continuous budgeting in place of conventional multi-year approaches. It also points to financial quantification of cyber risk as a way to make spending decisions more responsive to where potential losses are accumulating.

The survey ultimately describes a cybersecurity function with more institutional support than it once had and fewer excuses for failing to turn that support into practice. Boards are paying attention. Executives are funding the work. Cyber leaders have spent years building strategies and structures around risks that are now accepted as business risks.

What remains is harder to put on a slide. It is the work of getting security into architecture decisions before systems are built, understanding which third parties create risk rather than merely counting them, deciding whether another cyber tool actually adds something, and building budgets that can change when the threat environment does.

Deloitte frames its five paradoxes as obstacles that organizations can resolve. They also mark how the cybersecurity conversation itself has moved. The question is no longer simply whether organizations take cyber seriously. The survey gives ample evidence that they do. What separates them now is how much of that seriousness survives contact with the business.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong