Summary is AI-generated, newsdesk-reviewed
  • Cyber resilience gap: 94% confident in handling incidents; only 22% decision accuracy achieved.
  • 60% training focuses on outdated threats; limits progress in new attack readiness.
  • 41% integrate non-technical roles in drills; affecting unpractised collaboration during crises.

Recent analysis by Immersive highlights a significant gap between perceived confidence and actual capability in cybersecurity resilience.

Despite increased investments, enhanced board scrutiny, and comprehensive training programs, organisations' preparedness has shown minimal improvement.

Although most organisations express confidence in managing major security incidents, data from Immersive suggests otherwise.

Cybersecurity confidence vs. capability

According to Immersive's research, decision accuracy averages at a low 22%, and containment times are typically around 29 hours. Despite expectations of improved Resilience Scores, these have remained flat or decreased by an average of 3% since 2023.

James Hadley, Immersive's Founder and Chief Innovation Officer, said, "Readiness isn’t a box to tick, it’s a skill that’s earned under pressure... True resilience comes from continuously proving and improving readiness across every level of the business."

Key findings on readiness

Immersive's report identifies several systemic issues affecting cybersecurity preparedness

Immersive's report identifies several systemic issues affecting cybersecurity preparedness. These issues highlight gaps where confidence does not match capability, marking areas for improvement.

For example, while 94% of organisations believe they can detect and respond to major incidents, the data shows that only 22% achieve decision accuracy in simulations, with containment taking an average of 29 hours.

Despite heightened investment and oversight, response times and Resilience Scores have not progressed.

Outdated training practices

Training methods appear misaligned with current threats. A significant 60% of training focuses on vulnerabilities over two years old, leading to outdated preparedness. As a result, teams are over-prepared for past threats while inadequate against emerging ones.

Most training exercises are fundamental level, limiting teams from advancing to more complex readiness stages. This stagnation in training maturity results in organisations mastering obsolete tactics while newer threat methodologies emerge.

Integration of non-technical roles

The absence of rehearsed multi-functional collaboration tends to slow response times

The research shows that only 41% of organisations involve non-technical roles such as Legal and HR in their simulations, despite 90% believing in strong cross-functional coordination.

The absence of rehearsed multi-functional collaboration tends to slow response times and magnify the impact during actual crises.

Effective readiness requires coordinated efforts across an organisation, not just within technical security teams.

Navigating new threats

Veteran security practitioners tend to perform well in familiar incident-response scenarios, with around 80% accuracy. However, they struggle against novel attacks, such as those enabled by AI.

Participation in AI scenario labs by senior staff has dropped by 14% year over year, revealing an adaptability gap. James Hadley commented, "Experience teaches what to do next, until the next thing has never happened before... seasoned teams must evolve as fast as the threats they face."

Methodology behind the findings

Immersive's findings are based on a survey commissioned with Osterman Research, involving 500 cybersecurity practitioners from the U.S. and U.K., conducted between August and September 2025.

Additionally, the analysis utilises anonymised performance data from the Immersive One platform and results from the "Orchid Corp" crisis simulation. The latter involved 187 professionals participating in 11 drills across nine cities, measuring performance in real-world scenarios.

Find out about secure physical access control systems through layered cybersecurity practices.

In case you missed it

What are emerging applications for physical security in transportation?
What are emerging applications for physical security in transportation?

Transportation systems need robust physical security to protect human life, to ensure economic stability, and to maintain national security. Because transportation involves moving...

Gallagher & Fortified enhance perimeter security solutions
Gallagher & Fortified enhance perimeter security solutions

Global security manufacturer - Gallagher Security is proud to announce a strategic partnership with Fortified Security, a pioneering perimeter systems integrator with over 30 years...

Genetec: Data sovereignty in physical security
Genetec: Data sovereignty in physical security

Genetec Inc., the global pioneer in enterprise physical security software, highlights why data sovereignty has become a central concern for physical security leaders as more survei...