SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Suprema BioStation 3 sets global sales record
    • A landmark gathering shaping the future of real estate, investment, sustainability & design
    • IDIS launches new AI PTZ cameras for enhanced security
    • Leuze AI elevates optical sensor precision
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • What are emerging applications for physical security in transportation?
    • What is the most overlooked factor when installing security systems?
    • Amid rising certificate demands, stricter compliance and quantum threats, PKIaaS is a necessity
    • How should security adapt to the unique aspects of healthcare?
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Alamo enhances security with Alcatel-Lucent solutions

    Alamo enhances security with Alcatel-Lucent solutions

    The University of Dundee implements HID for modern access control

    The University of Dundee implements HID for modern access control

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    SBB upgrades surveillance with Hanwha Vision cameras

    SBB upgrades surveillance with Hanwha Vision cameras

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Technology Summit International 2025

    Technology Summit International 2025

    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    G2E Philippines 2025

    G2E Philippines 2025

    IFSEC India 2025

    IFSEC India 2025

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Eagle Eye Networks
    • Hanwha Vision America
    Other Resources
    • eMagazines
    • Videos
    One system, one card

    One system, one card

    Aligning physical and cyber defence for total protection

    Aligning physical and cyber defence for total protection

    Understanding AI-powered video analytics

    Understanding AI-powered video analytics

    Modernizing access control

    Modernizing access control

About us Advertise
  • AI-powered video analytics
  • AI special report
  • Cyber security special report
  • 6
Cyber security
  • Home
  • About
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos

Check out our special report on Cybersecurity

Read now!

Cybersecurity resilience: Bridging confidence & capability

18 Nov 2025

Cybersecurity resilience: Bridging confidence & capability
Contact company
Contact Immersive Labs
icon Add as a preferred source Download PDF version
Quick Read
⌵
Summary is AI-generated, newsdesk-reviewed
  • Cyber resilience gap: 94% confident in handling incidents; only 22% decision accuracy achieved.
  • 60% training focuses on outdated threats; limits progress in new attack readiness.
  • 41% integrate non-technical roles in drills; affecting unpractised collaboration during crises.
Related Links
  • The Hacking Games & Immersive: Cyber talent revolution
  • Immersive One AI-powered Lab Builder launched
  • Immersive appoints new CPO and CTO

Recent analysis by Immersive highlights a significant gap between perceived confidence and actual capability in cybersecurity resilience.

Despite increased investments, enhanced board scrutiny, and comprehensive training programs, organisations' preparedness has shown minimal improvement.

Although most organisations express confidence in managing major security incidents, data from Immersive suggests otherwise.

Cybersecurity confidence vs. capability

According to Immersive's research, decision accuracy averages at a low 22%, and containment times are typically around 29 hours. Despite expectations of improved Resilience Scores, these have remained flat or decreased by an average of 3% since 2023.

James Hadley, Immersive's Founder and Chief Innovation Officer, said, "Readiness isn’t a box to tick, it’s a skill that’s earned under pressure... True resilience comes from continuously proving and improving readiness across every level of the business."

Key findings on readiness

Immersive's report identifies several systemic issues affecting cybersecurity preparedness

Immersive's report identifies several systemic issues affecting cybersecurity preparedness. These issues highlight gaps where confidence does not match capability, marking areas for improvement.

For example, while 94% of organisations believe they can detect and respond to major incidents, the data shows that only 22% achieve decision accuracy in simulations, with containment taking an average of 29 hours.

Despite heightened investment and oversight, response times and Resilience Scores have not progressed.

Outdated training practices

Training methods appear misaligned with current threats. A significant 60% of training focuses on vulnerabilities over two years old, leading to outdated preparedness. As a result, teams are over-prepared for past threats while inadequate against emerging ones.

Most training exercises are fundamental level, limiting teams from advancing to more complex readiness stages. This stagnation in training maturity results in organisations mastering obsolete tactics while newer threat methodologies emerge.

Integration of non-technical roles

The absence of rehearsed multi-functional collaboration tends to slow response times

The research shows that only 41% of organisations involve non-technical roles such as Legal and HR in their simulations, despite 90% believing in strong cross-functional coordination.

The absence of rehearsed multi-functional collaboration tends to slow response times and magnify the impact during actual crises.

Effective readiness requires coordinated efforts across an organisation, not just within technical security teams.

Navigating new threats

Veteran security practitioners tend to perform well in familiar incident-response scenarios, with around 80% accuracy. However, they struggle against novel attacks, such as those enabled by AI.

Participation in AI scenario labs by senior staff has dropped by 14% year over year, revealing an adaptability gap. James Hadley commented, "Experience teaches what to do next, until the next thing has never happened before... seasoned teams must evolve as fast as the threats they face."

Methodology behind the findings

Immersive's findings are based on a survey commissioned with Osterman Research, involving 500 cybersecurity practitioners from the U.S. and U.K., conducted between August and September 2025.

Additionally, the analysis utilises anonymised performance data from the Immersive One platform and results from the "Orchid Corp" crisis simulation. The latter involved 187 professionals participating in 11 drills across nine cities, measuring performance in real-world scenarios.

Find out about secure physical access control systems through layered cybersecurity practices.

Show full press release

Immersive, the pioneer in cyber resilience, is revealing a widening gap between confidence and capability in cybersecurity. Despite record investment, heightened board oversight, and nonstop training, measurable readiness has flatlined. While nearly every organisation believes it can handle a major incident, the data tells a different story.

According to Immersive’s analysis, average decision accuracy is just 22%, and the average containment time is 29 hours. Meanwhile, Resilience Scores remain statistically flat to lower year-over-year (with an average decline of -3%) since 2023, showing that belief in preparedness continues to outpace proven performance.

“Readiness isn’t a box to tick, it’s a skill that’s earned under pressure,” said James Hadley, Founder and Chief Innovation Officer at Immersive. “Organisations aren’t failing to practice; they’re failing to practice the right things. True resilience comes from continuously proving and improving readiness across every level of the business, so when a real crisis hits, your confidence is backed by evidence, not assumption.”

Most significant findings

The findings reveal that readiness breaks down in predictable ways. From how teams measure success, to what they choose to practice, and who they involve in the process, Immersive’s data exposes systemic patterns that prevent organisations from achieving demonstrable resilience. These are the fault lines where confidence diverges from capability, and where the work to truly be ready must begin.

Among the report’s most significant findings:

Confidence without capability

  • 94% of organisations believe they could effectively detect, respond to, and recover from a major incident.
  • In practice, teams achieved only 22% decision accuracy and took 29 hours to contain simulated attacks.
  • Resilience Scores have remained statistically flat since 2023, and the median response time of 17 days to complete the latest cyber threat intelligence labs hasn’t improved despite increased spending and executive oversight. Confidence is climbing. Capability isn’t.

Practicing the past

  • 60% of all training still focuses on vulnerabilities more than two years old, leaving teams overprepared for yesterday’s threats.
  • The most common exercises remain fundamental-level labs (36%), limiting progression into intermediate and advanced readiness.
  • The result: stalled maturity and shrinking adaptability as organisations master outdated playbooks while new attack techniques evolve.

Excluding the business

  • Only 41% of organisations include non-technical roles (such as Legal, HR, Communications, or Executives) in simulations, even though 90% believe cross-functional coordination is strong.
  • The data proves otherwise: when crises hit, unpracticed collaboration slows response and amplifies impact.
  • True readiness demands rehearsed coordination across every function, not just the security team.

New risks, old habits

  • Veteran practitioners outperform newcomers on known threats, achieving roughly 80% accuracy in classic incident-response labs.
  • But when faced with AI-enabled or novel attacks, those same experts lag behind. Senior participation in AI-scenario labs dropped 14% year over year, exposing a growing adaptability gap as adversaries weaponise AI.

“Experience teaches what to do next, until the next thing has never happened before,” added Hadley. “Even the most seasoned teams must evolve as fast as the threats they face.”

Methodology

Immersive’s report draws from:

  • An Immersive commissioned survey with Osterman Research of 500 cybersecurity pioneers and practitioners in the U.S. and U.K. (August–September 2025), capturing how organisations perceive and measure readiness.
  • Anonymised performance data within the Immersive One platform (July 2024–June 2025), representing millions of hands-on labs across industries.
  • Results from Immersive’s “Orchid Corp” crisis simulation, involving 187 professionals across 11 drills in 9 cities, measuring real-world decision-making and containment under pressure.
  • Analysis of the Immersive Resilience Score, a benchmark that quantifies readiness across people, process, and technology by measuring decision accuracy, response time, framework alignment, and adaptability to new threats. The score applies to all Immersive users, subject to eligibility, as customers must have the relevant product to be evaluated on each corresponding factor.
Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Network / IP
  • Biometrics
  • Security training
  • Physical Security Information Management (PSIM)
  • Cyber security
  • Related links
  • Biometric Access control software
  • Quad Technology Detectors Intruder detectors
  • Detection Software CCTV software
  • IP Surveillance Software CCTV software
  • Smart Card Access control software
  • Centrally managed access solution Access control software
  • Combined online/offline solution Access control software
  • Monitoring Software CCTV software
  • Surveillance Software CCTV software
  • Related categories
  • CCTV software
  • Access control software
  • Intruder detectors
Related white papers
Aligning physical and cyber defence for total protection

Aligning physical and cyber defence for total protection

Download
Combining security and networking technologies for a unified solution

Combining security and networking technologies for a unified solution

Download
System design considerations to optimize physical access control

System design considerations to optimize physical access control

Download
Related articles
How physical security consultants ensure cybersecurity for end users

How physical security consultants ensure cybersecurity for end users

How managed detection and response enhances cybersecurity management in organisations

How managed detection and response enhances cybersecurity management in organisations

Drawbacks of PenTests and ethical hacking for the security industry

Drawbacks of PenTests and ethical hacking for the security industry

Follow us

Sections Products CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cyber security special report RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Counter terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
  1. Home
  2. Topics
  3. Cyber security
  4. News
  5. Corporate news
About this page

Explore how the gap between cybersecurity confidence and capability affects resilience. Discover why true readiness demands cross-functional coordination and updated practices to handle evolving threats.

See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2025, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
Understanding AI-powered video analytics
Understanding AI-powered video analytics
Security and surveillance technologies for the casino market
Security and surveillance technologies for the casino market
Modernizing access control
Modernizing access control
Addressing Cybersecurity Vulnerabilities in the Physical World
Addressing Cybersecurity Vulnerabilities in the Physical World
SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download PDF Version
Download SourceSecurity.com product tech spec