Security Outcomes Report, Vol. 3

Partner: Cisco

Security is about much more than just building a perimeter—it’s about building resilience so that a business can withstand, survive, and emerge stronger from unpredictable threats. This report, based on a survey of over 4,700 professionals, breaks resilience down into digestible and actionable success factors. It confirms that while 96% of executives prioritize resilience, nearly two-thirds of firms have recently suffered a major incident that jeopardized their operations.

The data highlights that internal culture is just as critical as technical architecture. Organizations that successfully cultivate a “culture of security” see a massive 46% increase in their resilience scores. This report rewards the click by mapping exactly which IT investments—like mature zero trust and XDR—actually provide the highest return on resilience, moving firms from the bottom 10th percentile to the top 10th percentile.

Experience also fundamentally shifts organizational priorities. For firms that have lived through a major breach, “mitigating financial losses” moves from the 4th to the #1 most important objective. This study provides an “effects matrix” of 13 NIST Cybersecurity Framework capabilities, showing how simple acts like tracking key systems increase your chances of containing an incident by 11%.

Key Findings

  • The 46% Culture Boost: Cultivating a strong security culture throughout the workforce results in a 46% increase in overall security resilience.
  • Zero Trust Gains: Organizations with mature zero trust implementations boost their security resilience rating by 30%.
  • XDR Efficacy: Mature extended detection and response (XDR) implementation correlates with a 45% improvement in security resilience scores.
  • Executive Alignment: Resilience scores are 39% higher in organizations where top leadership provides high levels of active support.
  • The Hybrid Complexity Tax: Early-stage hybrid cloud models can see resilience scores drop by 14% unless management is simplified.
  • Success Factors at Scale: Adhering to all seven success factors identified in this report moves an organization from the 10th to the 90th percentile of resilience.

Independent analysis by Cyentia Institute of 4,751 anonymous survey responses from security professionals across 26 countries.