Summary is AI-generated, newsdesk-reviewed
  • Cyber resilience reveals a gap between confidence and capability despite increased investment.
  • Only 22% decision accuracy; 29-hour containment time despite perceived preparedness.
  • 60% of training focuses on outdated threats, stalling maturity and adaptability.

Immersive has uncovered a significant gap between confidence and capability in the cybersecurity sector.

The report indicates that despite substantial investments and intensified board oversight, measurable preparedness remains stagnant. While a majority of organizations express confidence in managing major incidents, the data reveals a different scenario.

The company's analysis highlights a decision accuracy average of just 22%, with containment taking an average of 29 hours. Furthermore, since 2023, Resilience Scores have either flatlined or declined by an average of 3%, suggesting that the belief in preparedness outstrips actual performance.

Key Findings

The report shows predictable shortcomings in readiness. Immersive’s data points to systemic patterns that hinder true resilience, affecting how teams measure success, select practices, and involve participants. These patterns create gaps where confidence overshadows capability, highlighting areas needing immediate attention.

Confidence Without Capability

Despite 94% of organizations expressing confidence in their ability to effectively handle incidents, operational results showed only 22% decision accuracy with attack containment averaging 29 hours.

Resilience Scores have remained unchanged, with a median response time of 17 days in cyber threat intelligence labs, suggesting that increased spending has not translated to improved outcomes. While confidence rises, capability does not.

Practicing the Past

Data reveals that 60% of training concentrates on vulnerabilities over two years old, preparing teams for outdated threats. The prevalence of basic labs accounts for 36% of all training exercises, restricting advancements into more sophisticated readiness stages.

This focus on past threats has led to halted maturity and reduced adaptability amid evolving attack methods.

Excluding the Business

Only 41% of organizations engage non-technical roles in simulations, despite 90% believing in strong cross-functional collaboration. However, when crisis situations arise, the lack of practiced coordination slows responses and amplifies impacts.

Comprehensive readiness requires rehearsed collaboration beyond the security team.

New Risks, Old Habits

Veterans performed better than novices in managing known threats, achieving approximately 80% accuracy in traditional incident-response labs. However, these experienced individuals struggled with AI-enabled or novel attacks.

Participation in AI-scenario labs by senior staff declined by 14% in the past year, highlighting an increasing gap in adaptability as adversaries employ AI technology.

James Hadley, Founder and Chief Innovation Officer at Immersive, emphasized, "Experience teaches what to do next until the next thing has never happened before. Even the most seasoned teams must evolve as fast as the threats they face."

Methodology

The report stems from a survey by Osterman Research conducted on behalf of Immersive, involving 500 cybersecurity professionals in the U.S. and U.K. between August and September 2025.

The study captures perceptions and measures of readiness within organizations. Additionally, anonymized performance data from Immersive One, comprising millions of labs conducted across industries between July 2024 and June 2025, complements these insights.

The findings also include real-world assessments from the "Orchid Corp" crisis simulation, which involved 187 professionals across 11 drills in 9 cities. Evaluation through the Immersive Resilience Score provides a benchmark for readiness across people, processes, and technology.

Find out about secure physical access control systems through layered cybersecurity practices.

In case you missed it

Why Open Matters In The Age Of AI
Why Open Matters In The Age Of AI

Artificial intelligence (AI) creates efficiencies throughout various industries, from managing teams to operating businesses. Key outcomes include faster investigations, fewer fals...

What Are Emerging Applications For Physical Security In Transportation?
What Are Emerging Applications For Physical Security In Transportation?

Transportation systems need robust physical security to protect human life, to ensure economic stability, and to maintain national security. Because transportation involves moving...

Gallagher's Perimeter Solutions With Fortified Partnership
Gallagher's Perimeter Solutions With Fortified Partnership

Global security manufacturer Gallagher Security is proud to announce a strategic partnership with Fortified Security, a pioneering perimeter systems integrator with over 30 years o...