A new industry report reveals a significant gap between organizational confidence and actual cyber readiness, with most security teams overestimating their ability to handle major incidents. Despite 91-94% of leaders expressing confidence in their incident response capabilities, measurable resilience scores have not improved since 2023, according to Immersive's Cyber Workforce Benchmark Report 2025. The report, based on data from 1.8 million exercises and a survey of 500 cybersecurity leaders, highlights that teams average only 22% decision accuracy in crisis simulations and require over 29 hours to contain simulated attacks. Median completion times for essential hands-on labs remain at 17 days, and more than 60% of organizations are training on vulnerabilities that are over two years old, leaving them unprepared for current threats.
The report attributes this stagnation to narrow training scopes, with only 41% of organizations involving nontechnical roles in simulations, and a focus on outdated vulnerabilities. Immersive recommends that organizations diversify and increase the frequency of their simulations, ensure exercises are fully completed, directly engage senior leadership, expand participation beyond IT, and prioritize training on current CVEs. The findings underscore the need for organizations to shift from a checkbox approach to readiness toward building real, practiced coordination under pressure to improve cyber resilience.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
A Sygnia report found that despite near-universal adoption of formal incident response plans, 73% of surveyed organizations said they would not be adequately prepared for an imminent cyberattack. The report attributed the gap to weak stakeholder coordination, limited senior leadership involvement, legal and communications delays, and poor visibility into public cloud and SaaS environments.
An Immersive report found that many security teams are overly confident in their cyber preparedness despite limited improvement in actual readiness and performance in cyber simulations. The report framed overconfidence as a key factor masking gaps in resilience and incident response capability.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.