This section is The content in this section is supplied by Business Wire for the purposes of distributing press releases on behalf of its clients. Postmedia has not reviewed the content. by Business Wire Article content80% Say Heightened Attention to Post-Breach Security Lasts Only One to Six Months, and 59% Say Business Priorities Regularly Push It Aside
Sign In or Create an Account
or View more offersArticle content
AUSTIN, Texas — ManageEngine, a division of Zoho Corporation and a leading provider of enterprise IT management solutions, today released The Psychology of Being Breached, a new report examining the human and organizational factors that influence cybersecurity decisions across U.S. and Canadian organizations.
Article contentWe apologize, but this video has failed to load.Try refreshing your browser, or
tap here to see other videos from our team.Article content
The findings are based on a survey of 700 IT and cybersecurity leaders whose organizations have experienced a cybersecurity incident or breach. The results show that confidence does not always translate into sustained action. Organizations know the risks they face, but security can quickly lose ground once the immediate pressure of an incident passes and other business priorities take over.
Article content
Story continues below
This advertisement has not loaded yet, but your article continues below.
Article contentKey findings include:Article contentArticle content
- Confidence does not guarantee lasting focus: 91% of respondents are confident in their organization’s cybersecurity posture, yet just 8% say cybersecurity becomes a permanent priority after an incident.
- Post-incident urgency has a short shelf life: 80% say heightened attention to cybersecurity lasts only one to six months after an incident.
- Business priorities regularly push security aside: 59% say business priorities always or often cause security initiatives to be postponed or downgraded.
- Fear impacts incident handling despite swift reporting: 84% say employees are likely to report a cybersecurity mistake immediately, while 83% say fear of consequences influences how cybersecurity incidents are handled.
- AI adoption is outpacing verification: Among organizations using AI in cybersecurity, 67% always or often act on AI-generated recommendations without additional verification, including 29% that always do so.
Article content
“What stands out is that organizations already know cybersecurity matters. The challenge is keeping it a priority once the immediate pressure of an incident fades,” said Rajesh Ganesan, CEO at ManageEngine. “That means being clear about who owns the follow-up, what needs to get done and when, and making sure those commitments don’t disappear when the next business priority takes over.”
Article contentWhen Cyber Risk Becomes Business as UsualArticle content
Experiencing an incident does not always lead to sustained vigilance. A third (33%) of respondents believe a major cyber incident is inevitable regardless of their defenses, 26% say they accept risks they consider manageable, and 23% say known risks often remain unresolved until an incident or audit creates urgency.
Article content
The response after an incident shows a similar pattern. Organizations commonly make immediate technical or operational fixes, but 44% made no structural or strategic change following their most recent incident.
Article content
“Cybersecurity is not about designing a system that is 100% secure, because that simply does not exist,” said Dr. Erik Huffman, cyberpsychology expert and researcher. “There will always be risk. The challenge is making sure organizations do not become comfortable with that risk after an incident. They need to understand what level of insecurity is acceptable based on their risk tolerance and continually reassess it, rather than allowing attention to fade once the immediate threat has passed.”
Article content
Story continues below
This advertisement has not loaded yet, but your article continues below.
Article content
Culture and accountability can also affect what happens once an incident is reported. Eighty-four percent of respondents say employees are likely to report a cybersecurity mistake immediately, while 83% say fear of consequences influences how cybersecurity incidents are handled. One-quarter (25%) say unclear ownership can delay containment, remediation, or other critical actions.
Article contentAI Is Reshaping How Organizations Evaluate RiskArticle content
AI is now widely used in cybersecurity, but organizations are still working through how much oversight its recommendations require. Among organizations using AI in cybersecurity, two-thirds (67%) always or often act on AI-generated recommendations without additional verification, and 29% say they always do.
Article content
More than half (55%) say AI-enabled security tools have made their organization more willing to accept cyber risk. At the same time, 24% say AI has introduced new risks requiring significant changes to their cybersecurity strategy, while 81% say AI has made cybersecurity decision-making easier overall.
Article content
The full report, The Psychology of Being Breached, is available for download here.
Article contentSurvey MethodologyArticle content
In July 2026, ManageEngine commissioned independent market research agency Censuswide to survey 700 full-time IT and cybersecurity leaders across the United States and Canada, all of whom had their employer experience a cybersecurity incident or breach. The sample included 500 respondents in the United States and 200 in Canada, evenly split between mid-sized organizations and large enterprises.
Article contentAbout ManageEngineArticle content
ManageEngine is a division of Zoho Corporation and a leading provider of IT management and security solutions for organizations across the world. With a powerful, flexible, and AI-powered digital enterprise management platform, we help businesses get their work done from anywhere and everywhere—better, safer, and faster. To learn more, visit www.manageengine.com.
Article contentArticle contentArticle contentArticle contentView source version on businesswire.com: Article content
https://www.businesswire.com/news/home/20260910829103/en/
Article contentArticle content
Contacts
Article contentMedia Contact: Article content
Article content
Ahana Vissa
Article content
Article content
ManageEngine
Article content
Article content[email protected]Article content
