Sep 29
/
Latest News
Internal Friction, Not Technology, Is What Slows Security Teams in the AI Era
Cisco surveyed 8,000 security professionals across 30 markets and found that only 8% of organizations are positioned to defend effectively against AI‑era threats. The strongest predictor of resilience wasn’t tooling or visibility — it was internal friction, meaning the delays, ownership gaps, and cross‑departmental barriers that slow response when conditions change.
Fewer than one in ten respondents believe they can stay ahead of rapidly expanding AI‑driven threats. Cisco’s analysis points to organizational drag: procurement bottlenecks, IT‑controlled infrastructure decisions, and competing C‑suite priorities. The report concludes that most teams have the right technologies, but their organizations prevent them from using those tools quickly enough.
Only 21% of organizations can activate a new security control within six months after budget approval, while top performers reach 52%. Data friction also slows response — 40% of teams spend more time collecting and reconciling data across systems than investigating the threat itself. One CSO described a recent incident where unclear authority over shutting down compromised systems caused critical delays.
Increased spending did not guarantee improvement. Among organizations that raised budgets, 41% saw fewer incidents, compared with 71% in the top group. Cisco interprets the gap as evidence that what organizations buy matters more than how much they spend.
Friction accounted for half of Cisco’s 100‑point scoring model, meaning top performers were partly defined by having fewer internal barriers. Open‑ended responses repeatedly emphasized the same needs: clear ownership, defined escalation paths, and faster communication between departments. Cisco’s recommendations include assigning decision rights before incidents occur, unifying data into a single operational picture, pressure‑testing playbooks, enabling constrained automation for initial response, and making secure actions the easiest ones to execute.
Fewer than one in ten respondents believe they can stay ahead of rapidly expanding AI‑driven threats. Cisco’s analysis points to organizational drag: procurement bottlenecks, IT‑controlled infrastructure decisions, and competing C‑suite priorities. The report concludes that most teams have the right technologies, but their organizations prevent them from using those tools quickly enough.
Only 21% of organizations can activate a new security control within six months after budget approval, while top performers reach 52%. Data friction also slows response — 40% of teams spend more time collecting and reconciling data across systems than investigating the threat itself. One CSO described a recent incident where unclear authority over shutting down compromised systems caused critical delays.
Increased spending did not guarantee improvement. Among organizations that raised budgets, 41% saw fewer incidents, compared with 71% in the top group. Cisco interprets the gap as evidence that what organizations buy matters more than how much they spend.
Friction accounted for half of Cisco’s 100‑point scoring model, meaning top performers were partly defined by having fewer internal barriers. Open‑ended responses repeatedly emphasized the same needs: clear ownership, defined escalation paths, and faster communication between departments. Cisco’s recommendations include assigning decision rights before incidents occur, unifying data into a single operational picture, pressure‑testing playbooks, enabling constrained automation for initial response, and making secure actions the easiest ones to execute.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.