Skip to content

Security1 publisher2 min readPublished

Breached organizations drop back to old habits inside six months, ManageEngine survey of 700 leaders finds

Every one of the 700 IT and security leaders ManageEngine surveyed had already been through a breach. Eight percent said security became a permanent priority afterward, and 80 percent said the heightened focus faded within six months.

The Watch · Security desk

Illustration accompanying Breached organizations drop back to old habits inside six months, ManageEngine survey of 700 leaders finds

What happened

  • ManageEngine surveyed 700 IT and cybersecurity leaders in the US and Canada, all of whom had been through a breach or incident, and 91 percent said they trust their organization's current security posture.
  • Eight percent said cybersecurity becomes a permanent priority once the incident is behind them, and 80 percent said the heightened focus lasts one to six months before fading.
  • Close to half kept their existing structures and strategy in place after the incident, with a smaller share making targeted fixes to the specific gap and fewer changing governance, training or escalation.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The period in which a security team can win durable funding after an incident is measured in months, so any program that needs longer than six months to land is being pitched into the same priority contest that deferred it before.
  • exposure An organization that repaired only the path used against it is still reachable by every other path it had, and the staffing attention that would have found those paths has moved on.
  • contradiction The survey measures belief: the same population that trusts its posture includes a third who treat a major incident as inevitable whatever they do. The 91 percent is self-reported, so an auditor still has to test control effectiveness.

Of the 700 organizations, 56 said security stayed a permanent priority after their incident and 644 did not [1].

Known gaps tend to stay open until an audit or another incident forces the issue, according to the survey [8]. Only a minority of respondents said security gets consistent attention through the year, outside the aftermath of an incident [21]. A fix scoped to the gap that caused an incident closes that gap. Anything reachable by a different path is where it was before, and by month six the people who would have gone looking are back on other work [5].

About 637 of the 700 leaders said they trust the security posture they are running now [2]. A third of the sample said a major incident is inevitable regardless of their defenses [9]. "The belief that breaches are inevitable has lowered the bar for security," said Dr. Erik Huffman, a cyberpsychology researcher who commented on the findings [17]. All of this is leaders reporting on themselves, in a survey ManageEngine ran [1].

The reason security work slips is not mysterious to the respondents. A majority said competing business demands regularly cause security initiatives to be postponed or downgraded, and one in five named exactly that as the leading factor behind their most recent incident [10][11].

The AI numbers point the same way. A majority said AI has made them more willing to accept cyber risk [16], and among organizations using AI in security, about two in three said they often or always act on its recommendations without additional verification [15]. "LLMs are frequent targets for attackers because of the level of trust people place in the information they receive from AI systems," Huffman said [18]. He put the correction as "We need to move from 'trust but verify' to 'verify, then trust'" [19].

Reporting culture shapes the record an incident leaves behind. Eighty-three percent said fear of consequences influences how an incident is handled once it is reported, and a notable share described their organization's response as blame-focused [12]. Close to one in five said they were not sure whether security, IT, or business teams should be responsible for a given failure [13]. The survey attributes real costs to that uncertainty: delayed remediation, business disruption, and a higher chance that data is exposed before anyone closes the gap [14].

What to watch

  • Whether ManageEngine publishes the sample breakdown by company size, sector and breach severity, which would show where the one-to-six-month decay is worst.
  • Whether a second wave of the survey holds the 8% permanent-priority figure or moves it.
  • Whether auditors and cyber insurers start asking breached firms for evidence of sustained change rather than a closed ticket on the original gap.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories