Security1 distinct publisher3 min readPublished
Arctic Wolf's 2026 survey has security leaders rating their teams highly and reporting incidents in the same breath. Confidence ran higher, not lower, at the organisations that got hit.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The two figures answer different questions, which is why one of them cannot carry the weight boards put on it. The 96% is a self-assessment about keeping pace with the volume and complexity of threats [1]. The 63% is a report of something that already happened [2]. Add the 7% who suspect an incident went undetected [3], and 70% of the same respondent pool either confirmed or suspected a significant incident inside twelve months [1].
The strange part is the direction of travel. Among leaders whose organisations had been hit, 57% were very confident; at organisations that had not been hit, 47% were [4]. Being breached carried a ten-point confidence premium [2]. There are two honest readings. An incident is the only real test most security programmes get, so afterwards the answer is grounded in observed performance rather than assumption. Or the answer reflects relief at having survived. Either way, a director treating the confidence rating as a maturity indicator is reading a number that rises after failure.
The duration data is where this stops being a security metric. Of organisations that had a significant incident, 87% lost time or productivity, 48% were disrupted for two weeks or longer, and almost 10% for two quarters or more [5][6][7]. Apply that 48% to the 63% who confirmed an incident and roughly 30 of every 100 leaders surveyed spent at least a fortnight operating in a degraded state [3]. That is a delivery and finance problem being reported inside a security survey.
The mechanism behind it argues the same way. Verizon's 2026 report analysed more than 22,000 confirmed breaches and found identity contributed to 62% of them, with credential abuse in 39% of full breach chains, the most pervasive technique it tracked [8][9][10]. The FBI logged $20.877 billion in reported losses for 2025, up 26% on 2024, with business email compromise above $3 billion [11][12]. Arctic Wolf is careful to say these datasets measure different populations and should not be summed [13], which is the right caveat. But a valid login used by the wrong person is not a prevention failure a board can budget away; it is a detection and response interval, measured in hours or weeks.
Which is where the cost figure lands. IBM put the global average breach cost at $4.99 million, up 12% year over year, and found $1.93 million in average savings for organisations using security AI and automation extensively versus not at all [14][15]. That saving is about 39% of the average breach cost [4], and Arctic Wolf, which sells 24x7 monitoring and detection [16], says plainly that AI alone does not create resilience and that automation generating alerts without advancing an investigation adds cost [17]. Worth noting when the vendor supplying the diagnosis also supplies the remedy.
The survey's own reframing of the question is the useful part: if suspicious activity appeared today, could you detect it, establish what happened, and act before it became material disruption [18]. Those are timestamps, not opinions. When telemetry first showed the activity, when a human confirmed it, when scope was established, when containment closed, when the business function came back. They sit in ticketing and incident records for whatever the last real incident was. Only 29% of respondents were confident they had avoided a significant incident in the year, against 27% the year before [19], so most boards have a recent case to ask about.
Ranked by verification strength, evidence, and original report placement.
In the Arctic Wolf 2026 AI & Cybersecurity Trends Report, 96% of respondents said they were very or somewhat confident their security team could keep pace with the volume and complexity of today's threats.
In the same Arctic Wolf study, 63% of leaders were certain their organisation had experienced a significant cybersecurity incident in the previous 12 months.
A further 7% of respondents suspected an incident had occurred without being detected.
Confidence was higher among leaders whose organisations had already been hit: 57% were very confident, compared with 47% at organisations that had not been hit.
For 48% of those organisations, the disruption lasted two weeks or longer.
Almost 10% reported disruption running for two quarters or more.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 24, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Five Eyes tell boards they have months, not years, and resilience becomes a governance question1 distinct publisher
build
Shadow AI now has an invoice: about $670K on top of the average breach1 distinct publisher
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Quantified but single-sourced and largely secondhand
The cluster carries dense, specific numbers with a stated definition of a significant incident and an explicit non-additivity caveat, which is better discipline than typical vendor content. But every figure arrives through one publisher's post: the survey's sample size, geography and methodology are undisclosed, and the Verizon, FBI and IBM statistics are relayed without primary documents in the cluster, so they cannot be independently checked here.
No adoption signal in supplied sources
The cluster contains no release, deployment, pricing, licensing or usage-disclosure event. Survey percentages about confidence and incidents are perceptions and outcomes, not measurable adoption of any product, standard or practice, and no data on uptake of 24x7 monitoring, MDR or IR retainer coverage rates is supplied.
Data understated, conclusion overstated
The underlying survey numbers are presented soberly and even hedged, but the framing overshoots the evidence in two ways: the headline asserts that 24x7 monitoring and detection 'solves' the confidence gap when no outcome data links that service model to reduced incident duration or cost, and the IBM AI-and-automation saving is invoked as financial weight for the vendor's category while the post simultaneously warns against reading it as an argument to buy AI. Positive but moderate, because the factual core is specific and self-caveated rather than inflated.
Vendor-authored content promoting its own category
Both sources are Arctic Wolf's own blog, and the publisher sells the 24x7 monitoring, detection and incident response capabilities its headline presents as the remedy. The survey is the publisher's own instrument, the retainer-confidence correlation touches another of its commercial lines, and the third-party statistics selected all point toward greater spend on detection and response. No disclosure of that interest appears in the text.
Low-to-moderate: one interested publisher, no corroboration
Claim texts are internally consistent and the two sources match almost word for word, so what was published is not in doubt. Confidence in the underlying facts is limited because there is a single publisher with a direct commercial stake, no independent verification of any statistic, no survey methodology, and adoption cannot be assessed at all.