Cybersecurity Focus Fades Within Months After Breaches, Survey Finds
Cybersecurity attention often fades within months after an organization suffers a breach, according to a new ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada. Eighty percent of respondents said heightened security attention lasts only one to six months after an incident, while just 8% said cybersecurity becomes a permanent priority.
The findings point to a gap between how organizations respond immediately after a breach and how consistently they maintain security initiatives afterward. Although 91% of respondents said they are confident in their organization’s cybersecurity posture, 59% said business priorities often or always cause security initiatives to be postponed or downgraded.
Security Urgency Drops After a Breach
A cyber incident can trigger an immediate increase in security activity, including reviewing defenses and addressing weaknesses exposed during the attack. That urgency does not consistently translate into long-term changes, with four in five respondents saying heightened security attention lasts no more than six months.
The survey also found that organizations can struggle to maintain security work when competing business demands return. The 59% figure for security initiatives being pushed aside suggests that post-breach improvements can lose priority once the immediate consequences of an incident have been addressed.
AI Security Decisions Raise Questions
The survey also examined how organizations are using artificial intelligence in cybersecurity operations. Among organizations using AI for security, 67% said they always or often act on AI-generated recommendations without additional verification. Nearly one-third, or 29%, said they always do so.
The findings come as AI becomes more deeply integrated into security tools used for detection, analysis and response. Automated recommendations can help security teams process large volumes of information faster, but acting without additional verification can create risks if an AI system produces an incorrect or unsuitable recommendation.
Confidence Does Not Always Translate Into Action
The research also highlights the human side of incident response. Eighty-four percent of respondents said employees are likely to report a cybersecurity mistake immediately, but 83% said fear of consequences influences how cybersecurity incidents are handled.
That combination suggests organizations may have strong reporting expectations while employees remain concerned about what happens after an incident is disclosed. Maintaining an environment where mistakes are reported quickly can help security teams respond before a problem becomes more serious.
Businesses Face a Long-Term Security Challenge
The survey findings suggest that the challenge for organizations is not simply responding to breaches but maintaining security improvements after the immediate crisis has passed. A short burst of attention may address vulnerabilities exposed by one incident without creating lasting changes to security processes and priorities.
For security teams, the results put greater emphasis on making post-incident improvements part of normal business operations rather than treating them as temporary responses. The growing use of AI adds another consideration, as organizations will need to determine where automated security decisions can be trusted and where additional verification remains necessary.
