
A Cisco survey of 8,000 security professionals across 30 markets puts only 8% of organizations in the top group for AI-era defense, and the gap comes down to how quickly a company can switch on a new control. The biggest drag sits inside the business, not in the security stack: procurement holdups, infrastructure decisions owned by IT, and priorities the C-suite sets elsewhere. Teams have the tools, and the slowdown comes from how the organization runs them.
What did the Cisco AI-era defense benchmark measure?
Cisco scored respondents on a 100-point scale and gave the most weight to internal friction, the delays and turf problems inside a company that slow a security team when something changes. Frontier AI models can find software vulnerabilities at a scale and speed no human team working alone can match, which is the pressure the benchmark is built around. Fewer than one in ten respondents say they can stay ahead of the flood of new threats their answers describe.
How long does it take to switch on a new control?
Only 21% of organizations can switch on a new security control within six months, and that clock starts after budget and approval have cleared. In the top-scoring group, 52% manage it inside that same window. The gap shows up in daily operations before any incident: 40% of teams spend more time gathering and matching up data from different systems than they spend chasing the threat itself. When asked what would have made the biggest difference in a recent incident or near-miss, practitioners pointed to a clearer escalation path, because during the live incident there was confusion about who had the final authority to shut down the affected systems.
Does spending more money reduce incidents?
Among organizations that raised security spending, 41% reported fewer incidents. In the top group, 71% saw fewer incidents from their larger budgets. The figures rest on different bases, so the comparison should be read loosely. Cisco reads the gap as a sign that what a company buys and how it deploys it matters more than the size of the check.
How should the ranking be read?
Friction makes up half of the 100-point score, so the top group is defined in part by having little of it. Finding that those same companies report less friction is close to built into the design. Every data point comes from respondents describing their own organizations, which adds another layer of self-reporting. The open-ended answers carry more weight, because practitioners kept asking for the same things across markets: clear ownership, defined communication channels, and faster communication between departments. A team that cannot say who may shut down a compromised system loses time no matter what it has bought.
What does Cisco recommend?
Cisco’s first fix is to hand out decision rights before an incident starts, so that no one has to figure out who is in charge during the live event. The next four recommendations are to unify data into a single picture, run playbooks under pressure, let constrained automation handle the first ten minutes, and make the secure option the easiest one for staff to follow. Each recommendation targets a different part of the friction Cisco measured: clarity of ownership, data fragmentation, playbook execution, automation scope, and the path of least resistance for end users.
What does this mean for security operations?
The benchmark gives security leaders a way to benchmark their own rollout speed against a global sample, and the metric that matters most is the gap between budget approval and a live control. Reducing that gap is the lever the data points to, and the survey puts ownership, defined escalation paths, and inter-department communication at the center of the gap. AI-era defense is as much an organizational question as a tooling question, and the organizations in the top group appear to treat it that way.
FAQ
What is the Cisco AI-era defense benchmark?
Cisco surveyed 8,000 security professionals across 30 markets and scored them on a 100-point scale, with internal friction carrying the most weight. Only 8% of organizations landed in the top group.
How long does it take most organizations to roll out a new security control?
Only 21% of organizations can switch on a new security control within six months of budget approval, and the clock starts after budget and sign-off have cleared.
Does spending more on security reduce incidents?
Among organizations that raised security spending, 41% reported fewer incidents. In the top group, 71% saw fewer incidents from larger budgets. The figures rest on different bases, so the comparison should be read loosely.
This article summarizes reporting from helpnetsecurity.com.
