Companies have the tools to defend themselves, but their own internal barriers are slowing them down. That is the central finding of Cisco’s Relentless Defense report, a global study of 8,000 security professionals across 30 markets, surveyed in April and May 2026.
The threat is already here
Nearly all respondents (91%) faced at least one material, disruptive cyber incident in the past year. More than a third (35%) said it involved an AI-related attack. The report also cites Splunk research putting annual downtime costs for the world’s 2,000 largest companies at $600 billion, up 50% in two years.
Yet fewer than one in ten leaders are confident they can keep pace with the volume of new threats.
Only 8% make the cut
Cisco scored organizations out of 100 on coverage, speed and friction. Friction accounted for half the weight, because about six in ten practitioners blamed organizational blockers rather than technical ones. The average score was 64.
Only 8% qualified as “Relentless Defenders”. The rest were Established (39%), Reactive (41%) and Exposed (12%).
Where teams get stuck
The problems are mostly human. Some 43% say their security metrics are too technical to influence executives, and 27% have no consistent way to measure performance at all. Four in ten spend more time collecting and correlating data than chasing the threat.
Speed suffers too. Only 21% can fully deploy a new control within six months, even after approval. Just 14% can update controls in real time, against 45% of Relentless Defenders.
Visibility gaps and AI agents
98% of top performers have a single, real-time view of security data, compared with 58% globally. For AI agents and other non-human identities, 86% have comprehensive controls, compared with 41% overall. This matters because 98% of organizations are deploying or planning to deploy AI agents in security operations.
AI helps, if governance comes first
The news is encouraging. Some 87% say AI has improved the speed of threat detection by at least 25%, and half say it has improved it by at least 50%. But only 54% are very confident they could catch a compromised AI agent. Top performers, at 77%, are far more sure.
The report argues that these leaders did not scale AI because they worried less. They scaled it because they were better prepared.
Bigger budgets aren’t the answer
Only 41% of firms that raised security spending saw fewer incidents. Among Relentless Defenders, 71% did what they invested in matters more than how much.
Five moves the report recommends
- Fix ownership before fixing tools.
- Build one shared picture of the truth.
- Practice response plans, don’t just document them.
- Let AI handle the first ten minutes of an incident.
- Make the secure option the easiest one.
A note of caution
Cisco sells security products, and the study frames unified platforms as the way forward. Still, the finding that coordination, not capability, separates leaders from laggards is hard to dismiss, and it will resonate with any boardroom asking whether it is secure enough to adopt AI.
