The 2026 Cyber Security Survey Results
SURVEY REPORT
What security professionals admit when you promise not to tell their boss
We ran an anonymous survey built on a simple premise: most cybersecurity reporting is performance. People say what auditors, clients and bosses want to hear. So we asked the questions that don’t appear on a compliance checklist — about the corners that get cut, the incidents that get softened, and the gap between the posture organisations advertise and the one they actually run. 52 professionals answered candidly.
What follows isn’t a story about reckless companies. It’s a story about honest people working inside systems that quietly reward the appearance of security over the real thing — and what they told us when the usual incentives were switched off.
Who answered
The 52 respondents skew toward people who would know: roughly 60% sit in security, IT or compliance leadership (CISOs, Heads of Security, IT directors, risk and audit leads), with the remainder spanning other executives, practitioners and individual contributors. They’re concentrated in small and mid-sized organisations — more than four in five (83%) have fewer than 250 staff — and in technology and professional-services sectors. Geographically the sample leans UK and European, with North America, Oceania, Africa, Asia and South America also represented.
A sample this size is directional, not statistically representative — but the consistency of the candour across roles and regions is itself the finding. Read these numbers as a confession, not a census.
The one-line takeaway
Almost everyone takes security seriously. Almost no one thinks they’ve actually got it handled. The space between those two facts is where the risk lives.
Only 12% of respondents said security is “firmly embedded in how we operate.” The other 88% described gaps they haven’t filled, policies that exist in name only, or outright “security theatre.” That honesty — from a room full of the people responsible for security — is the thread running through every finding below.
1. The say–do gap is the real vulnerability
Across the whole sample, 71% said work usually wins when a security policy gets in the way — people find workarounds, or nobody really enforces the rules. Just 27% said security reliably holds the line. The uncomfortable part is the overlap: most of the people describing those workarounds are the same people who rate their organisation as taking security seriously. The intent is real. The operating reality is something else.
This is the gap leaders should worry about most, because it’s invisible on a dashboard. The policies are written, the box is ticked, and the actual behaviour quietly routes around all of it.
2. Shadow AI has already arrived — governance hasn’t
Only 15% reported clear AI policies that people actually follow. The rest split between “we have policies but I know people are using AI tools on the side” (the single most common answer) and “we don’t really have policies — it’s the Wild West.” AI adoption has outrun AI governance almost everywhere, and security teams know it. For most organisations this is the fastest-moving exposure on the list, and the one with the least mature controls around it.
3. The call is coming from inside the house
Asked to finish the sentence “The person most likely to cause a breach at my company is…”, 56% named a well-meaning employee having a bad day — and a striking 31% named their own CEO or senior leadership. When we asked separately about the single biggest risk right now, “your own employees (not malicious — just human)” topped the list at 38%, followed by lack of resources and, again, “leadership who think they’re exempt from the rules.”
The threat actor in the headlines is external. The threat actor in these answers is internal, ordinary, and often senior. Awareness, culture and leadership accountability — not another tool — are where respondents see the exposure.
4. Ransomware readiness is mostly a feeling
Nearly half (46%) chose “I think so, but not fully confirmed” — the answer of someone who has a plan they’ve never truly tested. A further 38% were openly unsure or certain they weren’t ready. Confidence here is largely untested confidence, which is exactly the kind that fails on the day it’s needed. The cheap, high-value move this exposes: actually rehearse the incident, don’t just document it.
5. Compliance is quietly standing in for security
Two-thirds of respondents (67%) hold at least one certification, and ISO 27001 is the clear centre of gravity — 18 organisations already hold it and 60% are working towards or considering it. But the survey also exposed how much of that effort is aimed at the auditor rather than the attacker.
- 19% have recommended or signed off a security control they didn’t personally believe was necessary — because an auditor or client required it, or to cover themselves politically.
- Only 15% said their security spend is entirely risk-driven. A fifth (21%) admitted they genuinely don’t know how much of their spend exists to satisfy auditors and clients rather than to reduce real risk.
Certification is valuable — but these answers are a reminder that a framework is a floor, not a finish line. When the certificate becomes the goal, spend drifts toward what’s auditable instead of what’s dangerous.
6. What gets said to clients isn’t always what’s true
Most people don’t lie outright; they shade. “Framing and wording” was the common refrain, with a handful admitting they’d been pressured into it. The same instinct shows up internally: 31% have seen a security concern quietly swept under the carpet, and 27% believe an incident at their company has been downplayed or hidden. The market runs on security assurances; these answers suggest a meaningful share of them are optimistic at best.
7. Nobody feels safe — and nobody thinks they’re too small to hit
The “we’re too small to be a target” myth is dying: 71% said they’ve never believed it, and most who once did have abandoned it. Yet only 10% feel they’ve genuinely got their posture handled. When professionals read about a breach in the news, the most common honest reaction was “That really could have been us” (46%), and another 23% immediately wondered what the breached company wasn’t telling anyone. The bravado is gone. What’s left is a clear-eyed, slightly anxious realism — arguably the healthiest mindset in security.
In their own words
The free-text answers were the rawest part of the survey. Asked for the most dangerous thing they’d ever witnessed, respondents described governance failures far more often than technical ones:
“They gave me a CISO-type title, but only so they could use my signature on documents. A penetration test found the equivalent of a one-metre hole in the front door. Two months later, nothing had been remediated — the official explanation was ‘it’s not a priority.’ When I refused to downplay it, they chose not to renew my contract.”
— Survey respondent, on accountability without authority
“Using the AD Domain admin credentials — not changed for 15 years — in a plain-text login script to map network drives.”
— Survey respondent
“PGP private/public keys printed as part of an IT disaster-recovery plan — and published as a public document online.”
— Survey respondent
“Shared passwords by finance and C-level on personal devices, copying corporate data in and out over WhatsApp.”
— Survey respondent
Asked, by contrast, what tools they genuinely recommend, the answers were refreshingly unbranded and practical — EDR and managed detection (CrowdStrike, Arctic Wolf, SenseOn, Darktrace, Bitdefender), visibility and monitoring (Tenable, Nanitor, Wazuh, Splunk, Zabbix), and Microsoft Purview for data security. One respondent’s advice cuts through the noise: “Whatever is necessary. Everyone has a different need and therefore a different solution.”
What to take from this
Strip away the individual statistics and the same message keeps surfacing: the dangerous gap in most organisations isn’t a missing tool or an unsigned certificate. It’s the distance between the security people perform and the security they practise.
Three places that gap is widest — and most fixable:
- Close the say–do loop. If 71% of people route around your policies, the policies are the problem. Design controls people can actually live with, and measure adherence, not just existence.
- Govern AI now, not later. Your staff are already using these tools. A clear, usable policy beats a perfect one that arrives next year.
- Test the things you claim. Rehearse the ransomware response, pressure-test the client assurances, and make sure your certification spend is buying down real risk — not just producing evidence.
The professionals in this survey already know where the bodies are buried. The organisations that pull ahead will be the ones willing to hear it — and act before an incident forces the conversation.
About this survey. Based on 52 anonymous responses from security, IT, compliance and executive professionals, collected via an online questionnaire. Percentages are rounded to the nearest whole number and, unless stated, are calculated against all 52 responses. Figures are directional given the sample size. Free-text quotes are reproduced as submitted, lightly trimmed for length and clarity.