
Absolute Security published The State of Enterprise Cyber Resilience in early January, part 1 of a multi-part e-book series on “the resilient CISO.” The findings are drawn from a 750 respondent survey across the US (500) and UK (250) in November 2025. To take the survey, respondents had to work at organizations with 5,000 or more employees.
The key findings of interest:
- Cyber resilience has become an essential mandate of the CISO’s role. Previously, the CISO role focused on security and risk. Now, 72% say it requires leading their organization’s ability to recover continuity following a cyberattack that stops business operations. 61% of respondents say the board of directors and other C-suite members expect zero breaches and ransomware incidents – and yet 55% say this elevated expectation was not met during 2025 (20% were unsure), and 0% of CISOs said they can currently recover from a cybersecurity incident within a day. In other words, there’s lots of room to improve.
- “Resilience” risks becoming a meaningless buzzword. A clear sense of what’s in / what’s not is essential if it’s to be operationalized within enterprises. Absolute recommends the use of the NIST definition for consistency.
- More than half expect costly and significant downtime from a cyberattack in the next 12 months. Ransomware’s the largest threat, with supply chain threats in second place. The expectation of CISOs of the likelihood of attacks / incidents over the next 12 months is counter to the expectation of boards and other C-suite members. There’s a misalignment here which needs correction.
- The CrowdStrike incident of 2024 highlighted the problem of security software failure, with a double whammy attached. To quote (page 11): Security leaders now face increased pressure, as it was the trusted CISO solution that triggered the crisis. This incident has made it clear: resilience is not just about stopping attacks but also about preparing for the unexpected failure of core security software. CISOs have recognized the importance of including software failures among their top operational risks.
For more, get a copy from the Absolute Security website. We’re hoping to see Part 2 in the next month or so.

