By Dan Potter
When a security breach erupts into a full-blown crisis, the post-incident review rarely asks which tool missed the warning sign first. Rather, the focus is usually on the human reaction: who made the call, on what information, and why.
Yet human response rarely gets the same billing in security strategy as the tools meant to support it. Budgets, headlines, and board attention gravitate toward detection and technical capability. The vulnerability detection capabilities of frontier AI models have only reinforced that pull, putting the spotlight firmly back on how fast and how well a system can find the problem in the first place.
These capabilities are certainly important, but they’re only part of the solution. Better discovery tools only ever change what an organization finds, not who is accountable once that finding becomes a crisis – or how they handle it.
Reassurance isn’t the same as readiness
If you could be a fly on the wall of a board meeting discussing cyber readiness, you’ll probably hear an overwhelmingly positive conversation. Immersive’s benchmark data shows that a near-universal 94% of organizations believe they’d handle a crisis well.
But when that belief is tested under realistic conditions, the picture changes sharply and we find the average decision-making accuracy in controlled crisis simulations comes out at just 22%.
The gap between confidence and capability isn’t typically due to a lack of investment and, in fact, we’re seeing record levels of engagement on skills development programmes.
Instead, the disconnect exists because most organizations are still measuring the wrong thing. Cyber skills reports are stacked with completion rates and attendance figures, both of which look reassuring in a board pack and neither of which says anything about whether a team can translate a fast-moving threat signal into a decision the business can act on.
The ability to quickly and confidently translate technical challenges in a crisis to support all layers of decision-making is one of the most important capabilities.
Yet it’s rarely the thing being measured, tracked, or reported to the people who need to know about it.
The bottleneck has moved from finding to deciding
Part of why those metrics look so reassuring is that they’re measuring a skill that the industry has spent decades perfecting: finding things. The analyst who spots the anomaly buried in months of logs to identify the pattern nobody else caught – that’s the version of capability cyber security has always known how to build and measure. Frontier AI models are now promising to almost entirely erase the time that used to take, turning what was once a multi-day investigation into a result delivered in seconds.
That shift creates a problem of its own, because faster discovery doesn’t arrive as a single clean answer. It’s more likely to be a stream: more findings, more flagged anomalies, and more suggested fixes, arriving faster than any team previously had to process them. Somebody still has to work out which of those are genuine, which are urgent, and which can be safely ignored; and doing that well under pressure is a different skill. It comes down to who can be trusted to make those calls correctly by interpreting AI signals and applying their own judgement and understanding of the business’s context.
While AI can be used to build an understanding of broader operational context, it is still imperative that security and resilience teams build bridges to the wider business to ensure that they have a common understanding of what matters most to both internal operations and stakeholders, such as end customers.
Further, before an AI-suggested fix goes near production, someone needs to have actually tested whether it holds up and know when the model’s read on a situation is wrong. None of that happens automatically just because the finding arrived faster. If anything, the sheer volume now flowing through security teams makes the judgement layer more important, not less.
Closing the gap between prevention and response
Most training budgets are still concentrated on the opening moves of an attack: getting better at spotting the breach itself, sharpening evasion detection, and hardening the front door. That’s valuable work and worth continuing, but organizations can’t afford to ignore what comes next.
With AI-powered automation taking on more of the discovery process, the opportunity now is to extend that same discipline further into the attack, into the territory of lateral movement, data harvesting, and exfiltration, where the outcome of a crisis is actually decided.
Assurance frameworks have already done the hard work of proving preventative controls are in place. Building response rehearsal on top of that foundation, testing not just whether controls exist but how a team performs once they’ve been breached, gives organizations a genuinely fuller picture of their resilience – and a stronger story to tell the board.
There are also encouraging signs of where to start. We’ve found, for example, that participation in AI-scenario training has climbed 41% among non-technical managers over the past year, evidence that appetite for this kind of readiness already exists well beyond the security function. The next step is bringing senior, experienced staff into that same standard of practice, since their judgement is exactly what a crisis needs most.
Accountability can’t be automated
Frontier AI promises to free up the time that used to go on manual discovery and enterprises now have the opportunity to reinvest it in building the decision-making capability that turns a fast finding into the right call.
Achieving this means rehearsing the parts of a crisis that often get the least attention today, the middle and aftermath of an attack. It’s also important to bring in legal, communications, and the executive team into that practice alongside the security function to strengthen those bridges between departments and build true resilience.
It also means measuring and reporting on decision accuracy under pressure, giving boards a genuinely reliable signal of readiness rather than a reassuring one.
AI has already compressed the time it takes to find a problem from days to seconds. What happens with that gift of time is still a choice. Spend it well and it builds the one capability that AI can’t hand over: the confidence to make the right call when it matters most.
The author
By Dan Potter, VP of cyber resilience, Immersive






