Binalyze has released a new report that examines enterprises’ approach to cyber incident response. The research finds that every hour of delay in responding to a cyber incident costs, on average, $114,000.
With 84% of CISOs saying a successful cyberattack is now inevitable, organizations must establish effective and rapid response protocols to stop attacks that are occurring, minimise financial losses, and protect against reputational damage. Yet 79% of organizations favour cyberattack prevention over response, with budgets averaging a 2:1 ratio towards prevention ($3.02 million to $1.54 million).
Binalyze’s report surveyed 200 US CISOs and exposes major cracks in enterprise crisis management, showing how repeated missteps in responding to cyberattacks are worsening both financial and reputational damage.
Key findings show:
A clarity gap blocking simple answers
Only 50% of CISOs can answer the most basic cyberattack questions, such as: Does the attacker still have access? How did they get in? Was data stolen? And if so, what? Being able to answer these questions with confidence should be every organization’s priority.
Repeating mistakes of the past
65% of CISOs admit that their organizations haven’t always learned the right lessons following cyberattacks. In fact, 75% say once a cyberattack has happened, there’s no guarantee that the exact same attack won’t succeed again.
The attack aftermath
70% of organizations say they struggled to remediate or recover from an attack in the past year. Additionally, 61% have been punished by regulators because of a security breach, and 56% have been denied cyber insurance payouts, due to being unable to demonstrate, through sufficient insight, that the necessary security controls were in place.
“With cyberattacks now inevitable, the real test for organizations is how fast they can respond and recover,” says Lee Sult, Chief Investigator at Binalyze. “Rapid cyber response encompassing in-depth cyber scene investigation is essential to identify, isolate, and eliminate threats while keeping regulators and insurers informed. But this relies on visibility, and 75% of CISOs feel they are missing key information every time there is a breach. With clear, actionable insight into IT environments, organizations can locate attackers, contain damage, and regain control before the impact spirals.”
The need for speed
Rapid response is critical when cyber breaches or attacks occur. Every minute gives attackers more time to cause damage or hide their tracks, and organizations less time to understand the breach, update stakeholders, and warn the wider community of new threats.
Yet limited visibility across security frameworks continues to hinder effective incident management, leading to inconclusive investigations and escalating costs. In fact, 88% of CISOs agree that faster response and investigation would significantly reduce breach costs. But awareness isn’t enough, with only 40% of CISOs reporting confidence in their organization’s crisis management framework.
Rapid, forensic investigation is key for understanding attacks and attackers, helping organizations respond to breaches before unnecessary financial and reputational damage is done. Currently, organizations take, on average, 8.6 hours to bring forensics into play.
“The less an organization understands an attack, the harder it is to recover, and the harder it is to learn any lessons,” says Sult. “True resilience starts with visibility. Security teams that can see across their entire IT environment and deploy forensics at the earliest stage don’t just accelerate recovery – they make attackers’ lives harder. Forensics empowers teams to uncover threats and identify vulnerabilities before attackers have the chance to exploit them – enabling organizations to act decisively and bounce back quickly.” “Yet CISOs claim to have visibility over only 57% of their organization’s IT environment at any one time. This lack of visibility not only slows recovery but risks non-compliance and regulatory penalties. Swift, forensic investigation shouldn’t just be a post-mortem exercise. When deployed proactively, it becomes a weapon – a way to identify, disrupt, and deter threat actors before they strike.”






