UK organizations are reporting stronger cyber resilience structures, but still show persistent weaknesses in people, governance, and adaptive learning, according to new research from ManageEngine.
The study, Owning Operational Resilience in 2026, based on a survey of 305 UK executives, IT leaders, and security professionals, found that cyber incidents are now a routine business reality. Some 77% of UK organizations experienced at least one cyber incident or attack in the previous 12 months, with phishing and social engineering, malware and ransomware, and data breaches among the most common incident types. The impact was often wider than a single device or user: 54% of incidents affected multiple devices within a team or function, while 27% spread across multiple systems or departments.
The findings suggest that many organizations have put formal resilience processes in place: 96% conducted a post-incident review after an attack, 94% had clear cyber incident responsibilities, and 97% reported having a backup and recovery strategy. However, the report questions whether these structures are translating into long-term improvement. While 46% implemented targeted changes after incidents and 37% adopted broader improvements, 13% resolved incidents without changing strategy.
Governance also remains uneven. IT continues to carry primary responsibility for both prevention and response, while management involvement is often reactive. Only 33% described senior management involvement in incidents as very high and continuous, compared with 43% where involvement was high only during crises.
People pressures are another concern: 60% of respondents said pressure on IT and security teams had increased over the past year, while the leading challenge was the skills gap created by rapidly evolving threats.
Looking ahead, AI-powered attacks were identified as the biggest risk, cited by 43%. Investment priorities now include AI and advanced threat preparedness, cyber governance, monitoring and detection, and training.






