Cybersecurity attention spikes after an incident but typically fades within months, according to a new ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada. All respondents had already experienced a breach or incident; 91% said they trust their organization’s current cybersecurity posture, while just 8% said cybersecurity becomes a permanent priority once the incident is behind them.
Cybersecurity confidence outpaces prevention
A third of respondents believe a major incident is inevitable regardless of their defenses, and a similar share accept risks they consider manageable. Known gaps often remain open until an audit or another incident forces action, and only a minority said security receives consistent attention year-round outside the aftermath of an incident. “The belief that breaches are inevitable has lowered the bar for security,” said Dr. Erik Huffman, a cyberpsychology researcher who commented on the findings. “We’ve said ‘it’s not a matter of if, but when’ for far too long. But we still have control over the security processes that directly influence the outcome.”
Urgency fades fast
Organizations do react immediately after a breach: process discussions increase, urgency spreads through teams, and technical fixes such as patching, access reviews and backup improvements are implemented. However, 80% of respondents said the heightened focus on cybersecurity lasts only one to six months before attention wanes. Close to half of organizations kept their existing structures and strategy in place after the incident, making no wider changes; a smaller share made targeted fixes aimed at the specific gap that caused the incident, and even fewer made broader, long-term changes to governance, training or escalation.
Business priorities were often the reason for backsliding: a majority said competing demands regularly cause security initiatives to be postponed or downgraded, and one in five named competing priorities as the leading factor behind their most recent incident.
Fear and unclear ownership hinder response
Most employees, respondents said, report a mistake immediately when it happens, but 83% admitted that fear of consequences influences how the incident is handled once reported. A notable share described their organization’s response as blame-focused. “Cybersecurity has had a fear-based culture for a long time, and it has created an environment many people want to avoid,” Huffman added. “Incident response should not be about who did what. The focus should be on what happened, why it happened, and who it impacts.”
Part of the problem is unclear ownership: close to one in five respondents said they were not sure whether security, IT, or business teams should be responsible for a given failure. That uncertainty carries costs, including delayed remediation, business disruption, and increased risk that data is exposed before gaps are closed.
AI recommendations often go unchecked
AI is widely used among these organizations for incident response automation, threat intelligence, penetration testing and vulnerability scanning. A large majority said AI has made decisions easier to reach, and more than half credited it with greater efficiencies or stronger security capabilities. AI has also made a majority of respondents more willing to accept cyber risk. Among organizations using AI in cybersecurity, about two in three said they often or always act on its recommendations without additional verification. “AI undoubtedly introduces new risks for organizations,” Huffman noted. “LLMs are frequent targets for attackers because of the level of trust people place in the information they receive from AI systems. We need to move from ‘trust but verify’ to ‘verify, then trust.’”
“Organizations that genuinely learn from incidents aren’t just the ones that respond quickly. They’re the ones that preserve visibility after the crisis, make risk decisions explicit, and turn temporary urgency into lasting discipline,” the researchers concluded.

