Most Organizations Take Six Months or More to Deploy New Security Controls, Survey Finds
What Happened — Cisco surveyed 8,000 security professionals across 30 markets. Only 21 % of respondents said they could switch on a new security control within six months after budget approval, and just 8 % landed in the top‑performing group. Internal friction—procurement delays, unclear ownership, and siloed data—was identified as the primary blocker.
Why It Matters for Trust & Control Assurance
- Delayed control rollout hampers continuous control monitoring and the ability to produce timely, defensible audit evidence.
- Unclear escalation paths create gaps in incident response, weakening the organization’s control‑assurance posture.
- Fragmented data collection prevents a unified view of control effectiveness, a core requirement of robust governance programs.
Who Is Affected – Enterprises of all sizes and sectors, especially regulated industries (finance, healthcare, cloud services) that must demonstrate control effectiveness to auditors and regulators.
Recommended Actions
- Formalize decision‑rights and escalation procedures for any new security control.
- Consolidate security‑related data into a single repository to streamline evidence collection.
- Deploy automated playbooks that handle the first ten minutes of an incident, reducing reliance on manual hand‑offs.
Source: Help Net Security – Cisco Cybersecurity Survey
Technical Notes – The report does not describe a specific vulnerability or exploit. It highlights governance, change‑management, and data‑integration challenges that impede rapid control deployment in the AI‑era threat landscape. Source: same as above