Downtime following security incidents impacts the vast majority of organizations. An international survey of IT security leaders reveals that monitoring systems frequently fail during active attacks and highlights gaps in autonomous recovery implementation.
Operational security in modern enterprises faces growing challenges. A study conducted by Censuswide on behalf of Absolute Security among 1,000 Chief Information Security Officers (CISOs) at large enterprises in the US and the UK documents systemic hurdles in managing cyberattacks. According to the research, 85 percent of surveyed security leaders reported operational downtime following incidents such as cyberattacks or ransomware infections on their endpoints.
A primary finding of the survey concerns the functionality of control systems during an active attack. 99 percent of surveyed CISOs stated that the monitoring of endpoint activities did not function flawlessly during a security event. While monitoring tools responded to the incidents, they failed to achieve the necessary effectiveness to prevent operational downtime.
Two core components of IT security were particularly affected by disruptions: Endpoint Detection and Response (EDR) failed for 22 percent of respondents, closely followed by Data Loss Prevention (DLP) systems at 21 percent. These failures demonstrate that maintaining IT controls and accelerating post-incident recovery are critical factors in limiting financial and operational damage.
Imbalance in Security Spending Allocations
Despite the evident risks associated with downtime, IT security budgets in many organizations remain primarily focused on prevention. On average, companies allocate 53 percent of their security budget toward threat defense and 47 percent toward recovery following an attack.
However, a shift in investment priorities is emerging. Over the past year, 92 percent of CISOs were impacted by security incidents, with attack vectors evenly distributed across email, endpoints, identities, cloud infrastructure, and networks. Given this broad distribution, 83 percent of organizations plan to increase their spending on AI-powered security tools over the next 12 months.
Security leaders identified the following investment priorities:
- AI-powered security solutions (29 percent)
- Endpoint security (25 percent)
- Agent-based AI security solutions (25 percent)
Adoption Gap in Autonomous Recovery Technologies
While 88 percent of CISOs agree that autonomous recovery reduces the total cost of a security incident, implementation continues to lag. To date, only 32 percent of surveyed organizations have deployed self-healing endpoint agents.
Furthermore, the study reveals a gap between perceived control over Artificial Intelligence and actual security outcomes. Although 89 percent of security executives expressed confidence in their ability to detect and control AI usage on endpoints, 71 percent reported that sensitive corporate data was exposed through unauthorized employee AI tools during the past year. This unapproved usage represents an active risk to data stored on endpoint devices.
The survey results highlight the need for organizations to balance pure prevention strategies with operational resilience and automated recovery. In light of evenly distributed attack vectors and challenges surrounding unauthorized AI usage, resilient endpoint architectures are becoming increasingly essential.
Carolina Heyder is a business analyst and moderator with extensive experience in the German and international IT market. She has worked for many years at renowned European trade publishers such as WEKA Fachmedien, Vogel IT Medien, Springer, and Aspencore. She creates content for both web and print media and is an expert in front of the microphone and camera. Thanks to her fluency in German, English, and Spanish, as well as her Chilean roots, she brings a global and intercultural perspective to topics such as cybersecurity, artificial intelligence, digital transformation, sustainability, and other key areas of the IT sector.
