Organisational response:
adaptation speed, behaviour change and future investment

Real time attacks demand real-time responses. These should be deployed in tandem with human behavioural change programmes. To achieve the necessary level of protection against AI-driven attacks, organisations must combine automated machine-controlled defence with ingrained individual employee security awareness.

How organisations respond differently to cyber threats

Our survey revealed that organisations respond to cyber threats in three main ways:

  1. 36% use a combination of technical plus human and process factors.
  2. 32% mainly employ technical systems for security, incident response and recovery.
  3. 30% use an end-to-end system, combining technology, people and processes.

Which statement best reflects how your organisation defines cyber resilience, if at all?

This demonstrates that almost a third of companies don’t focus on human reliance in their cyber defence strategies, despite the aforementioned increase in social engineering attacks. At the same time, it’s encouraging to see that the majority of companies we surveyed do include human resilience as a central part of their cybersecurity approach.

How quickly organisations can adapt to AI social engineering tactics

On average, security professionals said their organisation can update overall defences in 19 days.”

AI-driven social engineering attacks evolve rapidly, adjusting language, tone and delivery in very short timeframes. The key issue is whether organisational defence systems can respond at a comparable pace. Security professionals report that their organisations can update overall defences in an average of 19 days. 

When social engineering tactics change, how quickly can your organisation do each of the following, if at all?

However, hackers do not operate in fixed review cycles. Phishing campaigns can be created and refined within hours. A 19-day adaptation cycle highlights a clear imbalance between attacker agility and organisational response.

This also introduces an important contradiction. Many organisations describe themselves as adaptive, yet their reported response timelines suggest that adaptation is still measured in weeks rather than days. If updates require significant time to deploy and validate, then adaptiveness may be procedural rather than dynamic.

It should be a case of "we have done it", rather than "we can do it". For leadership teams, the more important question may not be whether the organisation can adapt in 19 days, but whether that timeframe is strategically sufficient in a threat landscape that evolves daily.

Playbook Action:
Closing the Agility Gap

Priority 2 (Short-Term):

Rapid Simulation Deployment:

Implement the capability to transform real, reported attacks into deployable simulations in minutes or hours, not weeks.

Active Detection Layer:

Turn every employee into a sensor. Provide instant, conversational guidance at the point of risk to reduce the 19-day window.

Next: The Path to Security Culture

Unlock the The Adaptive Defence Playbook

Complete the form below to unlock the entire playbook.

Experience our products first-hand

Use our online test environment to see how our platform can help you empower your team to continuously avert cyber threats and keep your organization secure.

The Forrester Wave™ Strong Performer 2024: Human Risk Management Solutions

This page is not available in English yet.

Diese Seite ist noch nicht in Ihrer Sprache verfügbar. Sie können auf Englisch fortfahren oder zur deutschen Startseite zurückkehren.

Cette page n’est pas encore disponible dans votre langue. Vous pouvez continuer en anglais ou revenir à la page d’accueil en français.

Deze pagina is nog niet beschikbaar in uw taal. U kunt doorgaan in het Engels of terugkeren naar de Nederlandse startpagina.

Esta página aún no está disponible en español. Puedes continuar en inglés o volver a la página de inicio en español.

Questa pagina non è ancora disponibile nella tua lingua. Puoi continuare in inglese oppure tornare alla home page in italiano.