![]()
ManageEngine, a division of Zoho Corporation and a leading provider of enterprise IT management solutions, today released The Psychology of Being Breached, a new report examining the human and organizational factors that influence cybersecurity decisions across U.S. and Canadian organizations.
The findings are based on a survey of 700 IT and cybersecurity leaders whose organizations have experienced a cybersecurity incident or breach. The results show that confidence does not always translate into sustained action. Organizations know the risks they face, but security can quickly lose ground once the immediate pressure of an incident passes and other business priorities take over.
Key findings include:
- Confidence does not guarantee lasting focus: 91% of respondents are confident in their organization’s cybersecurity posture, yet just 8% say cybersecurity becomes a permanent priority after an incident.
- Post-incident urgency has a short shelf life: 80% say heightened attention to cybersecurity lasts only one to six months after an incident.
- Business priorities regularly push security aside: 59% say business priorities always or often cause security initiatives to be postponed or downgraded.
- Fear impacts incident handling despite swift reporting: 84% say employees are likely to report a cybersecurity mistake immediately, while 83% say fear of consequences influences how cybersecurity incidents are handled.
- AI adoption is outpacing verification: Among organizations using AI in cybersecurity, 67% always or often act on AI-generated recommendations without additional verification, including 29% that always do so.
“What stands out is that organizations already know cybersecurity matters. The challenge is keeping it a priority once the immediate pressure of an incident fades,” said Rajesh Ganesan, CEO at ManageEngine. “That means being clear about who owns the follow-up, what needs to get done and when, and making sure those commitments don’t disappear when the next business priority takes over.”
When Cyber Risk Becomes Business as Usual
Experiencing an incident does not always lead to sustained vigilance. A third (33%) of respondents believe a major cyber incident is inevitable regardless of their defenses, 26% say they accept risks they consider manageable, and 23% say known risks often remain unresolved until an incident or audit creates urgency.
The response after an incident shows a similar pattern. Organizations commonly make immediate technical or operational fixes, but 44% made no structural or strategic change following their most recent incident.
“Cybersecurity is not about designing a system that is 100% secure, because that simply does not exist,” said Dr. Erik Huffman, cyberpsychology expert and researcher. “There will always be risk. The challenge is making sure organizations do not become comfortable with that risk after an incident. They need to understand what level of insecurity is acceptable based on their risk tolerance and continually reassess it, rather than allowing attention to fade once the immediate threat has passed.”
Culture and accountability can also affect what happens once an incident is reported. Eighty-four percent of respondents say employees are likely to report a cybersecurity mistake immediately, while 83% say fear of consequences influences how cybersecurity incidents are handled. One-quarter (25%) say unclear ownership can delay containment, remediation, or other critical actions.
AI Is Reshaping How Organizations Evaluate Risk
AI is now widely used in cybersecurity, but organizations are still working through how much oversight its recommendations require. Among organizations using AI in cybersecurity, two-thirds (67%) always or often act on AI-generated recommendations without additional verification, and 29% say they always do.
More than half (55%) say AI-enabled security tools have made their organization more willing to accept cyber risk. At the same time, 24% say AI has introduced new risks requiring significant changes to their cybersecurity strategy, while 81% say AI has made cybersecurity decision-making easier overall.
The full report, The Psychology of Being Breached, is available for download here.
Survey Methodology
In July 2026, ManageEngine commissioned independent market research agency Censuswide to survey 700 full-time IT and cybersecurity leaders across the United States and Canada, all of whom had their employer experience a cybersecurity incident or breach. The sample included 500 respondents in the United States and 200 in Canada, evenly split between mid-sized organizations and large enterprises.
About ManageEngine
ManageEngine is a division of Zoho Corporation and a leading provider of IT management and security solutions for organizations across the world. With a powerful, flexible, and AI-powered digital enterprise management platform, we help businesses get their work done from anywhere and everywhere—better, safer, and faster. To learn more, visit www.manageengine.com.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260910829103/en/
Media gallery
