Skip to content
feed: live
>_ 0dayNews
threat intel
Analysis

73% Not Ready: The IR Gap Is Coordination, Not Tools

New IR readiness research finds most security teams have the plans, tools, and staff — but still lack the coordination and exec alignment that determine whether any of it works under pressure.

73% Not Ready: The IR Gap Is Coordination, Not Tools
Image: 0dayNews / 0dayNews Editorial · All rights reserved
kilobaud Dave "Kilobaud" Ferris · Published · 3 min read

Vanson Bourne surveyed 600 senior IT security decision makers and published the results this week through The Hacker News: 73% of organizations say they are not fully ready for a major cyberattack. The survey is titled “The State of Incident Response Readiness 2026,” conducted in January.

The number itself isn’t the interesting part. What’s interesting is what the same survey says those organizations do have: incident response plans, security tools, and technical teams. What they lack is coordination, visibility, and executive alignment.

That distinction matters. “We don’t have tools” is a procurement problem. “We have tools but they don’t work together when it counts” is an organizational problem, and it’s considerably harder to solve with budget.

What recent incidents show

This year’s record is instructive. When attackers hit more than 30 Minnesota water utilities in a coordinated operational technology attack last weekend, the response required activating statewide cybersecurity infrastructure — because the individual utility coordination wasn’t sufficient. Each plant had some form of control system. The collective response was improvised under pressure.

The OpenAI agent breach that expanded into Hugging Face and four other services took four days to scope fully. Detection happened. Containment coordination across multiple organizations — and across organizational boundaries that hadn’t anticipated this particular kind of breach — took longer. That’s not a tool failure.

The Q2 IR trends from Talos reinforce the pattern: attackers are increasingly living off legitimate remote management tools rather than deploying custom malware precisely because defenders’ coordination around “suspicious process” alerts is better than their coordination around “legitimate tool doing suspicious things.” The detection gap isn’t in the endpoint agent. It’s in what happens after the alert lands.

The rehearsal problem

IR plans that have never been tested under realistic conditions share a consistent failure pattern: they specify the right actions in the wrong order, with authority assigned to people who don’t know they have it until the moment arrives. The plan gets written when the team is calm and structured. It gets executed when neither of those conditions applies.

The 27% who feel ready — that figure probably means something real. The distinguishing factors, consistently, are rehearsal frequency and decision-authority clarity. Someone needs to know, without making a phone call, what they are authorized to do at 2am on a federal holiday. That sounds like a small thing. It is not a small thing.

“Executive alignment” in this context means roughly: when the IR lead says “we need to take this system offline,” the executive on call says yes or no in ten minutes, not four hours after three escalation emails and a briefing document. The slow loops are usually not technical. They’re organizational.

What to do with 73%

If your organization is in the 73%, the survey finding isn’t useful as a benchmark — it’s useful as a prompt to ask a specific question: when was the last time you actually ran a tabletop that ended with a decision someone had to make under ambiguous information? Not a scenario where the answer was obvious by the end of slide 12. A scenario where someone in the room had to commit to an action with incomplete data, and the exercise kept going so they could see the downstream effect.

That’s the gap the survey is measuring, whether it calls it that or not. Coordination and executive alignment aren’t soft skills — they’re the infrastructure layer underneath all the other infrastructure, and it turns out they atrophy the same way everything else does when it doesn’t get used.

Sources: The Hacker News, “The State of Incident Response Readiness 2026,” Vanson Bourne (January 2026, published July 2026).

Found this useful? Share it.