Only 8 Percent of Firms Meet Top Threat Standards
New research shows that the vast majority of organizations remain in reactive or early stages of defense maturity.
Updated on Sept. 30, 2026 in Cybersecurity

Live Poll
Do you trust that major organizations are adequately prepared to defend against current cyber threats?
Cisco has released research detailing the security maturity of 8,000 global professionals, finding that only 8 percent of organizations reached the highest 'relentless defender' tier. The remaining organizations are split between established and reactive security postures.
Why it matters
This report highlights a significant gap in organizational security readiness, underscoring how most companies struggle to move beyond reactive threat mitigation. The findings illustrate a systemic vulnerability in the current cybersecurity landscape.
Cisco assigned a defense score to 8,000 security professionals to categorize organizational maturity. The data shows 39 percent qualify as established defenders, leaving the majority in lower-tier categories.
The players
Cisco
A global networking and cybersecurity firm that develops enterprise infrastructure, security software, and threat intelligence services.
The details
To measure threat detection efficacy, Cisco developed a scoring system that quantifies how organizations respond to security incidents. The method sorts entities into four maturity tiers based on their ability to handle threats, ranging from the most capable, termed 'relentless defenders,' down to the most passive groups. This categorization provides a standardized benchmark to track how security teams transition from reactionary triage to proactive threat management.
Timeline
September 30, 2026: Cisco published its latest threat detection research.
The Tech Race
This assessment aligns with the ongoing industry effort to standardize metrics within the Cisco Cybersecurity Readiness Index framework. It marks a continued push to move the sector beyond anecdotal security claims toward data-driven defense benchmarks.
Security teams should use these tiers to audit their internal response workflows against the established criteria for higher maturity levels. These findings are currently available for review by IT and security leadership looking to align their posture with global defense benchmarks.
The takeaway
The data suggests that the transition from reactive to relentless defense remains a significant hurdle for most modern enterprises. Readers should look for follow-up industry benchmarks from Cisco to see if organizations shift their maturity scores in future reporting cycles.
Further reading
For more on the current state of industry defense standards, visit the Cybersecurity section.
Live Poll
Do you trust that major organizations are adequately prepared to defend against current cyber threats?







