
Optiv Report Finds Increased Cybersecurity Incidents, Strategic Budget Shifts as Organizations Combat Evolving Threat Landscape
Download Optiv's 2025 Cybersecurity Threat and Risk Management Report: https://www.optiv.com/insights/discover/downloads/2025-cybersecurity-threat-and-risk-management-report
The report also highlights a notable shift in how organizations determine their cybersecurity budgets, with 67% now using risk and threat assessments to inform budget decisions, up from 53% in 2024. This move toward data-driven decision-making comes as organizations increasingly turn to managed security service providers (MSSPs), with outsourcing to MSSPs jumping from 47% in 2024 to 58% in 2025, particularly for cloud security guidance.
"The data clearly shows a concerning trend: despite increases in cybersecurity budgets and resources, organizations continue to face more frequent attacks," said John Hurley, Optiv's chief revenue officer. "What's promising is the shift toward more strategic, data-driven approaches to budget allocation and the growing adoption of MSSPs to extend capabilities, particularly as organizations work to better understand their security vulnerabilities within the threat landscape."
Additional key findings include:
AI and Machine Learning Adoption Accelerating: Forty-six percent of respondents say their organizations use AI/ML to prevent cyberattacks, with 88% of these respondents incorporating generative AI at some level. The primary drivers for AI/ML adoption are improving operational efficiency (41%) and maintaining competitive advantage (40%).
Automation Transforming Response Times: Fifty-seven percent of respondents report automation has reduced the time to respond to vulnerabilities, with 34% seeing significant improvements, highlighting automation's transformative role in cybersecurity operations.
Vulnerability Management Challenges: Nearly three in four respondents (74%) identify a lack of understanding of every potential source of vulnerability as their biggest challenge to effective vulnerability management.
SASE and SOAR Implementations Growing: Sixty-six percent of respondents say their organizations have fully or partially implemented Secure Access Service Edge (SASE), while 72% continue to significantly or moderately use Security Orchestration, Automation and Response (SOAR) to reduce cyber threats.
Effectiveness of Cybersecurity Incident Response Plans (CSIRPs): Fifty-one percent of respondents say their organizations have a CSIRP applied consistently across the entire enterprise, up from 46% in 2024. The effectiveness of CSIRPs in minimizing the consequences of cybersecurity incidents has increased from 50% of respondents in 2024 to 57% of respondents in 2025.
"Our independent research for Optiv reveals that organizations are making strategic investments in technology, processes and people to combat increasingly sophisticated threats," said Dr. Larry Ponemon, chairman and founder of the Ponemon Institute. "The growing adoption of AI, machine learning and automation technologies signals a significant shift in how organizations approach cybersecurity defense, focusing on both prevention and rapid response capabilities."
Findings from Optiv's report are based on responses from 620 U.S.-based IT and IT security practitioners familiar with their organizations' strategies to manage threats and risks.
For the latest news and updates from Optiv, visit https://www.optiv.com/newsroom.
Optiv Security: Secure greatness. ®
Optiv is the cyber advisory and solutions leader, delivering strategic and technical expertise to nearly 6,000 companies across every major industry. We partner with organizations to advise, deploy and operate complete cybersecurity programs from strategy and managed security services to risk, integration and technology solutions. With clients at the center of our unmatched ecosystem of people, products, partners and programs, we accelerate business progress like no other company can. At Optiv, we manage cyber risk so you can secure your full potential. For more information, visit www.optiv.com.
About Ponemon Institute:
Ponemon Institute is dedicated to independent research and education that advances responsible information and privacy management practices within business and government. Our mission is to conduct high quality, empirical studies on critical issues affecting the management and security of sensitive information about people and organizations.
We uphold strict data confidentiality, privacy and ethical research standards. We do not collect any personally identifiable information from individuals (or company identifiable information in our business research). Furthermore, we have strict quality standards to ensure that subjects are not asked extraneous, irrelevant or improper questions.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


CTV News
4 days ago
- CTV News
Costs of data breaches dropping globally but not in Canada: IBM study
The uOttawa-IBM Cyber Range at the University of Ottawa, in Ottawa, is seen on Wednesday, May 22, 2024. THE CANADIAN PRESS/Justin Tang TORONTO — A new report shows the global average cost of a data breach dropped for the first time in five years — but not in Canada. The average cost of a breach between March 2024 and February 2025 was $6.4 million, down from $6.6 million a year earlier, showed research released Wednesday from technology giant IBM and the Ponemon Institute, a U.S.-based cybersecurity research centre. While global costs are decreasing because of shorter breach life cycles, expenses related to these attacks have risen in Canada, IBM Canada's security delivery leader Daina Proctor said. The average cost of a Canadian breach soared 10.4 per cent to $6.98 million in the latest year studied from $6.32 million the year before. Canada's average is higher because detection and escalation costs, which cover forensic investigators, regulatory responses, legal counsel and crisis communications, have risen, Proctor said. Detection costs now average $470,000 in Canada, while post-breach recovery costs hover around $270,000. At the same time, Canada is facing rising costs because of 'slower adoption of AI-driven defences and governance gaps,' Proctor said in an email. In the last year, cybersecurity issues have been reported at Nova Scotia Power, the College of New Caledonia in Prince George, B.C., and PowerSchool, the maker of education software used by many Canadian schools. Breaches can be expensive because they can be difficult to detect and assessing and recovering from them can be tedious, time-consuming work requiring many professionals and sometimes, interruptions for customers and workers. Most countries have seen fees associated with a breach drop because it's taking less time to investigate breaches. Yet several countries including Canada bucked that trend. IBM and Ponemon's research showed the cost of data breaches also rose in the U.S., India, the Association of Southeast Asian Nations and Benelux — the economic union of Belgium, the Netherlands and Luxembourg. Average breach costs in the United States reached a record US$10.22 million, an increase of nine per cent from last year. When it analyzed 600 organizations impacted by data breaches, it found the most expensive attacks hit the health care sector, followed by the financial, industrial and energy industries. In many instances, hackers made use of shadow artificial intelligence — when workers use AI without employer approval or oversight. 'Shadow AI has become one of the biggest blind spots for organizations today,' Proctor said. 'Employees are adopting AI tools to boost their productivity, but without oversight, they are inadvertently creating vulnerabilities.' Shadow AI systems often process sensitive data and interact with external systems companies have no control over. 'Once attackers exploit these gaps, the cascading effects can expose entire systems and supply chains to significant breaches,' Proctor said. Twenty per cent of the organizations studied said they suffered a breach due to security incidents involving shadow AI. Global organizations with high levels of shadow AI said use of this technology added $967,011 to the average breach price tag compared to those that had low levels of shadow AI or none. Incidents involving shadow AI also resulted in more personal identifiable information and intellectual property being compromised. To address the risks associated with shadow AI, Proctor said companies need to give workers more approved AI tools and conduct regular audits to find gaps in their offerings and employee compliance. This report by The Canadian Press was first published July 30, 2025. Tara Deschamps, The Canadian Press


Winnipeg Free Press
4 days ago
- Winnipeg Free Press
Costs of data breaches dropping globally but not in Canada: IBM study
TORONTO – A new report shows the global average cost of a data breach dropped for the first time in five years — but not in Canada. The average cost of a breach between March 2024 and February 2025 was $6.4 million, down from $6.6 million a year earlier, showed research released Wednesday from technology giant IBM and the Ponemon Institute, a U.S.-based cybersecurity research centre. While global costs are decreasing because of shorter breach life cycles, expenses related to these attacks have risen in Canada, IBM Canada's security delivery leader Daina Proctor said. The average cost of a Canadian breach soared 10.4 per cent to $6.98 million in the latest year studied from $6.32 million the year before. Canada's average is higher because detection and escalation costs, which cover forensic investigators, regulatory responses, legal counsel and crisis communications, have risen, Proctor said. Detection costs now average $470,000 in Canada, while post-breach recovery costs hover around $270,000. At the same time, Canada is facing rising costs because of 'slower adoption of AI-driven defences and governance gaps,' Proctor said in an email. In the last year, cybersecurity issues have been reported at Nova Scotia Power, the College of New Caledonia in Prince George, B.C., and PowerSchool, the maker of education software used by many Canadian schools. Breaches can be expensive because they can be difficult to detect and assessing and recovering from them can be tedious, time-consuming work requiring many professionals and sometimes, interruptions for customers and workers. Most countries have seen fees associated with a breach drop because it's taking less time to investigate breaches. Yet several countries including Canada bucked that trend. IBM and Ponemon's research showed the cost of data breaches also rose in the U.S., India, the Association of Southeast Asian Nations and Benelux — the economic union of Belgium, the Netherlands and Luxembourg. Average breach costs in the United States reached a record US$10.22 million, an increase of nine per cent from last year. When it analyzed 600 organizations impacted by data breaches, it found the most expensive attacks hit the health care sector, followed by the financial, industrial and energy industries. In many instances, hackers made use of shadow artificial intelligence — when workers use AI without employer approval or oversight. 'Shadow AI has become one of the biggest blind spots for organizations today,' Proctor said. 'Employees are adopting AI tools to boost their productivity, but without oversight, they are inadvertently creating vulnerabilities.' Shadow AI systems often process sensitive data and interact with external systems companies have no control over. 'Once attackers exploit these gaps, the cascading effects can expose entire systems and supply chains to significant breaches,' Proctor said. Twenty per cent of the organizations studied said they suffered a breach due to security incidents involving shadow AI. Global organizations with high levels of shadow AI said use of this technology added $967,011 to the average breach price tag compared to those that had low levels of shadow AI or none. Incidents involving shadow AI also resulted in more personal identifiable information and intellectual property being compromised. To address the risks associated with shadow AI, Proctor said companies need to give workers more approved AI tools and conduct regular audits to find gaps in their offerings and employee compliance. This report by The Canadian Press was first published July 30, 2025.

National Post
24-07-2025
- National Post
ISG Names GTT a Leader for SASE and Managed SD-WAN in U.S. and U.K.
Article content New ISG reports highlight rising demand for integrated networking and security solutions that span enterprise infrastructures. Article content Article content , a leading networking and security as a service provider for multinational organizations, announced it has been named a Secure Service Access Edge (SASE) and Managed SD-WAN Leader in the United States and in the United Kingdom by the Article content Information Services Group Article content (ISG), a leading technology research and market intelligence advisory firm. 'Leaders,' as recognized by ISG, stand out for their comprehensive product and managed service offerings, strength in innovation and market competitiveness. The 2025 ISG Provider Lens™ Network – Software-Defined Solutions and Services reports provide a detailed analysis of the markets for managed SD-WAN services, SD-networks transformation services, SASE and edge technologies and services, assessing over 150 U.S. providers and 40 U.K. providers. ISG offers strategic insights for technology and procurement leaders evaluating security and networking investments, including how providers support the shift to comprehensive SASE frameworks. The reports also assess managed SD-WAN offerings, with a focus on flexible solution management and modern contracts. Article content In addition to the 'Leader' recognition in the U.S. and U.K. Quadrants for Managed SD-WAN and SASE, GTT has been named a ''Rising Star' in the SD-Networks Transformation Services category in both regions for its advisory, consulting and implementation services. Article content 'Aligned with the shift towards Zero Trust, our research across the U.S. and U.K. shows rising demand for integrated security solutions that protect the entire enterprise network infrastructure,' said Dr. Kenn D. Walters, Lead Analyst, ISG. 'GTT delivers powerful and advanced SASE and SSE solutions with vendor-agnostic, client-specific delivery supported by its Envision platform. Customers benefit from GTT's customized managed SD-WAN services and its global Tier 1 backbone that ensures secure, high-performance connectivity from core to edge. GTT's leading advisory professionals further support a fully comprehensive range of customer requirements.' Article content ISG highlights GTT's flexible, technology-agnostic SASE and SD-WAN solutions, powered by the GTT Envision platform that enables seamless network connection, orchestration, virtualization and automation. The firm notes that EnvisionDX, a digital gateway, delivers control for enhanced application performance and streamlined network policy management. ISG further highlights GTT's observability-driven governance, which helps enterprises leverage telemetry and AI-driven insights to identify optimization opportunities across legacy and modernized infrastructure. Article content 'GTT is proud to be recognized by ISG for our ability to help CIOs standardize or diversify their architectures without sacrificing feature parity, visibility or policy control,' said Tom Major, Senior Vice President Product Management and Technology, GTT. 'With our global network reach and tightly integrated security, networking and cloud advisory services, we work with our customers to drive business success and deliver greater technology together.' Article content GTT is a leading networking and security-as-a-service provider for multinational organizations, connecting people and machines to data and applications — anywhere in the world. We serve thousands of organizations, bringing together the right people, partners and technology to reduce the burden on IT teams and solve the most pressing networking and security challenges. Built on our top-ranked global Tier 1 network, the GTT Envision platform provides visibility, insights, orchestration and control, enabling customers with consumable solutions to achieve business missions and meet ongoing demand when, where and how needed. Our portfolio includes SASE, SD-WAN, security, internet, voice and other connectivity options, complemented by a suite of professional services and exceptional sales and support teams in local markets around the globe. We partner with our customers to deliver Greater Technology Together. Article content Article content Article content Article content Article content Contacts Article content Americas: Article content Article content Mary Lynn Heath, GTT Article content Article content +1-646-214-4078 Article content Article content Article content Europe: Article content Article content Siria Nielsen, GTT Article content Article content +31-6-2835-4259 Article content Article content Article content GTT Investor Relations: Article content Article content Charlie Lucas, GTT Article content Article content Article content