Deloitte Future of Cyber Survey 2025
Deloitte’s 5th Global Future of Cyber Survey shows cyber leaders are more mature, better funded, and increasingly aligned with business strategy, but major gaps still remain between confidence and true readiness. The report highlights five paradoxes—especially around business alignment, executive influence, vendor sprawl, breach interpretation, and budgeting stability—while showing that Frontunners consistently outperform Followers and Foundation Builders. #Deloitte #Frontunners #Followers #FoundationBuilders #CISO #ChiefArchitect

Keypoints

  • Annual cyber survey reports like this one typically begin with an executive summary, followed by the research methodology, respondent segmentation, major themes or “paradoxes,” supporting statistics, strategic recommendations, and a conclusion outlining future implications.
  • This report is built around five paradoxes that compare cyber maturity, leadership alignment, execution gaps, vendor complexity, breach trends, and budget planning to reveal where organizations are progressing and where they are still exposed.
  • The survey draws on responses from 1,058 business and technology leaders across 43 countries, 5 industries, and 23 sectors, plus interviews with 9 C-suite leaders.
  • Respondents are grouped into three categories: Frontunners, Followers, and Foundation Builders, based on their cyber readiness and implementation maturity.
  • Frontunners represent the most advanced group, scoring highest across key cyber program elements; the report says only 17% of organizations fall into this category, while 60% are Followers and 24% are Foundation Builders.
  • Overall cyber confidence is high: 85% of respondents say they are somewhat or very ready for future threats, and 54% say cyber is fully integrated into or actively being built into broader business and technology strategy.
  • Despite that confidence, the report emphasizes an execution gap: only 26% of respondents have fully integrated cyber into their broader business and technology strategy plans, showing that many organizations still struggle to move from vision to implementation.
  • Leadership support is strong in the C-suite, with cyber viewed as a priority at the highest levels; however, respondents say that influence does not always extend deeply enough into day-to-day business operations and technology decision-making.
  • The report says 90% of Frontunners have strong relationships with the C-suite and board, while 61% of Foundation Builders and 72% of Followers report the same, reinforcing that governance quality tracks closely with maturity.
  • A notable theme is the need for better role alignment, especially between CISOs and Chief Architects, so security is embedded into enterprise architecture, application design, and operational workflows rather than added later as a control layer.
  • Business alignment remains a recurring weakness: only 28% of C-suites are deeply involved in front-end strategic cyber planning, while many respondents say cyber is still too tactical and technical rather than fully business-driven.
  • Third-party cyber risk management is underused; only 25% of respondents have implemented these capabilities to a large or very large extent, even though supply-chain and partner exposure are increasingly important.
  • Vendor sprawl is a major concern, with many organizations adding new providers rather than consolidating, despite the fact that 74% expect the number of cyber partners to remain stable or rise in the next year.
  • The report notes that 38% of respondents have 11–20 cyber partners and 29% have 21 or more, showing that tool and vendor complexity is already substantial for many organizations.
  • Growth in vendor count is being driven by AI, regulatory needs, and the search for more integrated cyber platforms, but the report warns that more tools do not automatically mean better outcomes.
  • In the breach section, 78% of CISOs say their organizations experienced at least one breach in 2024, down from 90% in 2023, yet the report warns against assuming lower breach counts equal lower risk.
  • Among those breached, 58% of frontunners said they felt the same impact from incidents as followers, and the report suggests this may reflect stronger detection and response rather than reduced attacker pressure.
  • The survey shows a “containment” trend: organizations are increasingly focused on rapid detection, isolation, and eradication, with 62% saying they can contain incidents as quickly as possible to reduce broader damage.
  • Threats remain highly familiar and persistent, with ransomware, malware, and data exfiltration continuing to rank among the most common concerns, even as threat tactics evolve.
  • Budgeting is comparatively stable, with 85% of respondents expecting cyber budgets to increase or remain steady over the next year, and 88% planning to increase or maintain funding over the next 12 months.
  • Cyber funding is becoming more strategic: 35% of cyber budget is allocated one year beyond the current cycle, and 26% two years beyond it, suggesting a shift toward longer-term planning.
  • Even so, most budgets still remain annualized; the report notes that 61% of cyber budget is tied to the current year, which limits flexibility for multi-year transformation and larger platform shifts.
  • The report’s key takeaway is that cyber leaders must reconcile paradoxes instead of treating them as contradictions—combining confidence with realism, executive support with operational depth, and stable budgets with more agile planning.
  • Frontunners are consistently presented as the benchmark group because they have stronger readiness, better integration with the business, more mature governance, and more effective use of resources than Followers or Foundation Builders.
  • Overall, the report argues that the next stage of cyber maturity depends less on adding more tools and more on improving architecture, governance, cross-functional alignment, and disciplined execution across the enterprise.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)

Download Report from Github