‘The challenge is keeping it a priority once the immediate pressure of an incident fades’
Cybersecurity awareness spikes sharply after a breach but rarely sticks, according to a new report.
The report surveyed 700 IT and cybersecurity leaders across the United States and Canada in July 2026, all from organizations that had experienced a breach.
Ninety-one per cent of respondents say they are confident in their organization's current cybersecurity posture, including 47 per cent who describe themselves as very confident.
Yet only eight per cent say cybersecurity becomes a permanent priority after an incident, finds ManageEngine, a division of Zoho Corporation.

Attention is similarly uneven year-round: 29 per cent say their organization maintains consistent focus throughout the year, 25 per cent say security competes with too many other priorities, 24 per cent say it gets attention mainly after incidents, and 22 per cent point to desensitization from how common incidents have become.
A third (33 per cent) say a major incident is inevitable regardless of defences, and 18 per cent say that expectation has itself reduced urgency, the report found.
Why does the urgency fade?
Eighty per cent say heightened attention lasts only one to six months after a breach, according to ManageEngine's release.
Business trade-offs help explain why: 90 per cent say business priorities take precedence over security at least sometimes, and 59 per cent say this always or often causes initiatives to be postponed. Following their most recent incident, 44 per cent made no broader structural or strategic change.
"What stands out is that organizations already know cybersecurity matters. The challenge is keeping it a priority once the immediate pressure of an incident fades," says Rajesh Ganesan, CEO of ManageEngine.
Erik Huffman, a cyberpsychology expert and researcher cited in the release, says the goal is deliberate risk management, not elimination.
"There will always be risk. The challenge is making sure organizations do not become comfortable with that risk after an incident," he says.

Ownership gaps and AI oversight
Eighty-four per cent say employees are likely to report a mistake immediately, but 83 per cent say fear of consequences still shapes how incidents are handled.
Unclear ownership was linked to delayed containment or remediation by 25 per cent of respondents, and to greater business disruption by 20 per cent — relevant for HR leaders who help define accountability once Canada's rules around reporting employee data breaches are triggered.

Among organizations using AI in cybersecurity, 67 per cent act on AI-generated recommendations without additional verification always or often, and 55 per cent say AI has made them more willing to accept cyber risk. Still, 81 per cent say AI has made decision-making easier overall, and 27 per cent credited it with strengthening detection, investigation and response.

For Canadian HR and compliance teams, the findings track with obligations already surfaced by the Canada Life breach affecting up to 70,000 people, and with Canadian HR leaders bracing for AI-fuelled change in 2026 who are being asked to weigh how much oversight new tools receive.