DIB Cybersecurity Maturity Report 2025

Download Full Report Survey Methodology
Message

A Word from Our CEO

Home Page_Line@2x-2
Highlights

Key Findings

77% say enhancing cybersecurity is a high priority.

66% have three or more people dedicating time to security, and 80% rate their security skill level as very high or high.

47% had four or more user accounts or emails compromised in the past year.

24% had more than ten user accounts or emails compromised, and 47% had four or more of their endpoints compromised in the past year.

54% say it would take two days or longer to respond to ransomware or a breach.

Also, 38% would take a week or more to detect a threat in their environment. 44% would not be surprised to experience an operational disruption or data theft.

57% report low to medium effectiveness in threat hunting.

Additionally, 56% report low to medium effectiveness in threat investigation and 55% report low to medium effectiveness in threat monitoring.

37% say cybersecurity-related incidents have cost their company $100,001.

Of those, 4% report that cost to be more than $500,001.

The biggest security challenge is protecting sensitive data from breaches and leaks.

They’re also challenged with implementing and maintaining compliance with regulations and keeping up with evolving cyber threat landscapes.

The biggest challenge with outsourced providers is the inconsistent quality of service.

Other challenges include being too expensive given the overall value delivered and Limited support for compliance management.

The top capability they’re looking for in a new service provider is using the latest technologies to offer robust protection against evolving threats.

They’re also looking for providers with quality staff and swift, coordinated responses to security incidents.

While 71% have started CMMC, only 17% state they are Level 2 ready.

21% are compliant with Level 1, and 17% are compliant with Level 2.