Deloitte’s fifth Future of Cyber Survey, based on 1,058 respondents, finds that 85% are somewhat or very confident in their organization’s cybersecurity strategy. They report strong executive sponsorship, access to funding, modern security architectures, and increasingly integrated planning. Yet the same respondents report implementing the actions that make those strategies real at a lower rate. The average gap between confidence and readiness is 15 percentage points.
Deloitte calls the five tensions it found the confidence, influence, vendor, breach, and budget paradoxes. Read together, they describe less a collection of cybersecurity problems than a problem of organizational execution. Security has become good at getting attention from senior leadership. It is less consistently embedded in the decisions, systems, relationships, and operating processes where risk actually accumulates.
Confidence has moved faster than readiness
The first paradox is the simplest. Eighty-five percent of respondents express confidence in their cybersecurity strategy, while the average implementation rate for the surveyed readiness actions is 70%. Deloitte describes the resulting 15-point difference as the confidence-readiness gap.
The details explain why the gap persists. Only 63% report implementing a Business Information Security Office, or BISO, to a large or very large extent. A BISO can act as the link between cybersecurity and business functions, translating security requirements into the work of product, operations, and other teams. Third-party cyber-risk management is also among the least implemented capabilities in the survey, with 65% reporting implementation to a large or very large extent. Workforce skills rank first among the factors respondents identify as limiting their ability to respond with agility.
None of this makes the confidence irrational. An organization can have a mature security strategy, a supportive board, experienced leaders, and better tools than it had five years ago. It can still have thousands of applications, suppliers, business processes, and employees through which that strategy has to travel.
That is the harder part of cybersecurity: turning a strategy that looks coherent from the top into thousands of decisions that remain coherent at the edge.
Cyber has a seat at the table. It needs to be in the architecture.
The second paradox makes the organizational problem more visible. Cybersecurity leaders have strong relationships with senior executives. Sixty-six percent of CISOs describe their relationship with the CEO as strong, and 76% say the same of the C-suite overall. But the relationship weakens with the people who control how technology is actually built.
Only 37% report a deep, trusted relationship between the CISO and CTO. For the Chief Architect, the figure is just 22%.
The same pattern appears in DevSecOps. Seventy-eight percent say cyber leaders are formally integrated into DevSecOps practices, but only 40% report true joint ownership with shared performance indicators. Security can participate in the process without owning the outcome alongside engineering.
That distinction explains why “secure by design” can sound more mature than it actually is. A security review added after an architecture has been chosen is not the same thing as security shaping the architecture. A control documented in a standard is not the same thing as an engineering team treating resilience as one of its own design objectives.
Deloitte’s data suggests that the missing relationship is partly architectural. The CISO needs to work with the people who decide what systems get built, how they are integrated, and which standards govern them. Without that relationship, cyber remains influential at the level of policy but weaker at the level of design.
The vendor problem isn’t simply too many vendors
Cyber leaders say they want to simplify their technology estates while continuing to add vendors. In technology infrastructure, 29% of respondents already work with 21 or more providers. Seventy-four percent say their number of cybersecurity partners increased or significantly increased over the past year, and 85% expect the number to increase over the next five years.
That looks like poor discipline until you consider why organizations keep doing it. Deloitte notes that some companies deliberately maintain large vendor portfolios to avoid concentration risk. Replacing twenty providers with three can reduce integration costs while creating three much larger points of failure.
The better question is therefore not “How many vendors should we have?” It is “Which capabilities should be concentrated, which should remain distributed, and why?”
The survey points toward platforms as one possible answer. Only about 30% of respondents currently consider cyber highly integrated into their technology stack, while the share pursuing transformational integrated cyber platforms has grown from 10% in 2024 to 21% in 2025. Fifty-one percent expect an integrated platform approach to be transformational in 2026.
AI is part of the reason. AI systems need consistent, normalized data, and integrated platforms can provide the data models and controls required to connect security tools and automate workflows. But a platform strategy is not automatically a simpler or safer architecture. Consolidation still has to be evaluated against concentration risk, resilience, and the actual capabilities an organization needs.
More breaches can be a sign of better security
The fourth paradox is the most useful because it challenges an assumption that appears obvious: fewer breaches must mean better cybersecurity.
In 2025, 78% of respondents publicly reported at least one breach, down from 91% in 2024. Yet the more revealing measure is what happened after those breaches. The share reporting large or very large negative consequences from cybersecurity incidents fell from 64% to 52%. Operational disruption, the leading consequence, fell from 66% to 58%.
The pattern among Deloitte’s Frontrunners is even more counterintuitive. Twenty-six percent reported 11 or more breaches, compared with 19% of Followers and 20% of Foundation Builders. Yet Frontrunners were no more likely than Followers to report negative consequences.
One plausible explanation is better detection. An organization that can see more low-impact incidents may report more breaches because it is better at finding them. A low breach count can mean strong prevention, but it can also mean weak visibility.
The better measure is what happens between detection and consequence: how quickly an organization sees an attack, how effectively it contains it, and whether the incident disrupts the business. Cybersecurity maturity is visible in those outcomes, not in a single breach count.
The budget is stable because the organization wants it to be
The fifth paradox is a familiar problem in enterprise planning. Cyber budgets are becoming more predictable just as the threat environment is becoming less so.
Eighty-five percent of respondents increased their cyber budgets year over year, and 88% expect to increase them over the next twelve months. Nearly all respondents have some form of multi-year cyber investment, yet spending priorities are expected to remain remarkably stable. Threat detection and response leads the categories at 20%, followed by infrastructure security, data/identity/application security, and strategy, governance, and compliance.
That stability makes sense. Large organizations cannot rebuild their investment priorities every time a new threat appears. Security programs take years to build, and major technology investments cannot be redirected overnight.
But the threat environment does not respect the budget cycle. Deloitte points to generative AI as an example: only two or three years ago, few organizations were planning significant near-term investments in GenAI capabilities. Now 72% say they have incorporated new generative reasoning approaches into existing AI capabilities across cybersecurity initiatives. “Misuse of AI” has gone from absent from the survey’s threat list three years ago to a top-five concern today.
The lesson isn’t that cybersecurity budgets should become chaotic. It is that a stable base budget needs room for rapid reprioritization. A security organization that cannot redirect resources when the threat changes is planning for the threats it already understands.
What the five paradoxes have in common
Deloitte presents these as five tensions, but they reinforce one another.
Cyber has executive sponsorship, yet the CISO’s relationship with the CTO and Chief Architect is much weaker. Organizations have large cyber budgets, yet third-party risk management remains comparatively underdeveloped. Companies want simpler technology estates while adding more vendors. They report large numbers of breaches while getting better at containing their business impact. They build multi-year security programs while the threat environment changes faster than those plans can anticipate.
The common thread is the distance between strategy and execution.
The executive layer has become much better at saying yes to cybersecurity. The operating layer still has to make that yes real: in architecture reviews, product decisions, supplier assessments, development pipelines, business processes, workforce skills, and incident response.
The survey offers a useful counterexample to the idea that this gap is inevitable. Deloitte’s Frontrunners are not merely more confident. They are more likely to have the relationships and shared ownership needed to carry cybersecurity into the rest of the organization. Their advantage is not a better presentation to the board. It is a tighter connection between the people who set security strategy and the people who build and operate the enterprise.
That may be the real paradox of cybersecurity. The discipline has spent years becoming a strategic concern. Its next challenge is becoming an operating discipline.
A security strategy is only as strong as the organization that has to execute it.