Skip to content

Reputation, Not Ransom, Leading Driver of Incident Response Spending

A new Forrester/TransUnion survey finds 77% of security leaders rank reputation damage above revenue loss after a cyberattack — and the reasoning behind that shift matters more than the stat itself.

Seventy-seven percent of security decision-makers now name reputation damage as their top concern following a cyberattack. That leads over revenue loss and loss of consumer trust. That reordering shows how far incident response has moved beyond being viewed as an “IT problem,” among business leaders. 

The survey, fielded by Forrester Consulting on behalf of TransUnion (which sells incident response and cyber insurance) in February and March 2026 among 327 U.S. director-level-and-above decision-makers split evenly between enterprise and mid-market organizations. The survey found 60% had experienced at least one material cyberattack impact in the past 18 months. Phishing and credential theft remained the top threat concern, cited by more than 70% of respondents, followed by ransomware and multifaceted extortion at 65%.

"Today, reputation is a bigger [cybersecurity] motivator beyond losing a few bucks, but thinking they can recover. Reputation damage is more long term issue and if you don't address that the right way, it could be a business killer," said Matt Cullina, head of TransUnion's Global Cyber Insurance Business, discussing the survey findings with CYBR.SEC.Media.

A troubling gap

The survey lifted a troubling disconnect between where organizations want to be in incident response readiness and where they actually are. More than 60% of respondents said their organization continuously reviews its incident response strategy, and nearly 60% said they regularly evaluate current approaches and vendors, yet 40% reported lacking an end-to-end incident response partner, and 37% said they have no comprehensive incident response plan at all.

And while over 70% of organizations use at least one external incident response provider, 41% plan to reevaluate that provider within the next year. Only 46% rate their current provider's “end-to-end readiness” and response support as delivered "very well" or "extremely well," even though 76% call that capability "very important" or "mission-critical" to their selection process.

"It's a little bit of both," said Eder Ribeiro, director of TransUnion's Global Incident Response practice, when asked whether rising provider-reevaluation numbers reflect market maturity or persistent disorder. Ribeiro said some sectors, including healthcare, are moving toward owning security readiness directly, while others remain in flux.

That 30-point spread between what organizations demand from a provider is a troubling takeaway for security leaders: a signed retainer is not the same as tested readiness. Cullina said incident response should function as "a continuous readiness cycle, not a one-time plan," with tabletop exercises that include legal, communications, and executive stakeholders, not just IT and security teams.

Don’t Let Confirmation Bias Derail Incident Response
A construction site in Texas offers a powerful reminder that the biggest mistake in incident response isn’t missing an attack, but letting confirmation bias convince you one exists before the evidence does.
Bridging Public Safety and Incident Response
Battle boards meet cyber war rooms—learn how public safety response tactics can strengthen incident response, coordination, and decision-making.
Manufacturing: NIST Wants to Upgrade the Incident Response Playbook
NIST releases its first concrete OT recovery playbook and it looks nothing like an IT runbook. The document is formally aimed at manufacturing, but the problem it addresses is structural across every operational technology environment where stopping production has physical consequences.

The cost of being ill-prepared

Ribeiro described the operational cost of that gap. Organizations without a retained, onboarded incident response partner are often left searching for help mid-crisis, sometimes engaging unvetted vendors who worsen outcomes. Ribeiro described one case, outside the survey data, in which a company nearly issued a public breach notification over what investigation later showed was a minor incident, a near-miss he attributed to relying on generalist IT staff rather than an experienced response team already familiar with the organization's systems.

That disconnect between confidence and readiness is not evenly distributed. Midmarket organizations reported notably worse outcomes than enterprise peers, 73% versus 63%, and struggled with timely detection and remediation, which Forrester attributed largely to resource constraints. The report also found midmarket organizations more concerned about supply-chain and third-party risk than enterprises, 62% versus 48%. Ribeiro linked that gap to midmarket firms' heavier reliance on outsourced cloud and software vendors they don't control, a dependency Cullina said the industry has watched intensify over the past three years as third-party incidents outpace standard ones.

HOU.SEC.CON CTA

Latest