-

Immersive Labs Global Study Finds Improved Response Time to Threats, Yet Resilience Efforts Still Fall Short

Average response time accelerated from 29 to 19 days, from 2021 to 2022, with lessons from Log4j and other high-profile vulnerabilities having a significant impact on urgency levels

BOSTON & BRISTOL, England--(BUSINESS WIRE)--Immersive Labs, the world’s first Cyber Workforce Resilience solution, today released the second edition of its annual Cyber Workforce Benchmark Report, which offers a deeper look at organizations’ resilience to threats (or lack thereof), through analysis of proprietary data over a one-year period. The study found that, on average, organizations’ response time to cyber attacks accelerated by approximately one-third—from 29 to 19 days—from 2021 to 2022, which can be attributed to the urgency and need for fast response times amid the fallout of the Log4j crisis and other high-profile vulnerabilities over the last year.

Immersive Labs’ research is based on organizations’ performance completing real-life cyber simulations spanning 1.1 million exercises and labs spanning technical staff to executives during a 12-month period from April 2022 to April 2023. Immersive Labs’ unique Resilience Score was a key factor in measuring and gauging trends against industry benchmarks. The goal of this report is to empower cyber leaders with insights to address strategy gaps, mitigate risk, and build lasting resilience to threats across the workforce.

Improvements to organizations’ median time to respond to new threats reveals a great deal about the overall state of cyber resilience, since faster response time means a smaller window of vulnerability and a lower risk of negative impact to the business. The Log4j crisis, for example, was a watershed moment that served as a catalyst for this urgency given its catastrophic impact. While the initial discovery of Log4j dates back to December 2021, it continues to be a chart-topper among users of the Immersive Labs platform as two of the top five most frequently attempted CVE labs over the last year were Log4j-related.

“Leaders should ensure that their workforce – at all levels of experience – stays current with emerging threats, and get proof of their teams’ knowledge, skills and judgment to quickly and effectively respond to threats,” said Immersive Labs CEO and Founder James Hadley. “Our report’s insights underscore the critical importance of consistently conducting realistic exercises to assess skills gaps and fill them before it’s too late — but just as importantly, if the worse case scenario does happen, knowing how to best handle incidents ‘after the boom’ to mitigate fallout.”

Immersive Labs’ research data also revealed several other notable patterns emerge including:

  • Organizations aren’t preparing their workforces enough for after-incident responses: To effectively reduce risk, organizations must be prepared before and after an incident. While organizations are ensuring that cyber resilience activities span the MITRE ATT&CK® framework, Immersive observed a notable bias towards the earliest stages of the attack lifecycle, suggesting security leaders are potentially leaving their organizations exposed to after-incident risk.
  • Seasoned cyber pros are more complacent in their skills than junior staff: Junior staff tend to challenge themselves with more difficult exercises and are more likely to stay current with new threats compared to more experienced cyber professionals. More junior workers on average complete content that is more difficult than more experienced professionals. However, to effectively prepare for cyber threats, individuals at all stages of their career need to be prepared for the latest threats.
  • Cyber resilience is rising globally amid more sophisticated threats: Modest gains were made in achieving resilience, especially those who focused on key areas such verifying the skills of new talent (46%) and assessing security team capabilities in realistic scenarios (30%) amid more sophisticated cyber threats.
  • Financial services firms are the top individual performers: Holistically, regulated industries only marginally outperform less-regulated peers, with a 6% difference across key resilience metrics, showing that regulated industries on average are not substantially better prepared for attacks than less-regulated industries. Nevertheless, financial services firms tend to perform the best, as the industry represents seven of the top 10 overall performers, which can be largely attributed to their commitment to continuous exercising and benchmarking their teams, creating organizational competence.

Download the 2023 Cyber Workforce Benchmark Report here.

About Immersive Labs

Immersive Labs is the leader in people-centric cyber resilience. We help organizations continuously assess, build, and prove their cyber workforce resilience for teams across the entire organization, from front-line cybersecurity and development teams to Board-level executives. We provide realistic simulations and hands-on cybersecurity labs to evaluate individual and team capabilities and decision-making against the latest threats. Organizations can now prove their cyber resilience by measuring their readiness compared to industry benchmarks, building team capabilities, and demonstrating risk reduction and compliance with data-backed evidence. Immersive Labs is trusted by the world’s largest organizations and governments, including Citi, Pfizer, Humana, HSBC, the UK Ministry of Defence, and the UK National Health Service. We are backed by Goldman Sachs Asset Management, Summit Partners, Insight Partners, Citi Ventures, Ten Eleven Ventures, and Menlo Ventures.

Contacts

Immersive Labs


Release Versions

Contacts

More News From Immersive Labs

Immersive Launches Dynamic Threat Range to Set New Benchmark for Cyber Readiness

BOSTON & BRISTOL, England--(BUSINESS WIRE)--Immersive, the leader in cyber resilience, today announced the general availability of Dynamic Threat Range, a groundbreaking new capability within its Immersive One platform that transforms how organizations validate and improve cyber readiness. Dynamic Threat Range runs authentic, full-chain live-fire attacks within supported enterprise environments, delivering a level of realism that traditional log replays cannot match. Powered by a new Infrastruc...

Overconfidence Is the New Cyber Risk: Immersive’s 2025 Cyber Workforce Benchmark Report Exposes a Global Readiness Illusion

BOSTON & BRISTOL, England--(BUSINESS WIRE)--Immersive, the leader in cyber resilience, is revealing a widening gap between confidence and capability in cybersecurity. Despite record investment, heightened board oversight, and nonstop training, measurable readiness has flatlined. While nearly every organization believes it can handle a major incident, the data tells a different story. According to Immersive’s analysis, average decision accuracy is just 22%, and the average containment time is 29...

Immersive Appoints New C-Level Product and Technology Leaders to Accelerate Cyber Readiness with the Immersive One Platform

BRISTOL, England & BOSTON--(BUSINESS WIRE)--Immersive, the leader in cyber resilience, today announced the appointment of Aniket Menon as Chief Product Officer (CPO) and Thanos Karpouzis as Chief Technology Officer (CTO) to its executive leadership team. These critical additions will support innovation in Immersive One, the company’s unified cyber readiness platform, and reinforce Immersive’s mission to help organizations be ready for cyber threats through its AI-powered, evidence based Prove,...
Back to Newsroom