Article Read Time

Cyber attack readiness is not a document. It is a set of decisions you make before a cyber attack.
A few months ago, I sat in a county office with a clerk who had a binder on her shelf labeled “Emergency Plan.” She pulled it down and blew the dust off the cover. Inside was a phone list. Four of the eleven people on it no longer worked there. One had passed away. That binder was her incident response plan.
She is not an outlier, nor is she careless. She is busy. And she is in very good company.
According to The State of Incident Response Readiness 2026, a survey of 600 senior IT security decision-makers conducted by Vanson Bourne in January and February 2026 found that 73% of organizations admit they would not be “fully ready” if a significant cyber attack occurred tomorrow. These are not small shops. These are organizations with security budgets, security staff, and written plans. Nearly three out of four still say they would be caught flat-footed.
That finding should be oddly reassuring to a city clerk in Kentucky. The gap is not about money or tools. It is about coordination. And coordination is something a small organization can actually fix.
What the research really says about Cyber Attack Readiness
The report found that 76% of organizations were hit by at least one cyber attack in the past year, and 32% were hit more than once. So the attacks are not hypothetical.
What slows the response is not usually the technology. It is people not knowing who decides what. Ninety percent of those surveyed expect trouble coordinating stakeholders during a serious incident. 75% say delays in getting legal and communications involved slow down decisions. 89% point to limited involvement by executives and boards.
Read that again and translate it into local terms. The IT contractor knows something is wrong. The city administrator wants to be briefed before anything gets shut off. Nobody is sure whether the attorney should be called now or later. Nobody knows who tells the public. Meanwhile, the attacker is still inside.
That is the whole problem in one paragraph. It is not exotic. It is a chain-of-command problem, and it happens in organizations of all sizes.
Five things to do in the next month
Here is what I would do if I ran a small city, a clinic, a school district, or a twelve-person business. None of this requires a purchase order.
Write down who decides. Not who does the work. Who decides. Who has the authority to disconnect a server, close the office, pay a vendor for emergency help, or notify the public. Put a name and a backup name next to each one. If your answer is “we would figure it out,” you have found your first gap.
Build a contact sheet that lives outside your network. Ransomware locks up the very systems that hold your phone list. Print it. Put a copy in a folder at home, in the mayor’s car, in the office manager’s purse. Include your IT provider, your insurance carrier, your attorney, your bank, your cyber insurance claims line, and the FBI’s Internet Crime Complaint Center at ic3.gov. Update it twice a year, on a date you already remember.
Run a tabletop exercise, and invite the non-technical people. A tabletop is just a conversation. Sit six people around a table for ninety minutes with a scenario: it is Tuesday morning, payroll runs Thursday, and the accounting computer is showing a ransom note. Walk through it out loud. Who calls whom. What gets said to employees. What gets said to the newspaper. You will find the broken parts fast, and you will find them for free. The report noted that fewer than 40% of organizations rated their tabletop exercises as highly effective, largely because they only invited the technical staff.
Test a restore, not just a backup. A backup you have never restored is a promise, not a plan. Pick one important file share and restore it from your backup. Time it. If it takes eleven hours, you now know something true about your organization that you did not know yesterday.
Know what you cannot see. The survey found that 78% of respondents believe blind spots in their environment allow attackers to maintain a foothold and return later. For a small organization, this usually means simple questions nobody has answered. What is connected to the internet? Who has administrator access, including former employees and vendors? Where does the data actually live? Write the answers down. That list is worth more than most security software.
A word about AI, and about spending
The report shows AI use rising quickly in threat detection, with 63% of organizations expecting it to be embedded in their response work by 2027. It also shows something more useful: AI helped the organizations that already had disciplined processes. It did not rescue those who did not.
The same is true of any tool you might buy. Software does not decide who calls the attorney at 11 p.m. You do, in advance, on a quiet afternoon, in a room with a whiteboard.
You do not need us to do any of this. Most of it is an afternoon of honest conversation and a printed page. The cyber security and Infrastructure Security Agency publishes free tabletop materials at cisa.gov, and your state emergency management office and local InfraGard chapter can often help. If you want a second set of eyes on your cyber attack plan, we are happy to talk it through at 502-234-5554. No pitch, just a conversation.
Seventy-three percent of well-funded organizations say they are not ready. You can be in the other group by September, and it will not cost you a dime.
