What 1,100+ IT pros told us about growing security team pressure
- The biggest security risk may be sitting inside the organization
- Knowing the risk doesn’t always lead to investment
- Security teams are losing capacity to operational demands
- AI can take some work off the team’s plate, but expertise remains scarce
- Passing an audit doesn’t mean the work is done
There is a version of cybersecurity that works perfectly. Employees recognize every phishing email, budgets stretch to cover every risk and the right person is always available when an alert comes in.
That version exists in strategy decks and vendor pitches. It doesn’t exist on a Friday evening when someone in accounts payable has just wired money to the wrong person or reset their password to “Password123.”
Most security programs are built for the first version. Most security teams are living in the second.
That gap was the starting point for our latest Cybersecurity report: Building security that survives human error. We surveyed 1,132 MSPs and IT professionals across more than 63 countries and territories to understand what cybersecurity looks like when real-world pressures collide with the plans built to manage them.
The human factor is the weakest link
People remain one of the hardest parts of security to control. That concern comes through clearly in the data: 68% of respondents identified human error as a potential gateway to a successful attack, making it the threat vector they were most concerned about.
The same pattern appears when we look at the organizations that experienced an incident. Four of the five leading contributing factors involved people. Poor user practices or user error ranked first at 41%, which can mean something as simple as trusting a phishing email, using weak passwords or sharing information with the wrong person. A lack of end-user cybersecurity training followed closely at 40%, suggesting that people may not always know how to recognize a threat, handle sensitive information or respond when something looks suspicious.
That human element also explains why phishing ranked as the top threat faced by both MSP clients and internal IT organizations. Phishing puts a person directly in the path of an attack. The attacker delivers the lure through an email, but the recipient ultimately decides whether to click, reply, open an attachment or hand over credentials.
Security investment often follows the incident
Security leaders can know exactly where their exposure lies and still struggle to act on it.
A whopping 77% of IT departments said their cybersecurity investment was not keeping pace with the threats they face. Among MSPs, about 65% said their clients were underinvesting in cybersecurity.
MSPs also highlighted that investments in cybersecurity usually happen after a client experiences an incident or a near miss. Before that point, security has to compete with other business priorities, even when the risks are already known. The result is a familiar pattern: organizations understand the risk, but action can wait until the consequences become impossible to ignore.
That can leave security teams trying to close gaps under pressure, when the better opportunity would have been to address them while there was still time to plan.
Security creates work of its own
Then there is the pressure that rarely makes it into the strategy document: the daily work of keeping security running.
For 38% of respondents, end-user requests were the most common interruption to security work. At the same time, the controls designed to reduce risk create their own operational demands. MFA ranked as the security practice creating the most friction, cited by 36%.
That creates an uncomfortable reality. A control can be important and still consume time. A process can improve security and still create work for the people responsible for operating it. When enough of that work accumulates, teams have less capacity for the work that prepares them for what comes next.
The skills security teams need are in short supply
Even a well-funded security strategy needs people to run it. That is becoming harder as organizations struggle to find specialists with the skills needed to manage increasingly complex security environments.
Security automation and AI specialists were the hardest roles to find or retain, cited by 32% of respondents. Security operations and incident response followed at 30%. These roles matter because they sit close to the day-to-day work of finding threats, investigating what happened and deciding how to respond.
AI is already helping teams handle some of that workload. About 44% of respondents use AI for threat detection and monitoring, while 29% use it to reduce alerts or help with triage. Those are jobs that can consume significant amounts of a security team’s time.
Compliance has no finish line
About 65% of respondents said they could pass a compliance audit today without preparation. That suggests strong confidence in their current readiness. But an audit captures a moment in time. Staying compliant requires the organization to keep its controls, documentation and employee practices current long after the auditor leaves.
That ongoing work can create its own gaps. Nearly half of respondents (49%) said incomplete documentation or policies are most likely to create issues during an audit. Another 34% pointed to controls that were not fully implemented, while 33% cited gaps in employee security awareness or training.
Being ready on audit day depends on work that has to happen every day.
Build security for the real world
The verdict: security strategies must work within real-world constraints.
Resilient organizations plan for those realities. They put safeguards around human error, make the case for investment before an incident, reduce routine work and use AI to extend limited security capacity while keeping human judgment in the decisions that matter.
Get the report to explore the full findings and discover what it takes to build security that holds up under pressure. You’ll also get a free playbook with practical guidance to help turn those insights into a more resilient security strategy.


