The State of Security 2023: Collaboration Is Essential For Building Resilience

Security is, and always has been, a tough job. Security teams continue to face escalating cyberattacks while being bombarded by false positives and clocking more hours due to staffing shortages. However, security leaders and practitioners alike also understand that these crises are inevitable — and are increasingly focusing their efforts on recovering as quickly and efficiently as possible when disaster strikes.

These trends and other findings are explored in our newly-released report, The State of Security 2023, which we published today, detailing research on the challenges and opportunities ahead for security leaders and teams. The research was conducted in partnership with the Enterprise Strategy Group and features the thoughts, insights and opinions of more than 1,500 survey respondents representing 10 countries and 15 industries.

One welcomed revelation was that 2022 was free of any globally catastrophic security events comparable to SolarWinds or Log4J. Another encouraging insight was that the number of respondents who struggled to keep pace with security requirements decreased slightly from 66% in 2022 to 53% currently. That said, security teams often remain in a reactive mode as they face increasingly sophisticated ransomware attacks and other stealthy, advanced threats.

Getting out of this reactive mode will be even harder going forward. Increasingly stringent regulations governing data privacy and security will make compliance more challenging globally, particularly around securing software supply chains. Meanwhile, as more technology sector companies continue to downsize and streamline operations with layoffs, security teams will be forced to do more with less.

Ultimately, the companies that survive these prolonged challenges and headwinds will be the ones that build resilience into their operations, so they can recover faster, and get back to business sooner.

A Growing Need for Resilience

Although the term “resilience” is not widely used by security teams, the idea that organizations need to be able to withstand and overcome adversity is nothing new to security leaders, who have no shortage of supply chain risks, ransomware attacks and other threats to address.

Despite the efforts of security teams everywhere, cyber incidents have been rising and dwell times are longer (averaging nine weeks). And it’s all causing real damage — only 4% of respondents reported that they suffered security incidents without experiencing any significant consequences. The vast majority struggled with consequences ranging from loss and theft of confidential data and lost productivity, to damaged reputation and diminished company valuation.

In light of these challenges, the need for resilience is greater than ever. At the leadership level, 91% report that the CISO is collaborating with line-of-business leaders on cyber resilience strategies and investments. And an overwhelming majority of security teams also agree that the risk of significant business disruption has increased (83%) and that downtime may result in significant customer attrition (78%).

While resilience metrics such as MTTR have improved, decreasing to 15.5 hours from 21.4 last year, much work remains to be done. Fewer than a third of organizations reported that they have a comprehensive approach to resilience. Approximately another third reported they have implemented a resilience strategy in pockets of the organization, while the remaining third said they have yet to implement any.

The need for resilience is great, but security teams know that they can't change the culture of their organization overnight — or do it alone. Building and sustaining a resilience strategy will require the buy-in and effort of numerous teams and leaders across the organization.

Cross-organizational Collaboration Is Essential for the Future of Security

One positive finding from the research is that the vast majority (95%) of security teams will be supported by an increase in funding over the next two years. Teams are planning to direct these funds toward creating a faster-moving, more effective SOC. In fact, much of the spending will go toward purchasing tools that automate and orchestrate security operations. These security-focused allocations align with reported priorities to build an integrated software architecture that incorporates security analytics and operations, and speaks to goals around developing and more formal documented security operations processes.

It will take more than just an efficient, tightly run SOC, however, for organizations to survive. This year’s research also underscored collaboration as an essential ingredient for resilience, particularly between security teams and other functions throughout the organizations. This convergence will likely increase overall visibility around risks, while also improving threat identification and response processes.

Security teams have traditionally worked closely with the ITOps team, but we’re seeing a greater convergence with other adjacent functions such as digital experience, application development and observability. Whether it’s working together more closely or creating hybrid roles that span multiple functions, coming together allows organizations to make more concerted, streamlined efforts to minimize the damage sourced to incidents and other disruptions — and ultimately protect the data, brand and valuation of the organization.

It’s probably no coincidence that of the eight research-driven recommendations in The State of Security 2023, four of them discuss the value of cross-organizational partnership. This collaborative, and more unified approach is exciting and portends a lot of hope for the industry. Looking ahead, the security teams that continue to partner cross-functionally will not only improve their security posture, but will also help their organization be more resilient to adversity and weather any storm ahead.

Read the full report to get our findings on the present security landscape and the strategies that will be essential for security teams to succeed.

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.