Summary
- PwC says 84% of surveyed security and finance leaders expect cyber budgets to rise.
- Earlier NormCyber research found a wide gap between perceived resilience and performance during breaches or exercises.
- Recovery testing, continuity planning, and operational evidence provide a stronger measure than security spending or subjective confidence alone.
Companies expect to spend more on cybersecurity during the next year, but evidence of how well they would continue operating through a serious incident remains much less developed, with new PwC research showing a gap between rising budgets and formal continuity planning.
PwC’s 2027 Global Digital Trust Insights survey, published on 1 October, found that 84% of surveyed security and finance leaders expect cyber budgets to increase during the next 12 months, up from 78% a year earlier. Artificial intelligence is among the largest investment priorities, cited by 58% of security leaders.
Only 39% of security, risk, and operations respondents reported having a fully formalised and integrated operational continuity plan specifically addressing cyber risk, while fewer than half strongly agreed that cyber risk held a standing position on the board agenda.
Separate UK research from NormCyber provides a useful comparison between confidence and tested performance. Its June survey of 500 technology and security leaders found 88% rating their organisation’s cyber resilience above average, a distribution that indicates organisations were not judging themselves against a consistent benchmark.
Exercises expose weaker recovery than confidence suggests
Among respondents whose assumptions had been tested by a breach or tabletop exercise, 60% said the organisation had proved significantly less resilient or recovered more slowly than its resilience score suggested. Only 37% believed the score had accurately predicted performance.
NormCyber calls the difference between confidence and demonstrated capability “resilience debt”. Paul Cragg, its chief technology officer, said in comments supplied for Cybersecurity Awareness Month: “This gap between confidence and capability – known as the resilience debt – is growing.”
The phrase belongs to the vendor, but the gap it describes is familiar in operational resilience. Preventing an incident, detecting it, containing it, restoring systems, and continuing to provide critical services are separate capabilities, and strong preventive controls do not guarantee rapid recovery.
NormCyber’s survey also found that 54% of respondents believed leadership often confused being secure with being immune to downtime, while 39% thought their board could clearly distinguish attack prevention from maintaining operations during an incident.
The study is vendor commissioned and based on self reporting rather than direct testing of the 500 organisations. Its comparison between perceived resilience and experience during breaches or exercises is nevertheless more informative than a confidence measure alone because disruption provides an external test of assumptions.
More spending does not resolve the measurement problem
PwC’s same-day global research covered 3,934 business and technology executives across 71 countries and territories. Half of security leaders listed attacks targeting AI systems among the threats for which their organisation was least prepared, while only 22% said they would authorise fully autonomous AI agents for cyber defence.
Investment is also moving into architecture intended to reduce disruption. PwC found 54% adopting multi-cloud or hybrid cloud strategies, 47% strengthening regional technology and data redundancy, and 37% localising infrastructure within particular jurisdictions.
Those measures can improve resilience, but architecture alone does not establish how quickly a business can restore a service after ransomware, a supplier outage, destructive intrusion, identity compromise, or failure in shared infrastructure. Recovery depends on technology, suppliers, people, backups, communications, processes, and decision making working together under pressure.
Frameworks can give organisations a common structure for examining those dependencies. Cragg points to the National Cyber Security Centre’s Cyber Assessment Framework as one possible foundation, while NormCyber’s earlier research also acknowledges that alignment with a framework does not by itself provide continuous evidence of operational readiness.
Exercises and technical testing provide a harder measure. Restoring backups, failing systems over to alternative infrastructure, simulating supplier failure, and timing recovery can expose dependencies that policy documents and annual audits miss.
The growing cyber budget gives organisations more resources with which to close those gaps, but spending alone remains a poor proxy for preparedness. New security products can reduce particular risks while adding suppliers, technology, and information that also have to be managed during an incident.
A more useful test is whether investment changes the organisation’s ability to continue operating and recover within a predictable period. PwC’s figures show budgets rising while formal continuity planning remains incomplete, and NormCyber’s UK survey shows confidence falling once organisations compare their assumptions with the experience of disruption.
Cybersecurity Awareness Month will generate another cycle of advice about passwords, phishing, ransomware, and AI threats, but resilience becomes measurable only when organisations can show which services they need to recover, the dependencies behind them, and whether those assumptions have survived a realistic test.












