Cyber crisis planning is widespread, but operational disruption remains common when incidents occur. A global survey conducted in early 2025 covered 1,000 organisations across the UK, France, Germany, Italy, Spain, the United States, Australia, New Zealand and Singapore, including healthcare. Ninety-six per cent of organisations said they had a cyber crisis response plan, while 83% had integrated it into broader enterprise crisis management. Yet 71% experienced at least one high-impact cyber incident that disrupted critical business functions in the previous year, revealing a clear difference between the prevalence of formal preparation and actual crisis outcomes. 

 

Plans Are Common but Readiness Remains Uneven 

Formal cyber crisis response plans are now common across most organisations, but significant obstacles remain during cyber incidents. Across all sectors, only 10% of respondents reported no significant blockers to effective cyber response. Communication gaps ranked first, followed by outdated plans, unclear roles and responsibilities, too many disparate tools and staffing shortages. 

 

Healthcare organisations reported particularly high adoption of formal planning. Ninety-eight percent said they had a comprehensive cyber crisis response plan, although only 78% said that plan was integrated into enterprise crisis management. Healthcare also ranked among the sectors most frequently conducting practical exercises, with 85% reporting monthly or quarterly tabletop exercises or response plan audits. 

 

Seventy percent of healthcare organisations reported monthly or quarterly updates to cyber response runbooks and playbooks. Across all industries, the global figure was 72%. These figures sit alongside the high level of formal plan adoption and regular exercises reported by healthcare organisations. Across the full sample, plan integration varied by country and industry even though comprehensive plans were widely reported. 

 

Operational disruption nevertheless remained common across the wider sample. Globally, 36% of organisations experienced multiple high-impact cyber events during the previous year. In healthcare, 24% reported multiple such events. Across all organisations, 90% of crisis response teams had been activated because of a cyber incident during the same period. Forty-eight percent activated their crisis response team one to four times, while 39% did so five to 15 times. 

 

Must Read: Healthcare Cyber Risks Broaden Across Digital Systems

 

Communication and Coordination Create Major Barriers 

Cross-team communication was the leading obstacle to effective cyber response. Severe cyber incidents can disrupt ordinary email and messaging systems, while dedicated out-of-band tools support communication when those systems are unavailable. Eighty-five percent of organisations reported having such tools, but 21% said the same tool was not used across all teams involved in a crisis or were unsure whether it was. 

 

Tool fragmentation added another difficulty. Organisations used more than 20 disparate tools for cyber crisis response on average. Excessive numbers of tools ranked among the five main response blockers, alongside communication gaps, outdated plans, unclear responsibilities and staffing shortages. 

 

Cyber crisis response can also require actions from people outside IT and cybersecurity. Response actions may need to be completed in a specific order by specific people, while many organisations reported unclear roles and responsibilities during a crisis. 

 

The same cross-functional gaps appear in tabletop exercises. Globally, only 35% of organisations involved legal, finance or human resources, 37% included business continuity and 43% included disaster recovery. Fewer than half therefore included each of these groups in exercises, despite their involvement in real-world cyber crises. 

 

Cross-team communication gaps were also the leading blocker reported across healthcare, finance, energy, government, travel and transport, IT and telecoms and manufacturing and utilities. Country patterns differed: communication gaps led in the UK and Spain, while too many disparate tools were the leading blocker in France and Germany. 

 

Practice Is Frequent but Often Incomplete 

Most organisations conduct recurring exercises, but participation across business functions remains limited. Globally, 78% reported monthly or quarterly tabletop exercises or audits of their cyber response plans. Healthcare recorded one of the higher sector rates at 85%. 

 

Tabletop exercises are intended to test whether a plan can be executed in practice rather than only in theory. Practical exercises also allow organisations to apply lessons learned, adapt to evolving threats, new technologies and changing compliance demands and familiarise stakeholders with their roles. 

Plans need clearly defined roles and responsibilities across IT, cybersecurity and crisis decision-makers elsewhere in the organisation. Exercises also need practical, realistic scenarios that involve the stakeholders expected to act during a cyber crisis. However, the participation figures show that legal, finance, human resources, business continuity and disaster recovery are often absent. 

 

Regular updating is another part of preparedness. Across all respondents, 72% documented and updated cyber response runbooks and playbooks monthly or quarterly. Healthcare reported a similar rate of 70%. Among surveyed European countries, the corresponding rates ranged from 54% in Spain to 77% in Germany and the UK. 

 

Plans also need to reflect the organisation’s actual technology, staffing, business needs and available resources. Generic or outdated playbooks can create escalation paths that do not match operational conditions. Formal planning, regular exercises, role clarity, consistent communications and updated playbooks are all identified as elements of cyber crisis preparation. 

 

Cyber crisis readiness remains uneven despite widespread use of formal plans, regular exercises and response tools. Disruption persists alongside communication gaps, unclear responsibilities, outdated plans and limited cross-functional participation in exercises. Healthcare reports high levels of planning and frequent tabletop activity, but integration and regular updating are not universal, while multiple high-impact incidents continue to occur. Effective preparation depends on response plans that remain current, use clear roles, support consistent communication across teams and can be executed under realistic crisis conditions when critical business functions are disrupted. 

 

Source: Semperis 

Image Credit: iStock 


References:

Semperis (2026) The State of Enterprise Cyber Crisis Readiness. Hoboken: Semperis. 



Latest Articles

Cyber crisis planning is widespread, but operational disruption remains common when incidents occur. A global survey conducted in early 2025 covered 1...