Survey: CISOs Increasing Budgets for Crisis Simulations in 2025

Today, Cyber Performance Center, Hack The Box, released new data showcasing the perspectives of Chief Information Security Officers (CISOs) towards cyber preparedness in 2025.

In the aftermath of 2024’s high-profile cybersecurity incidents, including NHS, CrowdStrike, TfL, 23andMe, and Cencora, CISOs are reassessing their organization’s readiness to manage a potential “chaos” of a full-scale cyber crisis.

Many CISOs across the UK and US, are concerned about their organization’s ability to handle a cyber crisis. This is owing to a number of reasons – the rising volume of cyber incidents (31%), lack of incident response planning (20%), and a lack of realistic, stress-tested crisis simulations (19%).

This drives CISOs to reallocate budgets towards crisis preparedness, as they seek to maintain security posture.

Key findings include:

  • 74% of CISOs reported their organizations are increasing annual budgets for crisis simulation exercises in 2025, motivated by last year’s major incidents.
  • 73% identified practical crisis simulations and incident response exercises involving both technical and non-technical teams - as their top business priority for 2025.
  • 77% stated they would allocate greater budgets for cyber crisis simulations if the exercises were more realistic and actionable.
  • The findings highlight a growing recognition among CISOs of the importance of realistic, hands-on crisis simulations to build visibility and ensure their organizations can respond effectively during a crisis. In fact, as much as 16% of 2025 security budgets are being reallocated to simulation exercises following last year’s incidents.

    Haris Pylarinos, CEO and Founder at Hack The Box, commented: “Preparedness is the foundation of resilience, and crisis simulations play a crucial role in testing organizations security and workforce performance when it's most critical. Organizations are right to prioritize crisis simulation and must ensure that these are implemented in the right way. There is a need for these exercises to be increasingly realistic and engaging, to equip both technical and non-technical teams of all levels with the confidence needed to decisively defend against evolving threats.”

    “The next evolution of crisis simulation is coupling AI with expert knowledge to deliver highly realistic and tailored scenarios that challenge senior management and front-line professionals. These will unite previously disparate business units as one and allow real-world performance to be benchmarked in a controlled environment.”

    Lucas Kello, Associate Professor of International Relations at the University of Oxford, said: “With the expansion of artificial intelligence, the escalating cyber arms race is entering a new and more unstable phase. AI can act as both a weapon and a shield; it can enhance threats even as it helps to defeat them. The investment in crisis simulation exercises reflects a growing awareness that future cyber conflicts will transcend current threat models while requiring accelerated responses that outpace human reaction times.” “Cyber preparedness is now a matter of national and economic security. 2025 will be a critical year for setting new standards in how nations and industries both utilize and protect against AI.”

  • Featured

    • Smarter Access Starts with Flexibility

      Today’s workplaces are undergoing a rapid evolution, driven by hybrid work models, emerging smart technologies, and flexible work schedules. To keep pace with growing workplace demands, buildings are becoming more dynamic – capable of adapting to how people move, work, and interact in real-time. Read Now

    • Trends Keeping an Eye on Business Decisions

      Today, AI continues to transform the way data is used to make important business decisions. AI and the cloud together are redefining how video surveillance systems are being used to simulate human intelligence by combining data analysis, prediction, and process automation with minimal human intervention. Many organizations are upgrading their surveillance systems to reap the benefits of technologies like AI and cloud applications. Read Now

    • The Future is Happening Outside the Cloud

      For years, the cloud has captivated the physical security industry. And for good reason. Remote access, elastic scalability and simplified maintenance reshaped how we think about deploying and managing systems. But as the number of cameras grows and resolutions push from HD to 4K and beyond, the cloud’s limits are becoming unavoidable. Bandwidth bottlenecks. Latency lags. Rising storage costs. These are not abstract concerns. Read Now

    • Right-Wing Activist Charlie Kirk Dies After Utah Valley University Shooting

      Charlie Kirk, a popular conservative activist and founder of Turning Point USA, died Wednesday after being shot during an on-campus event at Utah Valley University in Orem, Utah Read Now

    • The Impact of Convergence Between IT and Physical Security

      For years, the worlds of physical security and information technology (IT) remained separate. While they shared common goals and interests, they often worked in silos. Read Now

    New Products

    • Camden CM-221 Series Switches

      Camden CM-221 Series Switches

      Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

    • 4K Video Decoder

      3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

    • A8V MIND

      A8V MIND

      Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.