ChannelLife US - Industry insider news for technology resellers
United States
Cyber resilience priorities diverge sharply across sectors

Cyber resilience priorities diverge sharply across sectors

Fri, 17th Jul 2026
Mark Tarre
MARK TARRE News Chief

Onyxia Cyber has published a survey report on cyber resilience priorities across five industries, finding wide differences in how chief information security officers assess acceptable risk.

The report is based on a survey of 300 chief information security officers in financial services, healthcare, critical infrastructure, technology, and retail. It says patching, identity controls, and staff responses to phishing vary sharply between sectors facing different regulatory pressures and operating conditions.

One of the clearest gaps appeared in patch management. Only 31.3% of critical infrastructure organisations said they aim to resolve critical vulnerabilities within three days, compared with 61.4% in financial services and 69.0% in IT and technology.

That spread points to uneven basic cyber hygiene across sectors that run essential systems and customer-facing services. The gap between the highest- and lowest-performing groups was more than two to one on the same measure.

Patch divide

Critical infrastructure also stood out on identity controls. It was the only sector in which no chief information security officer said their organisation requires 100% multi-factor authentication coverage for user accounts.

By contrast, 35% of chief information security officers in financial services said their organisations meet that standard. The comparison adds to concerns about identity management in industries responsible for power, water, and transport systems.

Healthcare showed a different pattern of weakness. Organisations in the sector reported the highest phishing click-through rate, at 5.53%, almost double the 3.13% reported in financial services.

Healthcare also recorded the highest share of inactive privileged accounts, at 3.42%. Such accounts can create access risks because they retain elevated permissions even when no longer in active use.

Sector contrasts

Financial services led several rankings on technical controls. The sector posted the lowest rate of unmanaged devices, at 1.76%, and the lowest share of inactive privileged accounts, at 1.05%.

Yet it also reported the highest acceptable security operations centre false-positive rate, at 13.23%, compared with 7.23% in healthcare. That suggests some mature security teams still tolerate high levels of alert noise.

Technology firms set the toughest expectations for employee reporting of phishing emails. Staff in the sector were expected to report 86.71% of phishing messages, compared with 76.02% in critical infrastructure.

The report presents that difference as a sign of contrasting assumptions about workforce behaviour and internal security culture. It suggests some sectors place more emphasis than others on the human layer of defence.

Retail and eCommerce sat between the leaders and laggards. The sector patches 62% of critical vulnerabilities within three days, placing it close to financial services on that measure.

Its identity controls were less consistent. Retail recorded a multi-factor authentication coverage gap of 3.72%, more than double the financial services benchmark, while its average phishing simulation reporting rate of 78.9% was the second lowest in the survey.

Benchmark question

The findings reflect a broader argument in the study: there is no common definition of acceptable cyber risk across industries. Measures treated as baseline practice in one sector may not be expected in another.

That can complicate comparisons for security leaders, especially as boards and regulators increasingly want clear evidence of resilience. Without broader benchmarks, organisations may judge their performance only against sector norms rather than stronger standards elsewhere.

According to Onyxia Cyber, the data shows the value of setting measurable resilience targets and comparing them with peers across multiple sectors rather than within a single industry alone.

"What this research makes clear is that acceptable risk isn't universal - the variation across sectors is striking, and those discrepancies have real consequences," said Sivan Tehila, founder and chief executive officer of Onyxia Cyber. "Security leaders need cross-domain, context-aware data to benchmark their programs continuously, not just against their own industry, but against the full picture of what good looks like elsewhere - that's what proactive operational cyber resilience actually requires."