CISOs Boost Investments in Realistic Cyber-Crisis Simulations for 2025

The increasing prevalence of cyberattacks has pushed Chief Information Security Officers (CISOs) in the United States and the United Kingdom to significantly prioritize their crisis simulation initiatives for the year 2025. This trend is driven by the alarming rise in cyber threats combined with the widespread recognition of inadequate incident-response plans and the lack of thorough stress-testing in many organizations. Projections suggest a considerable uptick in budget allocations, with 74% of CISOs planning to invest more in these realistic cyber-crisis simulations to ensure their teams are better prepared to handle potential security breaches.

The urgency for more realistic and actionable crisis simulations was highlighted in a recent study by Hack The Box, which revealed that 77% of surveyed CISOs would be inclined to allocate more resources if these exercises offered measurable and practical outcomes. Haris Pylarinos, CEO and founder of Hack The Box, stressed the necessity of preparedness, emphasizing that crisis simulations serve as a crucial tool in enhancing organizational resilience. These simulations not only test the robustness of security measures but also evaluate the performance of the workforce under simulated critical conditions, thereby identifying weaknesses and areas for improvement.

A notable insight from the study is that 73% of respondents emphasize the importance of involving both technical and non-technical teams in crisis simulations and incident-response training. Pylarinos elaborated on how the future of these simulations would increasingly leverage artificial intelligence and expert knowledge to craft highly realistic and customized scenarios. Such advanced simulations aim to foster collaboration across various business units while also allowing the benchmarking of performance within a controlled setting. This integrated approach ensures that all facets of the organization are prepared to respond effectively to cyber crises.

In summary, the consensus among CISOs underscores that enhancing crisis simulation exercises is a strategic necessity to counter the growing cyber threats. The planned increase in budget and the shift towards more realistic and comprehensive exercises signal a robust move towards strengthening organizational preparedness and resilience. By investing in advanced crisis simulations, CISOs aim to create a security environment that can withstand the complexities of modern cyberattacks, thereby safeguarding their organizations’ integrity and operational continuity.

Explore more

Ethereum Tests Glamsterdam Upgrade Amid Market Volatility

The activation of the Glamsterdam upgrade on the Sepolia testnet marks a critical phase in Ethereum’s infrastructure scaling as the network tests a gas limit increase from 60 million to 200 million. This substantial expansion of the gas limit represents a calculated gamble on the robustness of current hardware, aimed at accommodating a new wave of high-throughput decentralized applications. While

How to Design and Optimize AI Prompts for Production

The shift from experimental chatbots to high-scale enterprise intelligence systems in 2026 has transformed prompt engineering from a creative writing exercise into a disciplined branch of software engineering. The most effective production prompts use structural separation to distinguish between trusted system instructions and untrusted content from user inputs or retrieved documents. When an application processes thousands of model calls against

What Are the Best Email Marketing Tools for SMBs in 2026?

Small businesses often choose Constant Contact because it offers an extensive library of templates and specialized tools for managing event registrations and ticketing directly through emails. However, the broader landscape of digital outreach has shifted significantly, transforming email from a simple messaging tool into a sophisticated infrastructure for revenue growth and long-term customer retention. In 2026, the success of a

EY Breach Exposes Goldman Sachs and Man Group Client Data

Administrative IT tickets used for routine tax services inadvertently served as a repository for sensitive client data that was eventually stolen by hackers. This security failure at Ernst & Young (EY) has sent ripples through the financial sector, as it compromised the personal information of high-net-worth individuals associated with Goldman Sachs and the London-based hedge fund Man Group. While these

New Phishing Campaign Impersonates AI Tools to Steal MFA Codes

The campaign exploits the established trust that advertising agencies place in AI tools to bypass multi-factor authentication protocols that were previously considered secure. This sophisticated operation, identified in late 2026, represents a significant shift in the threat landscape, moving away from generic banking lures and toward the highly specialized tools used by modern marketing professionals. By impersonating platforms such as