Logicalis - Closing the Security Maturity Gap

Nearly Two-Thirds of Organisations Lack Mature 24/7 Security Operations

Nearly two-thirds of organisations lack mature 24/7 security operations, according to new Logicalis research. The findings point to a security operations maturity gap despite continued investment in cybersecurity.

Logicalis released its ‘Closing the Security Maturity Gap’ benchmark report on 2 October 2026. It found that 64 per cent of organisations lack mature round-the-clock security operations. Meanwhile, 74 per cent do not use security automation extensively.

The findings matter because AI is increasing the speed of both cyber attacks and defence. That puts more pressure on organisations to detect, respond to, and recover from threats quickly.

Security Operations Maturity Gap Persists Despite Investment

The research draws on 357 responses from IT and security professionals across Europe, the Middle East, Africa (EMEA), and Asia Pacific.

Logicalis assessed several capabilities that it says define effective security operations. These include ownership, 24×7 response, visibility, detection, incident readiness and access to external expertise.

The results show a gap between cybersecurity investment and operational capability.

Nearly four in 10 organisations (39 per cent) manage ‘business as usual’ security well but struggle to keep up with emerging threats. In addition, 64 per cent fall short of fully mature 24/7 security operations.

The findings suggest that buying security technology alone does not necessarily translate into mature security operations. Organisations also need the people and processes required to use those controls effectively.

AI Is Increasing Pressure on Security Operations

The report highlights AI as a factor accelerating both attack and defence capabilities. According to Logicalis, this is compressing the time between vulnerability discovery and exploitation.

As a result, the company argues that security maturity increasingly depends on how well organisations coordinate people, processes and technology.

That operating model must support detection, response and recovery as threats move at machine speed.

Ransomware preparedness remains another concern. Nearly two-thirds (63 per cent) of organisations are not fully prepared for ransomware attacks, according to the research.

Organisations Turn to Managed Security Expertise

The research also points to growing demand for outside security expertise.

Almost nine in 10 organisations (87 per cent) see a positive or potentially positive role for managed SOC and MXDR services.

Logicalis links that demand to the need for specialist skills, continuous coverage, advanced threat intelligence and faster response capabilities.

Organisations are also increasingly viewing managed security partners as an extension of their internal security teams. The model can provide additional capabilities while allowing internal teams to maintain visibility and control.

Roger Loh, head of solutions, Digital Transformation, Logicalis Singapore, said, “The findings show that cybersecurity is no longer simply about deploying more tools. As AI accelerates both cyber attacks and defence strategies, security leaders must focus on building adaptive security operations that combine skilled people, intelligence automation, and continuous response.”

Artur Martins, CISO, Logicalis Portugal, said, “The organisations closing the security maturity gap are not necessarily those investing the most, but those connecting people, processes, and technology into a coordinated operating model. The research demonstrates that resilience comes from the ability to anticipate, act, recover, and learn. For many organisations, trusted managed security services are becoming a critical enabler of that journey.”

What Businesses Should Take From the Research

The benchmark highlights a recurring cybersecurity problem: organisations can invest in controls without achieving the operational maturity needed to use them around the clock.

The 64 per cent figure for mature 24/7 operations and the 74 per cent figure for extensive security automation show where Logicalis sees some of the largest gaps.

Meanwhile, ransomware readiness remains incomplete for 63 per cent of respondents. The findings also show that 87 per cent see a positive or potentially positive role for managed SOC and MXDR services.

Logicalis will host a webinar titled ‘What organisations with mature security do differently: Five lessons from a global SOC’ at 7pm (AEDT) on 15th October. The session will examine practices used by organisations with mature security operations and what others can do to bridge the gap.

Register your interest in the webinar here.

Shopping Cart0

Cart

Login