For many organisations, the pressure to understand and contain a cyber incident begins almost immediately after it occurs.
Boards want answers. Regulators demand accountability. Customers expect transparency.
But according to new research from Gigamon, there may be a growing disconnect between how quickly executives expect answers and how long it actually takes security teams to uncover what happened.
The company’s 2026 Hybrid Cloud Security Survey found that nearly half of CIOs and CTOs believe the root cause of a cyber incident can be identified within 72 hours. Yet only 27 per cent of CISOs agree. Nearly half of security leaders say investigations can take up to a week, while others report incidents taking considerably longer to fully understand.
The gap highlights a challenge that many security professionals are grappling with as environments become increasingly distributed across cloud, data centre, container and AI-powered infrastructures.
Visibility Is Becoming the Real Incident Response Challenge
While cyber attacks continue to grow in sophistication, many security teams argue that the biggest obstacle is no longer detection. It is visibility.
Gigamon’s research found that nearly three-quarters of organisations report limited visibility into AI-driven data flows, while 45 per cent cite expanding visibility gaps caused by cloud complexity. More than 40 per cent say it now takes longer to detect and investigate breaches despite increased investment in security technologies.
In practical terms, security teams may know an incident has occurred, but determining exactly how attackers gained access, where data moved, and which systems were affected can be significantly more difficult.
As workloads move between public cloud, private cloud and on-premises environments, security investigations increasingly involve piecing together information from multiple disconnected tools and data sources.
The result is that many organisations are reconstructing events after the fact rather than observing them in real time.
The Cost of Getting It Wrong
The consequences extend well beyond technical teams.
The survey found that more than 40 per cent of organisations reported financial losses associated with security incidents, while 37 per cent experienced increased cyber insurance premiums and 32 per cent faced regulatory or compliance penalties following breaches.
For Australian organisations, those pressures are becoming more acute as regulatory expectations continue to evolve through frameworks such as APRA CPS 230, CPS 234 and the Security of Critical Infrastructure Act.
Organisations are increasingly expected not only to respond to incidents, but also to demonstrate how they occurred and what controls were in place.
Without clear visibility, that task becomes significantly harder.
Why AI Is Making Investigations More Difficult
The report suggests AI is amplifying existing visibility challenges.
AI systems introduce new pathways for data movement through models, APIs and automated workflows that are often difficult to monitor using traditional security approaches.
At the same time, AI is becoming a significant factor in cyber incidents. Gigamon found AI was involved in 83 per cent of reported security breaches globally, spanning external attacks, internal data leakage and direct targeting of AI systems themselves.
As organisations deploy more AI capabilities, security teams face the prospect of investigating increasingly complex environments where data moves dynamically across multiple platforms and services.
From Assumption to Evidence
The survey argues that closing the gap between executive expectations and operational reality requires a shift towards deeper visibility across data in motion.
Rather than relying solely on logs, alerts and endpoint data, organisations are increasingly looking at network-derived telemetry and application metadata to understand how systems interact and how threats develop.
According to Gigamon, the goal is not simply faster incident response. It is the ability to provide evidence-based answers when an incident occurs.
Because in modern hybrid cloud environments, the biggest challenge may no longer be detecting a breach.
It may be proving exactly what happened after one occurs.







