Cybersecurity: businesses are better prepared but still vulnerable when it comes to crisis management
The EY Cyber Barometer 2025 report, based on a survey of over 300 Italian companies, reveals more structured defences and a narrowing gap between SMEs and large enterprises. However, only 6.7 per cent have achieved the highest level of formalisation in their incident response plans.
When a cyberattack brings a business to a standstill, the contingency plan must work even when it’s not just sitting on the shelf. It is essential to know who makes the decisions, which systems to restore first and how to carry on with work. EY’s Cyber Barometer 2025 focuses on this gap between written procedures and the ability to implement them: defences are becoming more widespread, but crisis management remains weak.
The survey examines over 300 Italian companies subject to financial audit, compared with over 100 in the previous edition, which covered the two-year period 2023–2024. The assessments combine interviews, documents and operational evidence, ranging from records to system configurations. The scores, on a scale of zero to five, indicate the extent to which controls are organised, implemented and verified. They do not measure immunity to attacks.
The EY press release reports an overall maturity level of around 55 per cent, compared with the previous figure of 46 per cent. However, the expansion of the sample calls for caution when making comparisons. The gap between businesses of different sizes is also narrowing: SMEs stand at 46.5 per cent, whilst large companies are at around 50 per cent. The latter maintain an advantage in more complex activities, such as incident monitoring and response. In smaller businesses, by contrast, security is more often entrusted to the expertise of individual staff members.
The widest disparities are evident across different sectors. Digital and ICT sectors have reached a maturity level of 65–67 per cent, whilst traditional and manufacturing sectors range between 35 per cent and 50 per cent. For those selling digital services, ensuring continuity means safeguarding the product itself. In other sectors, security appears to be more fragmented and plays a lesser role in business decision-making.
The data on incident response plans show just how much work remains to be done. 54.6 per cent of respondents score three or four out of five, but only 6.7 per cent achieve the highest level. Almost 19 per cent score zero or one, with procedures either non-existent or largely informal. For IT business continuity plans, the proportion at the highest level drops to 4.6 per cent.


