When a ransomware attack hits a hospital or bank, it's not just company data or customer emails that are vulnerable. These organizations have access to health records, valuable intellectual property, and bank accounts.
Bad actors know how valuable this data is, and our new survey reveals that the organizations with this data are at high risk of cyberattacks. Nearly half (48%) of professionals in highly regulated industries like health care and finance say their organization has experienced a major cyberattack, like a ransomware attack or data breach.
It's vital that organizations with access to highly sensitive data have ironclad cybersecurity to protect that information. For these companies, a data leak could have serious ethical, legal, and regulatory implications.
But our survey of 461 people shows that, even though most health care and financial organizations expect a cyberattack in the next year, many don't have the security measures in place to manage an attack.
Key takeaways
48% of professionals in highly regulated industries like health care, finance, accounting, and legal say their organization has experienced a major cyberattack, like a ransomware attack or data breach.
58% say their organization's top cybercrime-related concern is data breaches or intellectual property theft, the most common response of any kind of cybercrime.
93% of people believe their organization will face a cyberattack in the next 12 months
However, 52% say their organization is fully prepared for major cyberattacks.
45% believe their IT or security team repeatedly deprioritizes security tasks due to competing operational demands.
Large banks with hefty cybersecurity budgets are attacked more than other orgs
Any company is vulnerable to an attack, but banks are more vulnerable than other industries because they manage massive amounts of sensitive information. More than half (51%) of people at banking or financial services organizations have had a breach, compared with only 39% of people in healthcare services.
Similarly, we found that larger companies with larger cybersecurity budgets are more likely to face attacks. Half of those in businesses of 500 employees or more say their organization has experienced a cyberattack, compared to 43% of people in organizations with fewer than 500 employees.
Slightly more (54%) people at organizations with a cybersecurity budget of $10 million or more have experienced an attack, compared to 44% of people at organizations with smaller budgets. These companies probably have larger budgets because they already know they're likely to be attacked.
These cyberattacks often resulted in operational disruptions, like work stoppage and legal action. Most commonly, 50% of people say a breach or cyber incident at their organization was disruptive.
Other common consequences included data being compromised (42%) and regulatory or legal fallout (39%). About one in three (34%) say their organization had a direct financial loss through theft, remediation costs, or extortion. This shows that some organizations' worst fears about cyber safety are actually realistic. More than half (58%) of people say their organization is more worried about a data breach or intellectual property theft than any other kind of cybercrime.
Experiencing a major cybercrime puts any company at risk, but the effects of a cyberattack against a company that deals with sensitive information have widespread consequences. Even though these companies must prioritize improving their cybersecurity efforts, our data shows they still commonly experience highly damaging cyberattacks. There's clearly more they can do.
Organizations often feel prepared, but many could do more
Regardless if they've experienced one or not, 52% of professionals say they believe their organization is prepared for major cyberattacks, meaning they have enough measures in place to handle an attack confidently.
More than one-third (37%) say their organization feels somewhat prepared because they have some measures in place. Another 10% say they're organization is mostly unprepared because they only have basic measures and 1% feel wholly unprepared.
However, in practice, people say their company has varied degrees of cybersecurity preparedness:
49% say their organization doesn't have a team dedicated to internal cybersecurity. More egregiously, 47% of people at organizations with a $10 million-plus cybersecurity budget don't have an actual cybersecurity team.
45% say their IT or security teams deprioritize security tasks due to competing operational demands. Only 30% say security tasks are consistently a top priority.
42% say their organization doesn't monitor cyber threats 24/7. Around one in four (26%) only monitor during work hours and don't monitor weekends or evenings.
27% say employees at their organization receive cybersecurity training twice a year or less, or there's no consistent cadence.
All respondents to our survey say their organization has some kind of cybersecurity measure in place. However, around half don't require basic security efforts like training, reporting suspicious messages, or multi-factor authentication. A separate study from the Cyber Readiness Institute found that small businesses are especially likely not to use MFA, often because they aren't aware that it's more secure than using passwords alone.
Not using cybersecurity measures like MFA puts organizations at risk because human error is the most common cause of data breaches. Without proper training and prioritization, companies with access to sensitive data are leaving themselves wide open to attacks.
Nearly all health care and finance orgs expect a cyber attack in the next year
Nearly everyone (93%) we surveyed believes their organization will face a cyberattack in the next 12 months. Most commonly, 45% say their organization is concerned about AI-enhanced attacks, like deepfakes and automated phishing; 37% are worried about ransomware; and 36% are worried about system disruption.
Only 29% say their organization is concerned about insider threats, like accidental or intentional data leaks or security breaches. While intentional data leaks may be less common, companies should be concerned about unintentional leaks. Again, human error is very, very common. Your organization's next leak is far more likely to be caused by an employee who accidentally clicks a phishing link than by a group of elite hackers.
"Human error factors into almost every major attack," says Brian Milbier, deputy CISO at Huntress. "That's not because people are careless. It's because attackers have gotten very good at looking legitimate."
To prepare, over the next 12 months, more than half of respondents say their organization is prioritizing proactive defense technologies like AI-driven threat hunting, security posture management, or identity-first security.
While most organizations expect an attack in the next 12 months, it's unlikely they'll be able to stop every single possible type of cybercrime before it happens. Their current strategies aren't always enough. Companies that handle sensitive data need to treat data security like the high-priority concern that it is.
At a minimum, they should train their employee base on security awareness, have dedicated cybersecurity experts on staff, and mandate more security measures than just MFA.
"Something people commonly overlook is focusing on protecting your identities with the same seriousness you protect your endpoints, giving your team training that actually sticks, and making sure someone's watching when something looks off at 2 a.m.," Milbier says. "Most attacks aren't immediately impactful to your business. What decides the outcome is how fast you catch them and respond."
Huntress knows how to watch for the threats that risk your company's data
No matter the industry, companies know there is a chance they may experience a cyber threat sometime in the next year. Don't let your organization ignore the risks. Huntress agentic cybersecurity platform offers 24/7 AI-Centric monitoring from the Security Operations Center (SOC) that detects and resolves security threats before they have the chance to affect your team.
Methodology
The survey was conducted by Centiment on behalf of Huntress and fielded between March 17, 2026, and April 14, 2026. The findings are based on responses from 461 participants and have a margin of error of ±4.5% at a 95% confidence level. To qualify, respondents were screened as U.S. technology or cybersecurity professionals holding a manager-level role or higher within regulated industries, such as finance, insurance, accounting and tax, legal, medical, real estate, government contractors, or publicly traded companies.