Companies can't implement every security measure at once, so they have to set priorities. For decision-makers, what matters most is which systems and processes would immediately disrupt business operations if they failed or were compromised. That's the finding of the "Cybersecurity in Numbers" 25/26 report from G Data, Statista, and Brand eins, for which the study's authors set a scale from 1.0 to 5.0, where a lower value indicates a higher priority.
Protecting business-critical systems and processes scores 2.72, the highest priority in the study. Close behind come risk and potential damage to the company at 2.75, and the available budget for IT security at 2.78. These three factors form the top tier that companies use to guide their security measures.
Compliance and security strategy still matter
Regulatory requirements and long-term security goals also shape planning. Meeting compliance requirements scores 2.94, and internal security strategy or roadmap follows at 2.95. After that, respondents cite the cost-benefit assessment of planned measures at 2.97. According to the study, IT security is no longer seen as a purely technical task, but is closely tied to business processes, budget decisions, regulatory requirements, and long-term company planning.
Time, threat landscape, and experience rank lower
Available time windows for implementation score 3.05. The current and future threat landscape, along with technical integration into existing systems, both follow at 3.08, and the availability of internal skilled staff and resources sits at 3.15. At the bottom of the ranking are experience from past security incidents at 3.25, and the expectations of customers, partners, or regulators at 3.28. G Data points out, however, that experience from past incidents can provide valuable insight into technical vulnerabilities, unclear responsibilities, or missing processes, and should therefore feed more strongly into security strategies, reporting channels, and incident response plans. G Data plans to publish the full 2026/2027 study over the course of September 2026.