The Retail and Hospitality Information Sharing and Analysis Center (RH-ISAC) released the 2025 CISO Benchmark Report, providing data-driven insights on how security leaders in different industry sectors are addressing today’s security challenges, including security maturity, resource priorities, workforce trends and governance.
The report reveals that 82% of companies lack strong security maturity of their Digital Core, a foundation that integrates advanced platforms, AI-driven cybersecurity and zero-trust architectures. Barriers to this include budget constraints (71%), cyber versus IT prioritization challenges (69%) and speed of business requirements (45%).
The report also highlights ransomware and supply chain risks as the top information security risks, with phishing following closely behind. The top 10 cybersecurity initiatives planned to mitigate risks have remained unchanged from 2024 to 2025, with business continuity and disaster recovery strategies as the top response (54%).
A rise in security spend is also noted in the report, with an average annual IT spend as a percentage of revenue at 4.2% in 2025. Workforce costs dominate security spending, with 3% allocated to training, followed by an increase in third-party security services spending (11%).
Read the full report here.