Loading

GLOBAL CYBER RESILIENCE REPORT

Is your recovery plan ready for today's threats, and the emerging ones still ahead? New research reveals what most organizations are missing.
Report cover stack

The world changed. Recovery plans haven’t.

Material cyberattacks are becoming more frequent

73% of organizations globally experienced one in the past 12 months, up from 54% the year before.

Attacks are also becoming more complex

AI and autonomous agents create new risks. Cloud and SaaS sprawl widens their reach.

Most recovery plans aren't built for this kind of pressure 

They assume incidents are understood, dependencies are mapped, and recovery is predictable.

The 5th annual Cohesity Global Cyber Resilience Report, conducted by Vanson Bourne, surveyed 3,200 IT and security leaders across 12 countries to reveal how those plans hold up under real pressure.

Outdated assumptions are still shaping recovery plans

Respondents who experienced a material cyberattack in the last 12 months

Assumption

83%

assume incidents can be fully contained before recovery begins.

containment icon
Reality

70%

saw the scope expand beyond their initial assessment.

Assumption

84%

assume dependencies are mapped clearly enough to sequence recovery accurately in advance. 

dependencies icon
Reality

61%

found moderate to significant gaps in dependencies they hadn't accounted for. 

Assumption

86%

assume once core systems are restored, business operations can safely resume.

operations icon
Reality

69%

experienced delays in resuming normal business operations, even after core systems were restored.

Minimum Viable Company (MVC):
defined in advance, not assumed

An MVC is the smallest version of the business that can continue serving customers and maintaining critical operations while broader recovery continues. It's a defined operating model about what matters most, decided before a crisis hits.

Venn diagram
Connector
22 percent
Only 22% have formally documented and tested an MVC.
66 percent
66% haven’t validated that their MVC would perform as intended during a cyberattack.
78 percent
78% say their cyber recovery plan is more focused on restoring systems than maintaining critical business operations during recovery.

AI is the next frontier for cyber resilience

AI is becoming more capable and more embedded in how organizations operate. That’s introducing risks that recovery plans haven't yet accounted for, from the AI already in use today to the more capable models still to come.

0%

are not very confident they can verify AI model integrity after an incident.
Model Integrity AI icon

0%

are not well prepared to detect or contain unintended actions by AI agents or workflows.
AI workflow containment icon

0%

say their recovery plan would require moderate or significant changes to withstand cyberattacks accelerated by frontier AI models.
AI recovery plan icon
Read the full report

Global Cyber Resilience Report

Thank you for your interest.

thankyou-hero-banner

Recovery has changed. Have the plans?

Explore findings by market and industry
Global
Australia
Coming soon
Brazil
Coming soon
France
Coming soon
Germany
Coming soon
India
Coming soon
Japan
Coming soon
Singapore
Coming soon
South Korea
Coming soon
United Arab Emirates
Coming soon
United Kingdom
Coming soon


Industry reports
Financial
Coming soon
Healthcare
Coming soon
Public Sector
Coming soon
Manufacturing
Coming soon
Retail
Coming soon
Telco
Coming soon
Energy, oil & gas
Coming soon
Commercial
Coming soon
Loading