Loading

PUBLIC SECTOR CYBER RESILIENCE REPORT

Is your agency's recovery plan ready for today's threats, and the emerging ones still ahead? New research reveals what most public sector organizations are missing.
Report cover stack

The world changed. Recovery plans haven’t.

Material cyberattacks are becoming more frequent

77% of public sector organizations experienced one in the past 12 months, up sharply from 49% the year before.

Attacks are also becoming more complex

AI and autonomous agents create new risks. A growing web of connected agency, citizen-facing, and third-party systems widens their reach.

Most recovery plans aren't built for this kind of pressure 

They assume incidents are understood, dependencies are mapped, and recovery is predictable.

The 5th annual Cohesity Global Cyber Resilience Report, conducted by Vanson Bourne, surveyed more than 400 IT and security leaders in the public sector across 12 countries to reveal how those plans hold up under real pressure.

Outdated assumptions are still shaping recovery plans

Respondents who experienced a material cyberattack in the last 12 months

Assumption

78%

assume incidents can be fully contained before recovery begins.

containment icon
Reality

74%

saw the scope expand beyond their initial assessment.

Assumption

77%

assume dependencies are mapped clearly enough to sequence recovery accurately in advance.

dependencies icon
Reality

70%

found moderate to significant gaps in dependencies they hadn't accounted for.

Assumption

79%

assume once core systems are restored, business operations can safely resume.

operations icon
Reality

76%

experienced delays in resuming normal business operations, even after core systems were restored.

Minimum Viable Entity (MVE):
defined in advance, not assumed

A Minimum Viable Entity is the smallest set of public and administrative capabilities — emergency services, benefits payments, citizen record access — an agency must keep running while broader recovery continues. It's a defined operating model about what matters most, decided before a crisis hits.

Venn diagram
Connector
22 percent
Only 14% have formally documented and tested an MVE.
66 percent
75% haven't validated that their MVE would perform as intended during a cyberattack.
78 percent
79% say their cyber recovery plan is more focused on restoring systems than maintaining critical citizen-facing services during recovery.

AI is the next frontier for cyber resilience in the public sector

AI is becoming more capable and more embedded in citizen services, case management, and administrative workflows. That's introducing risks recovery plans haven't yet accounted for, from the AI already in use today to the more capable models still to come.

0%

are not very confident they can verify AI model integrity after an incident.
Model Integrity AI icon

0%

are not well prepared to detect or contain unintended actions by AI agents or workflows.
AI workflow containment icon

0%

say their recovery plan would require moderate or significant changes to withstand cyberattacks accelerated by frontier AI models.
AI recovery plan icon
Read the full report

Public Sector Cyber Resilience Report

Thank you for your interest.

thankyou-hero-banner

Recovery has changed. Have the plans?

Explore findings by market and industry
Global
Australia
Coming soon
Brazil
Coming soon
France
Coming soon
Germany
Coming soon
India
Coming soon
Japan
Coming soon
Singapore
Coming soon
South Korea
Coming soon
United Arab Emirates
Coming soon
United Kingdom


Industry reports
Financial
Healthcare
Public Sector
Manufacturing
Coming soon
Retail
Coming soon
Telco
Coming soon
Energy, oil & gas
Coming soon
Commercial
Coming soon
Loading