-
78% of organizations prioritize restoring systems over maintaining business operations
-
Only 22% have tested how critical operations would continue during recovery
-
Just 3% say current plans are equipped for frontier AI threats
Cohesity, the leader in AI and data security, released its fifth annual Cohesity Global Cyber Resilience Report, finding that 78% of organizations focus cyber recovery efforts on restoring systems rather than maintaining business operations. Restoring systems alone, however, does not guarantee a business can resume normal operations. Recovery depends on more, including whether restored environments can be verified as clean and safe, applications and dependencies are functioning properly, and employees have reliable access to systems and data.
Also Read: CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight
The independent study, conducted by Vanson Bourne, surveyed 3,200 IT and security decision-makers across 12 countries. The research examined where recovery plans fall short during actual attacks, how organizations define business continuity during recovery, and how well current plans account for AI systems and emerging frontier AI threats. The findings were announced at Cohesity Catalyst 2026.
“The research makes clear that many organizations still view recovery as a technology exercise when it is fundamentally a business imperative,” said Vasu Murthy, chief product officer, Cohesity. “True resilience is measured by an organization’s ability to continue operating, meet customer commitments, and recover quickly during a cyber crisis. AI makes the challenge more urgent by increasing the speed of attacks while adding new systems, data, and workflows. That same speed and scale is why AI also has to be part of the answer — strengthening how organizations detect, recover, and restore trust at machine speed.”
Restoring systems does not mean the business has recovered
The research found that organizations may struggle to resume normal operations even after systems are restored. Among those that experienced a material cyberattack in the past 12 months, 60% encountered moderate or significant delays because they lacked confidence that restored data and systems were clean and safe to use. Sixty percent also reported identity or access issues after systems were restored.
The scope of affected systems expanded beyond the initial assessment for 70% of those organizations. At the same time, an average of 61% identified moderate or significant gaps in how their plans accounted for cloud infrastructure, SaaS applications, identity services, security tooling, third-party integrations, and AI systems. For recovery teams, changes in scope or incomplete dependency information can affect what is restored, in what order, and what must be revisited as the response progresses.
These recovery complications are significant because most plans depend on conditions that may not hold during an actual attack. Across the full sample of surveyed organizations, 93% said their cyber response and recovery plans rely on all five assumptions examined in the research: containment, dependency visibility, recovery sequencing, decision-making clarity, and trusted restoration.
The business side of recovery is rarely formalized and tested
A Minimum Viable Company (MVC) helps organizations narrow the scope of recovery to minimize business disruption by defining what must be restored first. While 37% of research participants have formally documented an MVC, only 22% have both documented and tested it. Among that group, 64% said their MVC directly determined what was prioritized and restored first during a material cyberattack. The findings suggest that defining and testing an MVC can influence recovery priorities, but only if organizations operationalize it during an attack.
AI is becoming operational before it becomes recoverable
Recovery priorities must also account for the technologies the business increasingly depends on. The research found that although AI is widely used, it is not yet comprehensively addressed in most recovery plans. AI systems, applications, workflows, or machine learning models are now used by 99% of organizations, yet only 39% say their cyber response and recovery plans comprehensively account for attacks targeting them.
Organizations also reported readiness gaps when responding to AI-related incidents, with 56% saying they are not well prepared to detect, contain, and recover from unintended or incorrect actions taken by AI agents, copilots, or AI workflows. Similarly, confidence in verifying the integrity of AI models and related data following a cyberattack was low, with 58% reporting they were not very confident.
Catch more CIO Insights: How Are CIOs Aligning Technology with Workforce Agility?
[To share your insights with us, please write to psen@itechseries.com ]

