Cohesity, the leader in AI and data security, today released its fifth annual Cohesity Global Cyber Resilience Report, finding that 78% of organizations focus cyber recovery efforts on restoring systems rather than maintaining business operations. Restoring systems alone, however, does not guarantee a business can resume normal operations. Recovery depends on more, including whether restored environments can be verified as clean and safe, applications and dependencies are functioning properly, and employees have reliable access to systems and data.

The independent study, conducted by Vanson Bourne, surveyed 3,200 IT and security decision-makers across 12 countries. The research examined where recovery plans fall short during actual attacks, how organizations define business continuity during recovery, and how well current plans account for AI systems and emerging frontier AI threats. The findings were announced at Cohesity Catalyst 2026.

“The research makes clear that many organizations still view recovery as a technology exercise when it is fundamentally a business imperative,” said Vasu Murthy, chief product officer, Cohesity. “True resilience is measured by an organization’s ability to continue operating, meet customer commitments, and recover quickly during a cyber crisis. AI makes the challenge more urgent by increasing the speed of attacks while adding new systems, data, and workflows. That same speed and scale is why AI also has to be part of the answer — strengthening how organizations detect, recover, and restore trust at machine speed.”

Restoring systems does not mean the business has recovered

The research found that organizations may struggle to resume normal operations even after systems are restored. Among those that experienced a material cyberattack in the past 12 months, 60% encountered moderate or significant delays because they lacked confidence that restored data and systems were clean and safe to use. Sixty percent also reported identity or access issues after systems were restored.

The scope of affected systems expanded beyond the initial assessment for 70% of those organizations. At the same time, an average of 61% identified moderate or significant gaps in how their plans accounted for cloud infrastructure, SaaS applications, identity services, security tooling, third-party integrations, and AI systems. For recovery teams, changes in scope or incomplete dependency information can affect what is restored, in what order, and what must be revisited as the response progresses.

These recovery complications are significant because most plans depend on conditions that may not hold during an actual attack. Across the full sample of surveyed organizations, 93% said their cyber response and recovery plans rely on all five assumptions examined in the research: containment, dependency visibility, recovery sequencing, decision-making clarity, and trusted restoration.

The business side of recovery is rarely formalized and tested

A Minimum Viable Company (MVC) helps organizations narrow the scope of recovery to minimize business disruption by defining what must be restored first. While 37% of research participants have formally documented an MVC, only 22% have both documented and tested it. Among that group, 64% said their MVC directly determined what was prioritized and restored first during a material cyberattack. The findings suggest that defining and testing an MVC can influence recovery priorities, but only if organizations operationalize it during an attack.

AI is becoming operational before it becomes recoverable

Recovery priorities must also account for the technologies the business increasingly depends on. The research found that although AI is widely used, it is not yet comprehensively addressed in most recovery plans. AI systems, applications, workflows, or machine learning models are now used by 99% of organizations, yet only 39% say their cyber response and recovery plans comprehensively account for attacks targeting them.

Organizations also reported readiness gaps when responding to AI-related incidents, with 56% saying they are not well prepared to detect, contain, and recover from unintended or incorrect actions taken by AI agents, copilots, or AI workflows. Similarly, confidence in verifying the integrity of AI models and related data following a cyberattack was low, with 58% reporting they were not very confident.

Frontier AI raises the stakes for recovery planning

Organizations expect frontier AI to place further pressure on existing recovery approaches. Eighty-three percent said their plans would require moderate or significant changes to address attacks involving capabilities such as vulnerability discovery, exploit development, and multi-step intrusions. Only 3% of respondents said their current recovery plans are equipped for those conditions.

Download the full Cohesity Global Cyber Resilience Report for deeper insights into cyber response and recovery, operational resilience, and AI readiness.

Methodology: Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across Australia, Brazil, France, Germany, India, Japan, Saudi Arabia, Singapore, South Korea, the United Arab Emirates the United Kingdom, and the United States in July 2026. For the purposes of this research, a material cyberattack was defined as having a measurable financial, reputation, operational and/or customer churn impact on their organization.

About Cohesity

Cohesity protects, secures, and provides insights into the world’s data. As the leader in AI and data security, Cohesity helps organizations strengthen resilience, accelerate recovery, and reduce IT costs. With Zero Trust security and advanced AI/ML, Cohesity Data Cloud is trusted by customers in more than 140 countries, including two-thirds of the Global 500. Cohesity is also backed by industry leaders such as NVIDIA, Amazon, Google, IBM, Cisco, and HPE.

Cohesity is certified as a Great Place to Work in multiple countries. Follow Cohesity on LinkedIn and visit www.cohesity.com to learn more.

Media gallery

About The Author