...

Cohesity Study Finds Most Cyber Recovery Plans Are Built for the Wrong Outcome 

Cyber recovery plans

Cohesity today published its fifth annual Global Cyber Resilience Report. Consequently, the study reveals that 78% of enterprise organizations build cyber recovery plans primarily to restore computer systems rather than maintain ongoing business operations. Restoring infrastructure alone does not guarantee a full business recovery. Instead, organizations must verify clean environments, test application dependencies, and ensure secure employee access. Therefore, traditional recovery plans frequently fail to protect real-world operational continuity during modern cyber crises.

Vanson Bourne conducted this independent research across 12 countries, surveying 3,200 security and IT decision-makers. The detailed report evaluates where standard recovery plans fall short during live ransomware attacks. Furthermore, the findings highlight severe gaps regarding artificial intelligence systems and emerging frontier threats. Cohesity officially announced these findings during the Cohesity Catalyst 2026 conference.

“The research makes clear that many organizations still view recovery as a technology exercise when it is fundamentally a business imperative,” said Vasu Murthy, chief product officer, Cohesity. “True resilience is measured by an organization’s ability to continue operating, meet customer commitments, and recover quickly during a cyber crisis. AI makes the challenge more urgent by increasing the speed of attacks while adding new systems, data, and workflows. That same speed and scale is why AI also has to be part of the answer strengthening how organizations detect, recover, and restore trust at machine speed.”

Addressing Hidden Delays and Critical System Dependencies

The survey demonstrates that companies struggle to resume routine operations even after IT teams restore main systems. Among organizations suffering a material cyberattack recently, 60% encountered major delays due to unverified data safety. Moreover, 60% experienced serious identity and access management problems post-recovery.

Seventy percent of impacted businesses also found that the extent of damage was much worse than the preliminary estimates. At the same time, 61% said they had critical gaps in their recovery plans around cloud infrastructure, SaaS tools, and identity services. A lack of complete dependency information results in security teams needing to revisit previously restored environments multiple times during active incidents.

Formalizing Business Continuity and AI Risk Management

Moreover, knowing a Minimum Viable Company (MVC) helps organizations to zero in on key operations in a crisis. Of the respondents that documented an MVC, 37% tested those procedures. 64 percent of that prepared group were able to successfully prioritize critical workloads during real-world cyber events.

However, new technologies create new operational vulnerabilities across sectors. 99% of businesses use AI tools today, but only 39% have AI infrastructure included in their recovery plans. Additionally, 56% believe they can’t handle autonomous AI errors, and 58% are uncertain they can validate AI data integrity after attacks. Lastly, 83% agree that fast frontier AI development requires urgent and substantial changes to current recovery plans. 

For related updates on digital trust and cybersecurity, explore our SOC News.

News Source: Businesswire