Veeam
Reports
All Statistics
32% of organizations say market expansion triggers action on data sovereignty.
38% of organizations identify public cloud environments as a major visibility gap.
99% of enterprise decision-makers agree that data sovereignty is critical.
On average, organizations recover 72% of affected data following a ransomware attack.
33% of organizations cite regulatory shifts as a top emerging threat.
42% of organizations report limited visibility into all AI tools or models used across the organization.
76% of leaders rated compliance pressures around data sovereignty as extremely or moderately important.
66% of IT leaders view AI-generated attacks as the most significant threat to data security, surpassing ransomware at 50%.
49% of IT leaders cited cybersecurity threats as the biggest disruptor in 2026.
37% of financial services organizations are dealing with higher costs passed on by ICT vendors as a consequence of DORA.
96% of EMEA financial services organizations believe they need to improve their resilience to meet DORA requirements.
34% of financial services organizations cite third-party risk oversight as the most challenging DORA requirement to implement.
Less than half of organizations had key technical elements included in their ransomware playbook.
Of organizations that paid a ransom, 60% paid less than half of the initial ransom.
A pre-defined “chain of command” was included in the ransomware playbook for 30% of organizations.
45% of UK organizations identify data used for AI and analytics as their biggest blind spot, the highest rate in Europe.
38% of organizations in MEA report reliance on third-party ecosystems and vendors, increasing supply-chain blind spots.
44% of organizations cite reducing the risk of data breaches as a top motivator for data sovereignty action.
43% of organizations cite gaining greater control over data as a top motivator for data sovereignty action.
34% of organizations identify cross-border data flows as a major visibility gap.
33% of organizations identify third-party vendors as a major visibility gap.
40% of EMEA leaders name data used for AI or analytics as their top operational blind spot.
58% of UK organizations cite preventing data breaches as the primary reason for data sovereignty efforts.
82% of German leaders say accelerating AI development takes priority over establishing data controls.
90% of organizations report high confidence in established frameworks such as GDPR.
68% of organizations prioritize broader digital transformation initiatives over establishing strong data controls.
33% of organizations say internal audits and compliance reviews trigger action on data sovereignty.
72.5% of EMEA organizations are actively deprioritizing data sovereignty in favor of accelerating AI.
46% of French leaders cite protecting intellectual property and sensitive information as a primary motivation for data sovereignty.
60% of organizations in Middle East and Africa (MEA) have fully operationalized data sovereignty.
88% of enterprises are running AI agents, but only 7% are fully prepared to manage them.
32% of organizations report major challenges with Shadow IT where systems are deployed outside of IT governance.
44% of organizations say increased cyber risk is the top "Shadow AI" risk.
88% of organizations are already using or piloting AI agents.
Only 28% of organizations are confident they can detect AI systems operating outside approved parameters.
65% of CEOs believe they have a full AI inventory.
83% of CEOs feel pressure to accelerate their AI and data capabilities.
Only 29% of organizations running AI today can identify within minutes which systems an AI accessed.
Only 25% of organizations running AI today can identify within minutes what actions an AI took.
Only 24% of organizations running AI today can identify within minutes what decisions an AI influenced.
Only 40% of leaders are very confident they can isolate and precisely reverse an agentic AI failure.
95% of organizations report unauthorized AI use within their organization.
Organizations relying on shared ownership are 47% less likely to detect rogue AI behavior.
Organizations where CISOs own AI agent risk are 24% more likely to detect rogue AI behavior.
97% of organizations classified as fully AI-ready report measurable business benefits from data and AI investments.
93% of organizations view unauthorized AI use as a significant risk.
61% of organizations say the EU AI Act has already influenced AI investment strategies in the last 12 months.
47% of organizations cite maintaining audit trails for AI decisions as their biggest compliance concern.
95% of organizations say data challenges have already slowed their AI progress.
48% of technical leaders believe they have a full AI inventory.