Report by Cohesity
Global Cyber Resilience Report
Key Findings
Among organizations that experienced a material cyberattack in the past 12 months, 60% encounter moderate or significant delays because they lack confidence that restored data and systems are clean and safe to use
60% of organizations that experienced a material cyberattack report identity or access issues after systems are restored
Only 3% of organizations say their current recovery plans are equipped to handle frontier AI attack conditions
78% of organizations prioritize restoring systems over maintaining business operations
22% of organizations have both documented and tested a Minimum Viable Company (MVC)
Among organizations that have both documented and tested an MVC, 64% say the MVC directly determines what is prioritized and restored first during a material cyberattack
For organizations that experienced a material cyberattack, the scope of affected systems expands beyond the initial assessment for 70% of them
93% of organizations say their cyber response and recovery plans rely on the five assumptions of containment, dependency visibility, recovery sequencing, decision-making clarity, and trusted restoration
37% of organizations have formally documented a Minimum Viable Company (MVC)
99% of organizations use AI systems, applications, workflows, or machine learning models
Only 39% of organizations say their cyber response and recovery plans comprehensively account for attacks targeting AI systems
56% of organizations say they are not well prepared to detect, contain, and recover from unintended or incorrect actions taken by AI agents, copilots, or AI workflows
An average of 61% of organizations identify moderate or significant gaps in how their plans account for cloud infrastructure, SaaS, identity services, security tooling, third-party integrations, and AI systems
58% of organizations report they are not very confident in verifying the integrity of AI models and related data following a cyberattack
83% of organizations say their recovery plans require moderate or significant changes to address attacks involving frontier AI capabilities such as vulnerability discovery, exploit development, and multi-step intrusions