Report by Veeam
Data Trust and Resilience Report 2026
Key Findings
On average, organizations recover 72% of affected data following a ransomware attack.
33% of organizations cite regulatory shifts as a top emerging threat.
42% of organizations report limited visibility into all AI tools or models used across the organization.
40% of organizations say security policies have not yet been updated to address AI-specific risks.
Among organizations hit by ransomware where operations or data were affected, only 28% fully recovered all affected data.
43% of organizations say AI adoption is outpacing their ability to secure data and models.
36% of organizations cite cyberattacks as a top emerging threat.
42% of organizations that experienced a cyber incident report customer or constituent disruption.
41% of organizations that experienced a cyber incident report financial loss or revenue impact.
25% of organizations say shadow IT and unauthorized AI tool usage are a primary concern related to employee AI tool use and data security.
69% of organizations say their recovery time objectives (RTOs) are fully aligned with business continuity goals.
49% of organizations increased cybersecurity budgets year-over-year.
90% of organizations say they can recover from a cyber incident within their recovery time objectives (RTOs).
38% of organizations that experienced a cyber incident report extended downtime of critical systems.
Full data recovery is 40% among organizations reporting increased cybersecurity budgets versus 16% among organizations without increased budgets.
Among organizations hit by ransomware where operations or data were affected, 44% recovered less than 75% of affected data.