Cohesity, a data backup and cyber recovery vendor, has found that organizations that suffered a material cyberattack took nearly twice as long to recover as their own recovery-time objective, on average.
The finding comes from Cohesity’s “Global Cyber Resilience Report,” based on a Vanson Bourne survey of 3,200 IT and security decision-makers at organizations with at least 1,000 employees across 12 countries. Nearly three-quarters (73%) said their organization had experienced a material cyberattack in the previous 12 months, up from 54% in Cohesity’s 2025 survey.
Among organizations that experienced such an attack, 76% said recovery exceeded their recovery-time objective. During recovery, 70% discovered that more systems had been affected than initially thought. Across the dependencies Cohesity measured, an average of just over 60% reported moderate or significant gaps in how their plans accounted for identity systems, third-party APIs and AI pipelines.
Restored systems were not necessarily ready
Getting systems back online did not always end the disruption. Cohesity found that about 70% of affected organizations did not always test identity systems after an attack to verify that attacker access and persistence mechanisms had been removed.
Cohesity said about 70% of affected organizations encountered all seven recovery-delay factors it measured. The share reporting moderate or significant delays was lower for individual factors: 63% for reconciling business activity since the last backup, 60% for uncertainty over whether restored systems were clean, 60% for identity or access problems and 59% for unvalidated or malfunctioning dependencies.
Among organizations that experienced a material cyberattack, almost 85% said differences between IT and security teams can slow decisions over when recovered systems are safe to return to production.
Those findings expose a difference between restoring infrastructure and resuming normal operations. More than three-quarters of all respondents, 78%, said their recovery plans focus more on restoring systems than maintaining critical operations and serving customers while recovery is underway. Among organizations that had suffered an attack, 76% said they prioritize recovery speed over certainty that restored systems are clean and safe.
Only 22% of respondents had formally documented and tested a “Minimum Viable Company,” Cohesity’s term for the smallest set of operations needed to continue serving customers during recovery. Among those organizations, a little over 90% said that exercise influenced their recovery priorities, while about 65% said it directly determined what was restored first during an attack.
Spending still favors prevention
Investment remains weighted toward the earlier stages of an attack. Only 34% of cyber resilience spending went to the NIST framework’s Respond and Recover functions, while 73% of respondents said too much of their organizations’ spending still goes toward prevention. The report said overall investment priorities remained largely unchanged from the previous year.
Cohesity’s figures are self-reported survey data rather than independently audited records of cyber incidents. The company commissioned the research and sells backup and cyber recovery software. The survey was conducted in July across Australia, Brazil, France, Germany, India, Japan, Saudi Arabia, Singapore, South Korea, the United Arab Emirates, the U.K. and the U.S.