Business leaders once treated cyberattacks as distant threats best left to the IT department. No longer. A single successful breach now serves as the harshest possible examination of whether an organization can keep operating when systems go dark.
Nearly half of chief information security officers who lived through a cyber incident watched operations grind to a halt. The figure comes from fresh analysis reported yesterday by TechRadar. Operational shutdowns hit 47 percent of those surveyed. That outpaced both data loss at 41 percent and direct revenue hits at 40 percent.
But the numbers get worse. Seventy-three percent of those same CISOs admit they lack confidence they could handle a major incident tomorrow. Despite years of new security tools and bigger budgets, preparedness has not kept pace. And the consequences stretch far beyond immediate downtime.
Coordination collapses under pressure. Ninety percent of organizations would struggle to bring the right stakeholders together quickly during a serious event. Seventy-five percent point to delays or confusion over legal and communications roles as factors that drag out decision-making and slow any chance of recovery. These are not abstract risks. They are measurable failures playing out in boardrooms right now.
Reality bites hard.
Recent research from Cohesity paints an even bleaker picture. Seventy-eight percent of organizations still direct their cyber recovery efforts toward simply restoring systems instead of keeping business processes alive. The Cohesity Global Cyber Resilience Report, released in September, makes clear that restoring servers does not equal resuming operations.
Among companies hit by a material cyberattack in the past year, sixty percent faced moderate or significant delays after restoration because they could not trust that the recovered data and systems were clean. The same percentage ran into identity and access problems once systems came back online. For seventy percent, the blast radius of affected systems grew larger than first assessed. On average, sixty-one percent identified notable gaps in how their plans covered cloud infrastructure, software-as-a-service applications, identity services, security tools, third-party connections, and artificial intelligence systems.
Only thirty-seven percent have formally documented a minimum viable company approach. Just twenty-two percent have both documented and tested it. The gap between plans on paper and performance under fire has widened.
Recovery capabilities appear to be eroding in other areas too. An October 2 report from Channel Dive detailed findings that more than four in five respondents experienced an attack disrupting services. That is up from sixty-six percent in similar research a year earlier. Three-quarters suffered more than one ransomware disruption in the past twenty-four months.
Success rates in restoring data have fallen sharply. Only thirty-nine percent of organizations managed to recover at least three-quarters of their data after ransomware attacks, down from fifty-seven percent the previous year. Seventy-six percent said the data lost in their worst incident exceeded their own recovery point objective. Fewer than two in five now maintain recovery time objectives of five business days or less.
“Ransomware can lead to a business continuity crisis, and the data shows that many organizations fall short when it comes to reliable recovery,” said Robinson in the release tied to that report.
Real-world examples keep arriving. The Change Healthcare ransomware attack, part of UnitedHealth Group, affected one hundred million Americans and disrupted claims processing across the health care sector for weeks. Hospitals and providers faced delayed payments and manual workarounds. UnitedHealth eventually paid twenty-two million dollars to the attackers, according to congressional testimony covered in a January 2025 roundup by Chief Healthcare Executive.
Automakers have not escaped. A cyber incident at Jaguar Land Rover halted production and contributed to a seventeen percent drop in retail sales for one quarter. Moody’s responded by cutting the company’s outlook to negative and forecasting a fourteen percent revenue decline for fiscal 2026. The case, examined in depth by Cybersecurity Dive in late 2025, underscored how supply-chain dependencies turn isolated breaches into industry-wide headaches.
Medical device maker Boston Scientific disclosed a cyberattack in late August 2026 that disrupted operating systems and business applications. Order processing and shipments suffered. Employees at manufacturing sites in Ireland were sent home. The incident, still without a claimed perpetrator months later, illustrates how even sophisticated manufacturers can lose control of physical operations when digital systems fail.
But the problem runs deeper than any single sector. Heath Renfrow, CISO and co-founder of Fenix24, reviewed more than eight hundred real recovery engagements for the firm’s 2026 State of Recoverability report. Only four organizations came close to their stated twenty-four to forty-eight hour targets. Most fell behind before technical restoration even started. Identity recovery plans rarely survived first contact with attackers. Complete application dependency maps were nonexistent.
Thirty-eight percent of backups that survived the initial attack still could not support full recovery. The reasons ranged from outdated technology to incomplete testing to lingering malware. These findings, reported September 25 by TechNadu, highlight that many organizations test fragments of their process but never the full sequence under realistic conditions.
Stakeholder alignment suffers in parallel. UK workers now rank cyberattacks as the top threat to business continuity, ahead of physical workplace incidents, according to an April 2026 survey by EcoOnline covered in SecurityBrief. Yet only thirty percent of respondents said they knew their employer had a crisis plan and understood it.
French organizations tell a similar story. Eighty-one percent of those hit by an attack saw restoration take longer than planned. Confidence in cyber resilience strategies dropped from forty-seven percent to thirty-six percent in one year even as nearly all claimed to have a strategy in place. The Cohesity data for France, analyzed by Alliancy in September, shows that having a plan no longer guarantees effective execution.
Vendors compound the difficulty. Eighty-nine percent of respondents in the Object First research said immutability claims from backup providers require independent verification. Only fifty-six percent actually perform third-party testing.
So what separates the prepared few from the majority? Testing matters. Organizations that regularly run full simulations recover faster and suffer fewer disruptions. Tabletop exercises that model ransomware, cloud outages, and even security-tool failures such as the 2024 CrowdStrike incident provide measurable value. Yet roughly fifty-five percent of organizations still do not test their business continuity procedures on a regular basis.
Plans must also shift focus. Instead of asking which systems to restore first, leaders should define the minimum set of processes required to keep revenue flowing, serve customers, and meet regulatory obligations. That minimum viable company concept, tested under simulated attack conditions, offers a practical starting point.
Identity systems deserve special attention. Active Directory and similar platforms are not ordinary applications. When they are compromised, every downstream service suffers. Few organizations arrive at an incident with a tested, attacker-resistant identity recovery strategy.
Third-party risk cannot be ignored either. Supply-chain attacks and software vulnerabilities in widely used platforms like Microsoft SharePoint continue to deliver initial access for ransomware groups such as Warlock. Recent campaigns against water utilities, telecom operators, and universities in Portuguese- and Spanish-speaking regions, documented October 2 by both BleepingComputer and The Record, show that unpatched internet-facing systems remain an open door.
Boards and executives face growing pressure to treat cyber risk as a core business-continuity issue rather than a technology problem. The UK National Cyber Security Centre reported a record two hundred four nationally significant cyberattacks in its latest annual review, with eighteen labeled highly significant. CEO Richard Horne urged corporate leadership to own the risk.
Insurance carriers have noticed. Cyber policies now often require evidence of tested recovery plans and regular tabletop exercises. Premiums reflect the gap between ambition and execution.
The data paints a consistent picture across reports released in the past several weeks. Cyberattacks have become the definitive test of business continuity. And nearly half of organizations are failing it. The difference between those who survive and those who do not increasingly comes down to whether their plans were built for systems or for the business itself.
That distinction will only sharpen as attacks grow more frequent and recovery windows shrink. Leaders who treat recovery as a business exercise rather than an IT task stand a better chance of keeping operations alive when the inevitable test arrives.
Cyberattacks Expose the Fragile State of Business Continuity Planning first appeared on Web and IT News.
The Metropolitan Police has suspended its use of digital forensics software from Oxygen Forensics. The…
Suno built its name on turning simple text prompts into complete songs. Now the company…
Meta launched Muse barely a month ago. The personal AI agent, styled as a helpful…
Security researchers uncovered a vulnerability in OpenAI’s ChatGPT application for macOS that could have handed…
Software used to be simple. One customer, one seat, almost zero incremental cost. Finance teams…
Elite programmers who coax peak performance from Nvidia chips once spent their days crafting intricate…
This website uses cookies.