Just 2 per cent of Australian organisations believe their current cyber recovery plans can withstand threats from frontier AI technologies, according to new research from Cohesity.
The company’s Global Cyber Resilience Report found 98 per cent believe their plans need changes, including 37 per cent who say significant changes are required.
The findings come as Australian organisations find themselves increasingly at the pointy end of malicious cyber activity, with 80 per cent experiencing a material cyber attack in the past 12 months, compared with 73 per cent globally. Overall, 95 per cent say they have been impacted by a material cyber attack at some point.
While 99 per cent have a cyber resilience strategy, 53 per cent say it still needs improvement. Among organisations attacked in the past year, 92 per cent said their recovery would likely require workarounds or improvisation, while 87 per cent took longer to recover than expected.
Cohesity said organisations are also making assumptions that may not hold during a live attack, including that threats will be contained before recovery begins and that recovery can proceed in a largely linear sequence.
The report also found gaps in Minimum Viable Company (MVC) planning, which identifies the people, processes, and technology needed to keep critical business functions running during a disruption.
While 74 per cent of Australian organisations have identified the critical functions needed to operate during a disruption, just 20 per cent have formally documented and tested an MVC, compared with 22 per cent globally.
“The challenge for leaders is no longer simply preventing an attack. It is ensuring the business can continue to operate and recover with confidence when an attack breaches the defences,” James Eagleton, managing director, ANZ, at Cohesity, said in a statement.
“Australia’s focus on Minimum Viable Company planning is encouraging, but identifying critical operations is only the first step. Organisations must formally document and regularly test whether these plans can support the business under real-world attack conditions. That requires realistic resilience strategies, as recovery is rarely straightforward – more systems may be affected than initially expected, and leaders often need to make critical decisions with incomplete information. In a real-life scenario, organisations with a proven and tested cyber recovery plan can be confident, as this nullifies the leverage an attacker will attempt to use.”
AI resilience is another weak point. Almost half of those polled (47 per cent) lack a centralised inventory or clear understanding of AI agents, copilots, and workflows, while only 40 per cent have recovery plans that comprehensively account for attacks targeting AI systems.
Just 38 per cent are very confident they could verify an AI model and associated data integrity following an incident, while 44 per cent say they can detect, contain, and recover from unintended AI actions.
Cohesity’s research was conducted in July 2026 by Vanson Bourne. The study surveyed 3,200 IT and security leaders across Australia, Brazil, France, Germany, India, Japan, Singapore, South Korea, the United Arab Emirates, Saudi Arabia, the United Kingdom, and the United States.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.