Cohesity Releases 5th Annual Global Cyber Resilience Report
Cohesity, a global AI and data security company, has released its fifth annual Global Cyber Resilience Report, revealing that 99% of Indian organisations surveyed believe their cyber response and recovery plans need changes to address the growing threat of AI-driven cyberattacks.
Indian organisations are already under siege even before frontier AI becomes commonplace. The research also shows that 83% of Indian organisations experienced at least one material cyberattack in the past 12 months, highlighting the pressure organisations face to ensure recovery plans work not only on paper, but under real-world attack conditions.
In India, 41% of respondents say the changes required to their cyber response and recovery plans would be significant, while 44% say the changes required would be moderate to operate effectively under scenarios involving frontier AI models.
The finding is specific to scenarios in which frontier AI models could accelerate and automate attack capabilities from vulnerability discovery and exploit development to autonomous, multi-step attack execution.
For Indian organisations, this points to the need to test whether recovery plans can withstand more complex attack scenarios, rather than relying only on plans designed around more predictable recovery conditions.
Also Read: How to Safeguard Businesses Against Cybersecurity Threats in 2026
Among Indian organisations that experienced a material cyberattack in the past 12 months, 87% experienced at least some delay in resuming normal business operations because they lacked confidence that restored data and systems were clean and safe to use. For 60%, the delay was moderate or significant.
This highlights the difference between technical restoration and business recovery. Getting systems back online is only part of the challenge; organisations also need confidence that restored environments can be trusted before normal operations can safely resume.
A Minimum Viable Company (MVC) helps organisations narrow the scope of recovery to minimise business disruption by defining what must be restored first.
Among Indian organisations that experienced a material cyberattack in the past 12 months, 79% agree that their organisation recognises the importance of an MVC but has not yet proven in practice that it would work during a cyberattack.
The findings suggest that defining and testing an MVC can help organisations focus recovery on maintaining essential business operations, rather than simply restoring individual systems.
Indian organisations are increasingly using AI across their environments, but only 44% of Indian organisations say their cyber response and recovery plans comprehensively account for attack scenarios targeting AI systems and applications, AI workflows or machine learning models. This leaves 56% whose plans do not comprehensively cover these scenarios.
The research also points to gaps in preparedness for AI-related incidents. The majority (53%) of Indian organisations are not well prepared to detect and contain unintended or incorrect actions taken by AI agents, copilots or AI workflows, and recover affected systems or data.
Also Read: Cyber Security: One Of The Most Important Infrastructures In A Company
"The research shows that many organisations still view recovery as a technology exercise when it is fundamentally a business imperative," said Mayank Mishra, Senior Regional Director, Sales, India & SAARC, Cohesity. "True resilience is measured by an organisation's ability to continue operating, meet customer commitments, and recover quickly during a cyber crisis. AI compounds the challenge by increasing the speed of attacks while adding new systems, data, and workflows. As Indian enterprises accelerate the adoption of AI, that same speed and scale is why AI also has to be part of the answer — strengthening how organisations detect, recover, and restore trust at machine speed."



