Cohesity: Recovery plans lag behind frontier AI threats
Cohesity, the AI and data security specialist, has released findings from the 5th annual Cohesity Global Cyber Resilience Report highlighting that only 2% of Singapore organisations are confident in their ability to withstand cyberattacks accelerated by frontier artificial intelligence (AI) models. Forty percent say significant change is needed, higher than the global average of 32% showing Singapore is more attuned to the risks, but gaps in organisational readiness remain.
Even before frontier AI becomes commonplace, many Singapore organisations were already struggling to keep pace with current threats, Cohesity said. While almost every Singapore organisation (99%) has a cyber resilience strategy, the research highlights that these strategies may not withstand real-world scenarios or conditions. Three in five (60%) say their strategy still requires improvement, including 12% who say the improvement needed is significant.
A high proportion (93%) of those attacked in the past 12 months said their current recovery plan would likely need workarounds or improvisation during an attack. Sixty-three percent took longer to recover – about six hours more than their target objective on average.
Seventy-two percent saw more systems affected than initially assessed. Among the most common gaps cited in response and recovery plan were skills and knowledge (73%), managing identity and access with tools like Okta (71%), and AI models, pipelines and workflow tools (69%).
The research found that organisations may struggle to resume normal operations even after systems are restored. Among those that experienced a material cyberattack in the past 12 months, 68% encountered moderate or significant delays because they lacked confidence that restored data and systems were clean and safe to use. Sixty-seven percent also reported identity or access issues after systems were restored.
The scope and sequence of recovery proved similarly difficult to anticipate. Seventy-two percent saw the scope of affected systems expand beyond the initial assessment. On average, 71% also identified moderate or significant gaps in how their plans accounted for dependencies across cloud infrastructure, software-as-a-service (SaaS) applications, identity services, security tooling, third-party integrations, and AI systems.
For recovery teams, changes in scope or incomplete dependency information can affect what is restored, in what order, and what must be revisited as the response progresses. This highlights the gap between technical recovery and true business recovery, Cohesity noted, pointing out that the findings as a whole point to a broader recovery challenge for Singapore organisations.
The Cohesity Global Cyber Resilience Report also found that the potential of the minimum viable company (MVC) concept remains largely untapped. An MVC is the smallest version of a business that can keep serving customers while broader recovery continues. In Singapore, just 15% of organisations report having a formally documented and tested MVC, while 19% have a formally documented MVC that has not yet been tested and 30% rely on an informal or partially documented MVC. Of those with an MVC, 41% said it directly determined what was prioritised and brought back first.
Recovery priorities must also account for the technologies the business increasingly depends on. The research found that although AI is widely used, it is not yet comprehensively addressed in most recovery plans. Ninety-nine percent of organisations use AI systems, applications, workflows, or machine learning models, yet only 44% say their cyber response and recovery plans comprehensively account for attacks targeting them.
Organisations also report readiness gaps when responding to AI-related incidents. Fifty-five percent are not well prepared to detect, contain, and recover from unintended or incorrect actions taken by AI agents, copilots, or AI workflows. Fifty-one percent also reported they were not very confident in their ability to verify the integrity of AI models and related data following a cyberattack.
As AI becomes embedded across customer- facing and internal workflows, failing to treat AI systems as first class dependencies in recovery planning increases the risk that core business processes cannot be restored, even after underlying infrastructure appears to be back online.
“Cyber resilience across ASEAN is no longer simply a technology challenge — it is a business imperative. As organisations across the region accelerate their adoption of AI and deepen digital interconnectivity, the ability to continue operating, meet customer commitments, and recover quickly during a cyber crisis has never been more critical,” said Lim Hsin Yin, VP and GM, ASEAN, Cohesity.
“The growing complexity of third-party integrations, AI models, and automated workflows means organisations must ensure recovery is given the same level of attention as protection. AI is increasing the speed and scale of cyber threats, but it can also be part of the answer — strengthening how organisations detect, recover, and restore trust at machine speed.”
![]() |
| Source: Cohesity landing page. Recovery plans cannot cope with current cyberattack volume or complexity. |
Explore
Download the Cohesity Global Cyber Resilience Report
*The 5th annual Cohesity Global Cyber Resilience Report was conducted in July 2026 by independent research firm Vanson Bourne on behalf of Cohesity. The study surveyed 3,200 IT and security leaders across Australia, Brazil, France, Germany, India, Japan, KSA, Singapore, South Korea, the UAE, the UK, and the US. For the purposes of this research, a material cyberattack was defined as having a measurable financial, reputation, operational and/or customer churn impact on their organisation.

Comments
Post a Comment