Cohesity: Cyber Recovery Plans Need Business Operations Design, Not Just Restoration
TECHWORLD ·
✦ AI Summary
Cohesity on the 22nd released the fifth annual Cohesity Global Cyber Resilience Report.
The report said domestic companies' cyber recovery plans are centered on restoring IT systems rather than maintaining business operations.
The survey was conducted among 3,200 IT and security decision-makers in 12 countries and examined gaps in recovery plans during real attack scenarios, as well as how well AI systems and frontier AI threats are reflected.
Cohesity on the 22nd released the fifth annual Cohesity Global Cyber Resilience Report. The report said domestic companies' cyber recovery plans are centered on restoring IT systems rather than maintaining business operations. It added that this imbalance was cited as a factor delaying the resumption of normal operations after a cyber crisis response.
The survey was conducted among 3,200 IT and security decision-makers in 12 countries. The report examined gaps in recovery plans during real attack scenarios, how companies define business continuity in their recovery processes, and how well current plans reflect AI systems and emerging frontier AI threats.
The report said 78% of domestic companies worldwide are focusing their cyber recovery efforts on system restoration rather than maintaining business operations. It said restoring systems alone is not enough for companies to resume normal operations.
It also explained that successful recovery requires verifying that the restoration environment is clean and safe, that applications and dependencies are functioning properly, and that employees can access systems and data securely.
The survey found that 56% of domestic companies that experienced a material cyberattack in the past 12 months suffered moderate or severe delays because they lacked confidence that restored data and systems were clean and safe for use; the global figure for the same item was 60%. It also found that 56% of domestic companies said they experienced identity or access issues after system restoration, compared with 60% globally.
Domestic and overseas companies said the scope of damage was broader in actual response and recovery than they had initially assessed. In domestic companies, 63%, and globally, 70%, said the range of systems affected expanded beyond the initial assessment during actual response and recovery. In addition, an average of 61% of Korean companies and 61% globally said there were moderate or severe gaps in their response and recovery plans. The gaps cited included cloud infrastructure and SaaS applications, identity services, security tools, third-party integrations, and AI systems.
The severity of this recovery complexity was attributed to the fact that many plans depend on conditions that may not be effective in a real attack. Among domestic companies in the survey, 88%, and globally, 93%, said their cyber response and recovery plans are based on five assumptions. The five assumptions are containment, dependency visibility, recovery sequencing, decision-making clarity, and trusted restoration.
The report said domestic companies are falling short in their MVC response. It also said recovery readiness is not keeping pace with the rapid rise of AI, and that advanced frontier AI is increasing the recovery burden. The share of domestic companies with formal MVC documentation was 23%, while the global share was 37%.
Among domestic companies, 15% had both documented and tested MVC, while the global figure for both documentation and testing was 22%. The share of domestic companies using AI systems, applications, workflows, and machine learning models was 96%, compared with 99% globally.
Among domestic companies, 46% said AI-targeted attacks had been comprehensively reflected in their cyber response and recovery plans, while 39% globally gave the same response. The report said that although many domestic companies are using AI, they remain insufficiently prepared for AI-related incident response.
In domestic companies, 51% said they are not well prepared to detect, isolate, and recover from unintended or incorrect actions by AI agents, copilots, and AI workflows, and 56% globally gave the same answer. In addition, 64% of domestic companies said they were not highly confident in verifying the integrity of AI models and related data after a cyberattack, while 58% globally said the same.
The survey showed a high need for improvements to current recovery plans from the perspective of responding to advanced attacks, both domestically and overseas. In domestic companies, 82%, and globally, 83%, said their current recovery plans need moderate or major changes. The reasons cited for those changes included responding to attacks using vulnerability discovery, exploit development, and multi-stage intrusion capabilities. By contrast, only 4% of domestic companies and 3% of global companies said their current recovery plans are sufficient.
In response, Lee Sang-hoon, head of Cohesity Korea, said that as AI- and cloud-centric work environments expand, cyber recovery has shifted from a simple technical task to a business issue for safely resuming core operations. He added that domestic companies need recovery strategies focused on validating real business continuity, not just restoring systems.
Lee Sang-hoon said advance assessment is needed for the recovery priorities of core operations. He also said a comprehensive advance review is needed of vulnerabilities, dependencies, protection scope, and compromise indicators across the operating environment, including core infrastructure and external third parties. He added that recovery procedures should be tested regularly in a trusted environment, and stressed that combining preventive risk management with verified recovery capabilities will serve as the basis for sustained growth and innovation.
Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407257
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.