Cohesity, the leader in AI and data security, today released findings from the fifth annual Cohesity Global Cyber Resilience Report, highlighting that almost all (99%) Indian organisations surveyed say their cyber response and recovery plans would require some change to operate effectively against scenarios where frontier AI models could accelerate and automate attack capabilities.
Indian organisations are already under siege even before frontier AI becomes commonplace. The research also shows that 83% of Indian organisations experienced at least one material cyberattack in the past 12 months, highlighting the pressure organisations face to ensure recovery plans work not only on paper, but under real-world attack conditions.
Frontier AI is raising the bar for cyber recovery
In India, 41% of respondents say the changes required to their cyber response and recovery plans would be significant, while 44% say the changes required would be moderate to operate effectively under scenarios involving frontier AI models.
The finding is specific to scenarios in which frontier AI models could accelerate and automate attack capabilities from vulnerability discovery and exploit development to autonomous, multi-step attack execution.
For Indian organisations, this points to the need to test whether recovery plans can withstand more complex attack scenarios, rather than relying only on plans designed around more predictable recovery conditions.
Restoring systems does not necessarily mean the business has recovered
Among Indian organisations that experienced a material cyberattack in the past 12 months, 87% experienced at least some delay in resuming normal business operations because they lacked confidence that restored data and systems were clean and safe to use. For 60%, the delay was moderate or significant.
This highlights the difference between technical restoration and business recovery. Getting systems back online is only part of the challenge; organisations also need confidence that restored environments can be trusted before normal operations can safely resume.
Minimum Viable Company: from recovery planning to business continuity
A Minimum Viable Company (MVC) helps organisations narrow the scope of recovery to minimise business disruption by defining what must be restored first.
Among Indian organisations that experienced a material cyberattack in the past 12 months, 79% agree that their organisation recognises the importance of an MVC but has not yet proven in practice that it would work during a cyberattack.
The findings suggest that defining and testing an MVC can help organisations focus recovery on maintaining essential business operations, rather than simply restoring individual systems.
AI is becoming operational before it becomes fully recoverable
Indian organisations are increasingly using AI across their environments, but only 44% of Indian organisations say their cyber response and recovery plans comprehensively account for attack scenarios targeting AI systems and applications, AI workflows or machine learning models.This leaves 56% whose plans do not comprehensively cover these scenarios.
The research also points to gaps in preparedness for AI-related incidents. The majority (53%) of Indian organisations are not well prepared to detect and contain unintended or incorrect actions taken by AI agents, copilots or AI workflows, and recover affected systems or data.
“The research shows that many organisations still view recovery as a technology exercise when it is fundamentally a business imperative,” said Mayank Mishra, Senior Regional Director, Sales, India & SAARC, Cohesity. “True resilience is measured by an organisation’s ability to continue operating, meet customer commitments, and recover quickly during a cyber crisis. AI compounds the challenge by increasing the speed of attacks while adding new systems, data, and workflows. As Indian enterprises accelerate the adoption of AI, that same speed and scale is why AI also has to be part of the answer — strengthening how organisations detect, recover, and restore trust at machine speed.”
About the research
The fifth annual Cohesity Global Cyber Resilience Report was conducted in July 2026 by independent research firm Vanson Bourne on behalf of Cohesity. The study surveyed 3,200 IT and security leaders across Australia, Brazil, France, Germany, India, Japan, Saudi Arabia, Singapore, South Korea, the United Arab Emirates, the United Kingdom, and the United States. For the purposes of the survey, “material cyberattack” was defined as having a measurable financial, reputational, operational and/or customer churn impact on their organisation.
About CohesityCohesity protects, secures, and provides insights into the world’s data. As the leader in AI and data security, Cohesity helps organisations strengthen resilience, accelerate recovery, and reduce IT costs. With Zero Trust security and advanced AI/ML, Cohesity Data Cloud is trusted by customers in more than 140 countries, including two-thirds of the Global 500. Cohesity is also backed by industry leaders such as NVIDIA, Amazon, Google, IBM, Cisco, and HPE.
