When a cyberattack hits an Australian business, the recovery plan usually does not hold.
New research from data management firm Cohesity, published in September 2026, found that among Australian organisations that experienced a material cyberattack in the past year – 80% of those surveyed, compared with 73% globally – 92% said recovery required workarounds or improvisation. A further 87% took longer to recover than expected.
Most of those organisations had a plan. Ninety-nine percent reported having a cyber resilience strategy. The research suggests having one and being able to execute it are two different things.
Business interruption coverage is built around projected recovery timelines. When actual recovery consistently runs longer, those projections carry risk for both the insured and the insurer.
The Cohesity research also identified weaknesses in Minimum Viable Company (MVC) planning – the process of mapping the people, systems, and processes needed to keep critical functions running during a disruption. While 74% of Australian organisations have identified their critical functions, only 20% have formally documented and tested a plan. The global figure is 22%.
Overall, just 2% of Australian organisations believe their current cyber recovery plans can withstand threats from frontier AI technologies. Of the remaining 98%, 37% say significant changes are required.
“The challenge for leaders is no longer simply preventing an attack. It is ensuring the business can continue to operate and recover with confidence when an attack breaches the defences,” said James Eagleton, managing director, ANZ, at Cohesity.
He added: “Organisations must formally document and regularly test whether these plans can support the business under real-world attack conditions. That requires realistic resilience strategies, as recovery is rarely straightforward – more systems may be affected than initially expected, and leaders often need to make critical decisions with incomplete information.”
Read next: Biological weapons researchers were using AI. Insurers should know
The Cohesity research points to a specific and growing blind spot: AI systems. Nearly half of respondents – 47% – reported having no centralised inventory or clear understanding of the AI agents, copilots, and automated workflows inside their organisations. Only 40% have recovery plans that account for attacks targeting AI systems. Just 38% were confident they could verify a model’s integrity after an incident.
Without visibility of what AI tools are in operation, organisations cannot demonstrate those systems are secured, governed, or recoverable.
This has become a regulatory issue. In April 2026, the Australian Prudential Regulation Authority (APRA) wrote to all regulated entities – including banks, insurers, and superannuation trustees – warning that governance and operational resilience practices were not keeping pace with AI adoption. APRA noted that many boards lacked the technical literacy required to provide effective oversight of AI-related risks and called for a step-change in how the sector manages them.
The backdrop to these recovery failures is a worsening threat picture. The Office of the Australian Information Commissioner (OAIC) recorded 1,205 data breach notifications in calendar year 2025 – the highest total since mandatory reporting began in 2018, and an 8% rise on the prior year. Of those, 716 were attributed to malicious or criminal activity.
The Australian Signals Directorate’s (ASD) Annual Cyber Threat Report 2024-25 found the Australian Cyber Security Centre (ACSC) responded to more than 1,200 cyber security incidents during the financial year – an 11% increase – while self-reported costs for medium-sized businesses rose 55% year on year to an average of $97,200 per incident.
Separate research from Netskope Threat Labs adds an AI-specific dimension. Its Australia and New Zealand report found prompt injection and jailbreaking attacks – designed to manipulate AI systems into unauthorised behaviour – occurring at twice the global rate locally: 254 alerts per 10,000 organisations, against 129 globally.
The same report tracked an 89% rise over two months in connections to remote Model Context Protocol (MCP) servers – an open standard linking AI models to external data sources – alongside a 69% increase in MCP-related security events. Many existing security tools were not built to monitor this type of traffic.
“Our research outlines the increasing complexity of AI risks ANZ organisations are facing, and new threats are going to keep emerging as enterprise AI use increases and evolves. This is a whole new landscape that requires a new response; redesigning security architectures for the AI era, re-scoping the baseline for data security practices to include monitoring and securing bi-directional AI traffic, AI agents, model behaviours, and new machine-to-machine communications protocols such as the MCP, as well as more broadly preserving the integrity of the AI supply chain,” said Ray Canzanese, director of Netskope Threat Labs.
Read next: CFC folds cyber, AI wording into financial institutions suite
Cyber insurance uptake in Australia rose 50% in 2025, according to EBM Insurance & Risk, as organisations sought cover against ransomware, phishing, and AI-driven attacks.
That growth is occurring against a backdrop of rising loss costs. The ASD’s 2024-25 data shows self-reported cybercrime costs for medium-sized businesses rose 55% year on year to an average of $97,200 per incident – a figure that sits alongside broadly competitive insurance market conditions, creating a gap between pricing and actual exposure trends.
The Cohesity research was conducted in July 2026 by Vanson Bourne, drawing on responses from 3,200 IT and security decision makers across 12 countries, including Australia.