Cyber resilience research · 900+ security leaders
Data Trust &
Resilience Report 2026
We surveyed 900+ security leaders. 90% are confident they can recover inside their recovery time objectives. Only 28% of ransomware-affected organizations fully recovered their data. Here’s what closes that gap.
are confident they can recover within their recovery time objectives (RTOs).
say their RTOs are fully aligned with business continuity goals, leaving a gap between confidence and readiness.
Key takeaways
The four things every leader should know about data trust and resilience
-
01
Data recovery
90% of security leaders are confident they can recover within their RTOs, but only 28% of ransomware-affected organizations fully recovered their data.
-
02
AI adoption
AI adoption is outrunning risk visibility: 43% say adoption outpaces their ability to secure data and models, and 42% lack full visibility into the AI tools in use.
-
03
Best practices
Four practices consistently correlate with stronger recovery: expand ownership beyond security, operationalize AI governance, communicate risk frequently, and track the right KPI.
-
04
Investment
Investment shows up in outcomes: organizations that grew cybersecurity budgets fully recovered data more than twice as often (40% vs 16%), and fewer of them paid a ransom (33% vs 52%).
What does real cyber resilience require?
Confidence in recovery isn’t the same as proven recovery capability
Organizations with stronger recovery outcomes share four defining capabilities.
— Data Trust & Resilience Report 2026, Veeam
Clear visibility
Where data lives, how it flows, and where AI risk sits across the enterprise, so nothing critical stays hidden.
Why is recovery confidence misleading?
Confidence is common,
but validated recovery capability is not
Only 28% of ransomware-affected organizations fully recovered their data.
That leaves more than 7 in 10 facing data loss, downtime, or business disruption.
What happens when an incident hits?
When incidents occur, the downstream impact is significant
42%0%
Customer or constituent service disruption
41%0%
Financial loss or revenue impact
38%0%
Extended downtime of critical systems
Why is AI outpacing risk visibility?
Adoption is running ahead of the controls meant to govern it
Adoption is outracing security
AI is moving from experimentation to everyday execution, embedded in core processes. The controls around it aren’t keeping pace.
say AI tool adoption is outpacing their ability to secure data and models.
Teams can’t see the tools
AI introduces new data paths across users, apps, APIs, and third-party services, amplifying data sprawl and unclear ownership.
have limited visibility into all the AI tools or models used across the organization.
Policies haven’t caught up
Governance often trails adoption. When nobody turns policy into enforceable controls, oversight fragments.
say they haven’t updated security policies to include AI-specific risks, such as the use of generative AI.
Shadow AI slips through
Even with policies in place, unsanctioned tools expand the data you have to secure, govern, and recover.
say shadow IT and unauthorized AI tool usage are a primary concern related to employee AI tool use and data security.
Does policy alone reduce risk?
Policy alone doesn’t reduce risk, enforceable controls do
48% of organizations have data loss prevention (DLP) controls in place.
The kind of enforcement that turns governance into daily execution.
Governance only works when controls and validation back the policy. Intent and guidance don’t reduce risky data movement.
Enforceable controls do, and that matters more as AI usage expands.
Do enforceable controls change the picture?
Organizations with DLP report stronger visibility and control
Lower is better — fewer organizations report these gaps when DLP is in place.
-
Limited visibility into AI tools and models
39%
With DLP
45%
Without DLP
-
AI adoption outpacing security controls
38%
With DLP
48%
Without DLP
What practices strengthen recovery?
Four practices consistently correlate with stronger recovery outcomes
-
Expand ownership
beyond securityExtend cyber resilience ownership into IT, data, and business leadership. Incident-free organizations use cross-functional policy committees more often (37% vs 31%).
-
Operationalize AI
governanceBack policy with controls: model validation, testing, and drift monitoring. Budget-growth organizations are much more likely to run model validation and testing (43% vs 26%).
-
Report cyber
risk frequentlyCommunicate cyber risk to the board monthly or more, using more frequent or advanced reporting such as risk quantification (56% vs 50% cadence; 40% vs 35% advanced reporting).
-
Track the KPIs
that matterMeasure what insurers and leaders ask for: restore and recovery testing (57%), mean time to recover (56%), time to isolate and contain (42%), automated recovery (23%).
How ready are organizations, really?
Bigger budgets show up in two places: metrics and capabilities
49% of organizations increased cybersecurity budgets year over year. Those that did are much more likely to track the metrics and build the capabilities that make recovery real. Open each to see the gap.
What sets rising-budget organizations apart
Budgets are rising
49% increased cybersecurity budgets year over year, while 51% stayed flat or decreased.
Reporting drives budgets
Budget growth is much more common where teams report cyber risk to the board monthly (62% vs 47%).
Metrics make gaps visible
Rising-budget teams track RTOs more closely (78% vs 56%), turning confidence into something they can validate.
Recovery time objectives (RTOs)
78% of budget-growth organizations track recovery time objectives, versus 56% without. An RTO turns recovery into a deadline you either meet or miss.
How does investment change recovery?
Budget growth tracks with stronger ransomware recovery
Organizations that increased cybersecurity budgets recovered more of their data, and paid ransoms less often. Investment in disaster recovery and validated recovery time objectives shows up in the outcomes. Correlation, not causation, but the pattern is consistent.
Ransomware response and recovery, by budget status:
33%0%
paid a ransom with budget growth, 52% without increases.
40%0%
fully recovered affected data, versus 16% among organizations without budget growth.
Compliance is becoming a resilience driver
name cyberattacks the emerging risk most likely to impact data resilience in the next 12 months.
cite regulatory and compliance mandates close behind, as obligations expand.
cite data residency and sovereignty as the most important factor in data placement.
Measured resilience, trusted data
Real resilience means disaster recovery you’ve validated against your recovery time objectives, backed by strong governance, clear ownership, and disciplined execution. As AI speeds up how data moves, recoverable data is what keeps the business steady. Veeam helps you protect, contain, and recover.
About the survey
The findings come from a global survey of 906 IT, security, and risk leaders, fielded in December 2025. Every respondent was director level or above at an organization with 1,000 or more employees, and each one owns some piece of cyber risk day to day, from CISOs and CIOs to the risk, governance, and data leaders who sit alongside them. They span the United States, Canada, the United Kingdom, France, Germany, Brazil, Mexico, Argentina, Australia, and New Zealand, with U.S. federal agencies represented in depth alongside commercial organizations. The survey ran in five languages across four regions.
900+
security leaders
90% confident on RTOs, but only
28%
fully recovered their data.
Frequently asked questions
The data trust and resilience gap, answered
The data resilience gap is the distance between how prepared organizations feel and how well their disaster recovery actually performs. 90% of security leaders are confident they can recover within their recovery time objectives (RTOs), yet only 28% of ransomware-affected organizations fully recovered their data.
Organizations with stronger recovery outcomes share four capabilities: clear visibility into where data and AI risk live, enforceable security controls, disaster recovery you’ve tested against your recovery time objectives, and executive alignment with shared ownership of risk.
Confidence is easy to have and hard to prove. While 90% are confident in meeting their RTOs, 44% of ransomware-affected organizations recovered less than 75% of their data and only 28% fully recovered, with downstream impact including service disruption (42%), financial loss (41%), and extended downtime (38%).
AI adoption is outpacing the ability to secure and govern the data behind it. 43% say adoption outpaces their security controls, 42% have limited visibility into AI tools and models, 40% haven’t updated security policies for AI-specific risks, and 25% cite shadow IT and unauthorized AI tool usage as a primary concern.
Not on its own. Policy alone doesn’t reduce risk. Enforceable controls do. 48% of organizations have data loss prevention (DLP) in place, and those organizations report stronger visibility and fewer control gaps than those relying on policy or guidance alone.
Governance usually rests with a single executive: the CISO (38%) or CIO (27%), and only 17% use a cross-functional committee. Because AI risk spans security, IT, data, compliance, and business operations, cross-functional oversight consistently proves more effective than single-owner models.
Budget growth tracks with stronger ransomware recovery. Organizations that increased cybersecurity budgets fully recovered their data more than twice as often (40% vs 16%), paid ransoms less (33% vs 52%), and track recovery time objectives more closely (78% vs 56%), turning investment into validated recovery capability.