Cyber resilience research · 900+ security leaders

Data Trust &
Resilience Report 2026

We surveyed 900+ security leaders. 90% are confident they can recover inside their recovery time objectives. Only 28% of ransomware-affected organizations fully recovered their data. Here’s what closes that gap.

are confident they can recover within their recovery time objectives (RTOs).

90%

say their RTOs are fully aligned with business continuity goals, leaving a gap between confidence and readiness.

69%

Key takeaways

The four things every leader should know about data trust and resilience

  • 01

    Data recovery

    90% of security leaders are confident they can recover within their RTOs, but only 28% of ransomware-affected organizations fully recovered their data.

  • 02

    AI adoption

    AI adoption is outrunning risk visibility: 43% say adoption outpaces their ability to secure data and models, and 42% lack full visibility into the AI tools in use.

  • 03

    Best practices

    Four practices consistently correlate with stronger recovery: expand ownership beyond security, operationalize AI governance, communicate risk frequently, and track the right KPI.

  • 04

    Investment

    Investment shows up in outcomes: organizations that grew cybersecurity budgets fully recovered data more than twice as often (40% vs 16%), and fewer of them paid a ransom (33% vs 52%).

What does real cyber resilience require?

Confidence in recovery isn’t the same as proven recovery capability

Organizations with stronger recovery outcomes share four defining capabilities.

— Data Trust & Resilience Report 2026, Veeam

Why is recovery confidence misleading?

Confidence is common,
but validated recovery capability is not

Recovery reality after a ransomware attack:

  • 56%Attackers encrypted or exfiltrated data
  • 44%Recovered less than 75% of data
  • 28%Fully recovered all affected data

Only 28% of ransomware-affected organizations fully recovered their data.

Partial recovery
Full recovery

That leaves more than 7 in 10 facing data loss, downtime, or business disruption.

What happens when an incident hits?

When incidents occur, the downstream impact is significant

42%0%

Customer or constituent service disruption

41%0%

Financial loss or revenue impact

38%0%

Extended downtime of critical systems

Why is AI outpacing risk visibility?

Adoption is running ahead of the controls meant to govern it

Adoption is outracing security

AI is moving from experimentation to everyday execution, embedded in core processes. The controls around it aren’t keeping pace.

43%

say AI tool adoption is outpacing their ability to secure data and models.

Teams can’t see the tools

AI introduces new data paths across users, apps, APIs, and third-party services, amplifying data sprawl and unclear ownership.

42%

have limited visibility into all the AI tools or models used across the organization.

Policies haven’t caught up

Governance often trails adoption. When nobody turns policy into enforceable controls, oversight fragments.

40%

say they haven’t updated security policies to include AI-specific risks, such as the use of generative AI.

Shadow AI slips through

Even with policies in place, unsanctioned tools expand the data you have to secure, govern, and recover.

25%

say shadow IT and unauthorized AI tool usage are a primary concern related to employee AI tool use and data security.

Does policy alone reduce risk?

Policy alone doesn’t reduce risk, enforceable controls do

48% of organizations have data loss prevention (DLP) controls in place.

The kind of enforcement that turns governance into daily execution.

Governance only works when controls and validation back the policy. Intent and guidance don’t reduce risky data movement.

Enforceable controls do, and that matters more as AI usage expands.

Do enforceable controls change the picture?

Organizations with DLP report stronger visibility and control

Lower is better — fewer organizations report these gaps when DLP is in place.

  • Limited visibility into AI tools and models

    39%

    With DLP

    45%

    Without DLP

  • AI adoption outpacing security controls

    38%

    With DLP

    48%

    Without DLP

What practices strengthen recovery?

Four practices consistently correlate with stronger recovery outcomes

  • Expand ownership
    beyond security

    Extend cyber resilience ownership into IT, data, and business leadership. Incident-free organizations use cross-functional policy committees more often (37% vs 31%).

  • Operationalize AI
    governance

    Back policy with controls: model validation, testing, and drift monitoring. Budget-growth organizations are much more likely to run model validation and testing (43% vs 26%).

  • Report cyber
    risk frequently

    Communicate cyber risk to the board monthly or more, using more frequent or advanced reporting such as risk quantification (56% vs 50% cadence; 40% vs 35% advanced reporting).

  • Track the KPIs
    that matter

    Measure what insurers and leaders ask for: restore and recovery testing (57%), mean time to recover (56%), time to isolate and contain (42%), automated recovery (23%).

How does investment change recovery?

Budget growth tracks with stronger ransomware recovery

Organizations that increased cybersecurity budgets recovered more of their data, and paid ransoms less often. Investment in disaster recovery and validated recovery time objectives shows up in the outcomes. Correlation, not causation, but the pattern is consistent.

Ransomware response and recovery, by budget status:

33%0%

paid a ransom with budget growth, 52% without increases.

40%0%

fully recovered affected data, versus 16% among organizations without budget growth.

Compliance is becoming a resilience driver

name cyberattacks the emerging risk most likely to impact data resilience in the next 12 months.

36%

cite regulatory and compliance mandates close behind, as obligations expand.

33%

cite data residency and sovereignty as the most important factor in data placement.

58%

Measured resilience, trusted data

Real resilience means disaster recovery you’ve validated against your recovery time objectives, backed by strong governance, clear ownership, and disciplined execution. As AI speeds up how data moves, recoverable data is what keeps the business steady. Veeam helps you protect, contain, and recover.

About the survey

The findings come from a global survey of 906 IT, security, and risk leaders, fielded in December 2025. Every respondent was director level or above at an organization with 1,000 or more employees, and each one owns some piece of cyber risk day to day, from CISOs and CIOs to the risk, governance, and data leaders who sit alongside them. They span the United States, Canada, the United Kingdom, France, Germany, Brazil, Mexico, Argentina, Australia, and New Zealand, with U.S. federal agencies represented in depth alongside commercial organizations. The survey ran in five languages across four regions.

900+

security leaders

90% confident on RTOs, but only

28%

fully recovered their data.

Frequently asked questions

The data trust and resilience gap, answered