Cohesity report finds 2% of Australian organisations prepared for frontier AI cyberattacks

0

Only 2% of Australian organisations believe their current cyber recovery plans are equipped to withstand threats posed by “frontier AI” technologies, according to Cohesity’s 2026 Global Cyber Resilience Report.

The report, based on a survey of IT and security leaders conducted by research firm Vanson Bourne in July 2026, suggests a widening gap between AI adoption and organisations’ ability to recover from cyber incidents that affect AI systems, data, or workflows.

Among the Australian findings, 80% of organisations reported suffering a “material” cyberattack in the past 12 months, compared with 73% globally. Cohesity said 99% of Australian respondents reported having a cyber resilience strategy, but 53% said it still required improvement, including 9% who said the improvement needed was significant.

The report also indicates many organisations are relying on recovery plans that may not reflect real-world conditions. Among respondents that experienced an attack, 93% reported recovery plans based on “unproven assumptions”, while 92% said their current recovery plan would likely require workarounds or improvisation during an incident (compared with 88% globally). Cohesity said 87% took longer to recover by about five hours on average (compared with 76% globally), and 74% saw more systems affected than initially assessed (compared with 70% globally).

In the report, Cohesity points to gaps that respondents said emerged during cyber incidents, including skills and knowledge (70%), managing identity and access with tools like Okta (67%), and AI models, pipelines and workflow tools (65%). The report also found that 47% of Australian organisations lack a centralised inventory or clear understanding of the AI agents, copilots and workflows operating across their businesses.

Cohesity’s report also highlights what it calls Minimum Viable Company (MVC) planning, described as identifying the minimum people, processes and technology required to keep essential business functions operating during a disruption. While 74% of Australian organisations said they have identified critical functions needed to operate during a disruption, only 20% said they have formally documented and tested an MVC plan (22% globally).

“The challenge for leaders is no longer simply preventing an attack. It is ensuring the business can continue to operate and recover with confidence when an attack breaches the defences,” said James Eagleton, managing director ANZ at Cohesity, in the release.

Greg Statton, Cohesity’s VP and CTO for APJ, said: “If a business cannot identify the AI systems and workflows it relies on or verify the integrity of the data and models behind them, it’s difficult to trust that the data after an incident is actually safe and clean – and ultimately, trusted AI depends on trusted data.”

For the purposes of the survey, a material cyberattack was defined as an attack having a measurable financial, reputational, operational and/or customer churn impact on an organisation. The study surveyed 3,200 IT and security leaders across Australia, Brazil, France, Germany, India, Japan, Singapore, South Korea, the United Arab Emirates, Saudi Arabia, the United Kingdom, and the United States.

You can read the full report here.

Share.