Skip to content

Nearly half of organizations fail cyber resilience tests during attacks

Research reveals that nearly half of organizations experience operational shutdowns, data loss, or revenue loss following cyber incidents. AI-enabled attacks and poor coordination across teams are exacerbating the risks, while tabletop exercises and integrated risk management emerge as critical solutions.

Editor, Lazyfounder

Published 6 min read
Nearly half of organizations fail cyber resilience tests during attacks
Image: (Image credit: sarayut Thaneerat/ via Getty Images) via source

Research reveals that nearly half of organizations experience operational shutdowns, data loss, or revenue loss following cyber incidents. AI-enabled attacks and poor coordination across teams are exacerbating the risks, while tabletop exercises and integrated risk management emerge as critical solutions.

30 SEC SUMMARY

  • Nearly half of organizations face operational shutdowns, data loss, or revenue loss after cyber incidents, according to recent findings.
  • 73% of CISOs lack confidence in their ability to manage a major cyber incident effectively.
  • AI-enabled attacks are accelerating, with threat actors targeting multiple businesses simultaneously.
  • Legal and communications teams often slow down decision-making during cyber incidents.
  • Tabletop exercises and integrated risk management are critical for improving cyber resilience.

TABLE OF CONTENTS

  • The state of cyber resilience
  • AI and the evolution of threats
  • Coordination breakdowns during crises
  • Paths to improvement
  • Broader context
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • 47% of CISOs report operational shutdowns as a direct consequence of cyber incidents, while 41% cite data loss and 40% report revenue loss.
  • 73% of CISOs lack confidence in their ability to manage a major cyber incident effectively.
  • AI is enabling threat actors to accelerate attacks, target vulnerabilities faster, and pursue multiple businesses simultaneously.
  • 90% of organizations struggle to coordinate stakeholders during a significant cyber incident, with legal and communications teams often causing delays.
  • Tabletop exercises and integrated risk management are critical for improving cyber resilience and decision-making during crises.

The state of cyber resilience

According to TechRadar, nearly half of organizations fail to prevent operational shutdowns, data loss, or revenue loss following cyber incidents. Specifically, 47% of CISOs report operational shutdowns as a direct consequence, while 41% cite data loss and 40% point to revenue loss. These figures highlight a gap not just in technology but in preparedness and response strategies.

The findings also reveal a broader crisis of confidence: 73% of CISOs say they are not confident in their ability to manage a major cyber incident if it occurred tomorrow. This uncertainty extends to coordination, with 90% of organizations admitting they would struggle to align stakeholders during a significant attack.

AI and the evolution of threats

AI is reshaping the cyber threat landscape, according to the research. Attackers are using AI to accelerate reconnaissance, identify vulnerabilities, and create convincing social-engineering content. Perhaps most concerning, threat actors can now pursue multiple attack paths simultaneously, targeting hundreds of businesses at once. This creates operational chaos and increases the pressure on organizations to pay ransoms or face prolonged disruptions.

The shift toward AI-enabled attacks means that businesses must account for faster, more scalable threats in their cybersecurity strategies. Traditional defenses may no longer be sufficient to counter these automated, parallelized assaults.

Coordination breakdowns during crises

A recurring theme in the research is the breakdown of coordination during cyber incidents. Legal and communications teams, in particular, are cited as sources of delays in decision-making. According to the findings, 75% of organizations report that delays or uncertainty around these teams slow down their response efforts.

The consequences of these delays can be severe. A single breach can disrupt production, transactions, supply chains, and other critical functions within hours, leading to financial and reputational damage. Security leaders warn that blind spots in an organization’s environment—often exacerbated by poor coordination—increase the risk of persistent attacker access and repeat incidents.

The research suggests that organizations fail not because of their security technology but because they lack the speed and alignment needed to lock down critical data and transition to recovery.

Paths to improvement

The research points to several strategies for improving cyber resilience. Tabletop exercises, which simulate cyber incidents, are highlighted as a critical tool for removing friction and enabling faster, risk-based decision-making during real crises.

Another key recommendation is the adoption of a "Minimal Viable Business Objective"—a framework used by mature organizations to guide recovery efforts during a crisis. This approach ensures that businesses focus on maintaining critical functions even under attack.

Beyond these tactics, the findings emphasize that cyber resilience must be treated as a foundational business function. It requires buy-in from all departments and leadership, not just the security team. The most successful organizations, according to the research, are those that continue operating while managing a cyber incident, rather than treating resilience as an afterthought.

Broader context

The challenges highlighted in this research align with broader trends in business continuity and risk management. For example, cost-saving measures like cheaper hosting solutions often introduce hidden risks, such as downtime or security gaps, which can undermine initial savings. Similarly, AI adoption—while transformative—can quickly become a financial and operational liability if not managed carefully, as Uber’s budget overruns reportedly demonstrated.

Privacy and security by design are also emerging as critical principles, particularly for AI hardware. Retrofitting privacy measures after a product launch can lead to trust issues and regulatory complications, much like the coordination gaps seen in cyber incident responses.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

For founders and operators, this research underscores a stark reality: cybersecurity is no longer just an IT issue—it’s a core business challenge. The ability to maintain operations during an attack, not just recover afterward, is what separates resilient organizations from those that suffer lasting damage.

The data reveals a troubling disconnect between technology investments and operational preparedness. Even with advanced security tools, organizations falter when coordination breaks down, particularly between security teams and other departments like legal and communications. This highlights the need for cross-functional alignment, not just technical defenses.

AI’s role in accelerating attacks adds another layer of urgency. Founders must recognize that attackers are leveraging the same tools businesses use to innovate—scaling threats faster than ever. For startups, this means cybersecurity can’t be an afterthought; it must be baked into product development, crisis planning, and even board-level discussions.

Ultimately, the findings suggest a shift in mindset: cyber resilience isn’t about avoiding attacks altogether but ensuring the business can function despite them. For resource-constrained teams, this might mean prioritizing tabletop exercises, defining minimal viable business objectives, and stress-testing decision-making processes before a crisis hits.

Key takeaways

  • Cyber resilience is now defined by an organization’s ability to operate during an attack, not just recover from one.
  • Nearly half of organizations experience operational shutdowns, data loss, or revenue loss following cyber incidents.
  • 73% of CISOs lack confidence in their ability to manage a major cyber incident, highlighting a gap in preparedness.
  • AI is being weaponized by attackers to accelerate reconnaissance, exploit vulnerabilities, and target multiple businesses at once.
  • Legal and communications teams often delay critical decisions during cyber incidents, underscoring the need for cross-functional coordination.
  • Tabletop exercises and integrated risk management are proven methods to improve cyber preparedness and response times.

FAQ

What is cyber resilience?

Cyber resilience refers to an organization’s ability to continue operating and delivering critical functions during and after a cyberattack. It goes beyond traditional cybersecurity, which focuses on prevention, by emphasizing preparedness, response, and recovery.

Why do organizations struggle with coordination during cyber incidents?

Cyber incidents often involve multiple stakeholders, including security teams, legal advisors, communications staff, and executive leadership. Each group may have different priorities, leading to delays in decision-making. Poor alignment and lack of pre-defined roles can exacerbate these challenges.

How can tabletop exercises improve cyber resilience?

Tabletop exercises simulate cyber incidents in a controlled environment, allowing teams to practice their response strategies. These exercises help identify gaps in coordination, clarify roles, and reduce friction during real crises, leading to faster and more effective decision-making.

What role does AI play in cyberattacks?

AI is being used by threat actors to accelerate attacks. It enables faster reconnaissance, identification of vulnerabilities, and creation of convincing social-engineering content. AI also allows attackers to pursue multiple targets simultaneously, increasing the scale and speed of threats.

What is a 'Minimal Viable Business Objective'?

A 'Minimal Viable Business Objective' is a framework used by organizations to define the most critical functions that must continue during a crisis, such as a cyberattack. It guides recovery efforts by ensuring that limited resources are focused on maintaining these essential operations.

Related on Lazyfounder

Sources

  1. TechRadar · 2026-10-02
    Cyberattacks are the ultimate business continuity tests that nearly half of organizations fail

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us