Absolute Security has published comprehensive research looking at the state of enterprise cyber resilience. Among the top findings was that, when hit with cyber incidents and attacks, no surveyed organizations could recover business operations within a day.
The global study of 750 CISOs in the US and UK reveals that, during the past 12 months, 55% of CISOs stated that their organization had experienced a cyberattack, ransomware infection, compromise, or data breach that rendered mobile, remote, or hybrid endpoint devices inoperable. When asked about recovery time, a majority (57%) reported their organizations took more than 4.5 days (on average) for full remediation and recovery, with 19% revealing recovery efforts stretched as long as two weeks.
The survey further revealed that 98% of organizations are spending between $1 and $5 million to recover from cyber incidents, with the average cost to recover per incident now $2.5 million. Losses are likely understated, says the report, as this cost does not include overall losses attributed to total business downtime that attacks and incidents cause.
CISOs in the firing line
CISOs are increasingly held responsible when it comes to dealing with the downtime caused by cyberattacks and security software incidents.
72% agree that their role has evolved from being responsible for security and risk only, to now leading their organization’s business continuity following a cyberattack, ransomware infection, security incident, or software failure that stops operations.
Adding to the pressures of the role, 61% agreed their organization’s board and C-suite expect the cybersecurity group to guarantee zero breaches and ransomware incidents. A full 59% agreed they are concerned that a security or IT incident causing significant downtime could lead to job loss, personal liability, and legal penalties.
67% of CISOs stated they are the primary executive responsible for ensuring cyber resilience, with 68% agreeing that their organization currently has a cyber resilience strategy in place.
As threats and vulnerabilities continue to proliferate and the risk of extended downtime grows, 65% of CISOs agree their organization prioritises cyber resilience over traditional prevention, detection, and response.






