For many years, the cyber security industry has treated detection speed as the headline measure of how well prepared an organization is. If an organization can identify an attacker quickly, it is considered to be performing well. However, new research suggests that this assumption should be reconsidered.
ManageEngine’s Owning Operational Resilience in 2026 study surveyed over 1,500 IT and business decision-makers across the UK, Spain, Germany, Italy, and the Netherlands. The results revealed an uncomfortable finding: UK organizations surveyed reported the highest cyber incident rate of the five European countries. On the positive side, 94% of UK organizations reported detecting cyber incidents within 24 hours, among the fastest detection rates in Europe. However, 49% reported recovery within ten days, while 26% said recovery could take more than ten days, including 6% that reported recovery taking more than 20 days.
Detection and recovery are distinct capabilities; and we’ve spent years optimising for the wrong one. Detecting an attack quickly does not, by itself, determine how long recovery will take. Resilience isn’t the moment you notice something is wrong. It’s everything that happens next.
The gap isn’t technology, it’s people
If detection has genuinely improved, the obvious question is then why hasn’t recovery kept up? The answer, according to the survey data, has less to do with technology and more to do with the people running it.
A skills gap driven by rapidly evolving threats was cited by 46% of UK respondents as a top operational challenge. This was the highest figure for any country surveyed and nine percentage points above the European average. Team fatigue and burnout were cited by 29% of UK respondents, as was insufficient management support. Both were the highest rates in Europe.
This matters because recovery is a sustained, hands-on effort. It’s not a single alert being triaged – it’s days or weeks of coordinated work across IT, security, and often the wider business. When 60% of UK respondents say that operational pressure on their teams has increased over the past year and a quarter say that pressure has critically limited their ability to respond to incidents at all, it adds up. You can have the best detection stack in Europe and still stall at the recovery stage if the people behind it are stretched too thin to execute.
AI isn’t just adding volume, it’s compressing time
AI is another pressure reshaping this picture: 43% of UK organizations named AI-powered attacks as their single biggest risk over the next 12 months. This was ahead of ransomware, phishing, and data breaches, with 41% citing AI and advanced-threat preparedness as a top spending priority.
What’s easy to miss is that AI’s real impact isn’t simply more attacks – it’s speed. AI-assisted attackers can probe, adapt, and pivot within an environment far faster than a human-led one, which shortens the window of opportunity in which an overstretched, fatigued team has to respond before disruption. A skills gap that was manageable against yesterday’s threats becomes a much bigger liability against attacks that move at lightning speed.
What separates fast recovery from weeks of disruption
UK organizations are taking action: 67% have implemented a formal resilience methodology, 96% conduct a formal review after every incident, and executive engagement in cyber security is comparatively strong. But strong governance on paper doesn’t always translate into strong recovery in practice. 13% of organizations that reviewed an incident made no strategic changes at all and only 37% went beyond tactical fixes to make broader, long-term improvements.
The organizations that recover in days, not weeks, are the ones that treat every incident review as a mandate for structural change. That’s the real dividing line that we’re seeing; and organizations that are closing skills gaps, supporting their teams, and building recovery playbooks that assume AI-speed threats will be the winners.
Detection will keep getting faster – this was never in doubt. The organizations that will set themselves apart will be the ones that stop measuring resilience by how quickly they spot a problem and start measuring it by how quickly their people, not just their tools, can bring the business back to business as usual.
The author
VimalRaj Sampathkumar is UK Technical Head, ManageEngine






