
A cyberattack used to end with an IT cleanup bill and a quiet all-clear. Cohesity, a data security and backup-and-recovery vendor, argues that era is over. Its new Risk-Ready or Risk-Exposed cyber resilience study is based on 3,200 IT and security leaders surveyed by Vanson Bourne in September 2025. The cybersecurity bill now lands on the forecast: 70% of public companies adjusted earnings or financial guidance after a material cyberattack, and 68% saw it move their stock price.
- The damage is not only a public-company story: 73% of privately held firms pulled budget out of innovation and growth to pay for recovery, a cost no disclosure ever shows.
- 92% of organizations that took a material hit reported legal, regulatory or compliance consequences, from fines to lawsuits.
- 81% of IT and security leaders say generative AI is outrunning their ability to manage its risk, while only 47% are fully confident in their own resilience.
76% Took a Material Hit, and It Reached the Forecast
The executives Cohesity surveyed have stopped calling cyberattacks an IT problem and started calling them something that moves earnings guidance. Across the 3,200 organizations in the study, expanded in the 2026 Global Cyber Resilience Report, 76% had absorbed at least one material cyberattack. Cohesity defines that as an incident with measurable financial, reputational, operational or customer-churn impact, so this is three in four businesses taking a hit large enough to surface in a quarterly review.
Among public companies, the fallout rarely stays internal. 70% adjusted earnings or financial guidance after an attack, and 68% watched their stock price react. “Cyber resilience is no longer just a technology issue. It’s a business and financial imperative,” Cohesity CEO and president Sanjay Poonen said in the research release. The line explains why this data now turns up in board decks, not only on SOC dashboards.
Why Private Firms Pay the Quietest Price
Most coverage of a breach fixates on the visible damage, the guidance cut and the stock dip that public companies have to announce. The more consequential finding sits one layer down. 73% of private firms redirected money away from innovation and growth to fund recovery, a decision that never reaches a press release or an SEC filing and quietly grows into lost ground against better-funded rivals. Cohesity buries the number that matters most: the untracked cost to private firms.
A separate Cohesity survey of 100 UK chief executives, which we covered when it landed, put the CEO-estimated revenue hit at roughly 15% of annual revenue. Most of those executives also doubt their cyber insurance would cover the full cost. The direction is consistent across both datasets and with the wider body of data breach cost research. Prevention is not holding, 76% still took a material hit, and the money moves to whoever has to clean up afterward. The 92% of firms facing legal, regulatory or compliance consequences drive the point home, because a single incident now spawns a pile of breach reporting obligations that outlast the technical recovery.
Turning Cyber Resilience Into a Budget Line
The sequence matters: put a number on the exposure first, then fund the capability that limits it, then make the financing and accountability match the risk. Each step follows from a finding in the study, and you can measure your own cyber resilience against the same yardstick.
Model the business impact in dollars before an incident – Cohesity found the revenue and guidance damage is already quantifiable. Translate a material cyberattack into a forecast hit your board can see, the same 15% order UK chief executives already cite.
Fund tested, immutable recovery as capital expenditure – With 76% of organizations already hit and 73% raiding growth budgets after the fact, provable recovery is what denies attackers the upper hand. A backup an intruder can still reach is not a safety net; immutability is what turns a recovery plan into recovery capacity when the attacker is already inside.
Reprice cyber insurance against real recovery cost – If your executives already doubt the policy covers full recovery, treat that gap as budget you must self-fund. Then press underwriters on what immutable, tested backups would change about your premium.
Do that, and the finance chief who once adjusted guidance in the dark instead walks into the next board meeting with the cyber resilience number already modeled and the recovery already funded.
Join our LinkedIn group Information Security Community!










