Cyberattacks as Business Continuity Tests: 47% of Organizations Report Shutdowns
A TechRadar report says 47% of CISOs who experienced a cyber incident reported operational shutdowns, more than data loss or revenue loss. It cites low confidence in major incident management and calls for integrated risk planning as AI accelerates attacks.
The report says a single breach can ripple through an organization within hours, disrupting production, transactions and supply chains, and causing financial loss and reputational damage. For CISOs, the hardest task is no longer only retrieving stolen data or absorbing lost income; it is keeping the lights on for the business functions that matter most, which can limit damage to the company and its supply chain.
That task is complicated by a preparedness gap. TechRadar reports that 73% of CISOs are not confident they could effectively manage a major cyber incident if it happened tomorrow. The gap appears in a lack of resources and visibility and in disconnects between teams. Sygnia's global director of executive and board cyber services describes an exercise with a large international bank in which the security operations team rated an IP address as a 2 out of 5 risk, while business owners rated it 5 out of 5 because the address was the bank's data lake, containing critical data.
The report argues that integrated risk management spans cyber, IT, legal, communications and other functions and cannot happen in silos. Business context is central: understanding what is at risk and having a plan to keep the business running. Cybersecurity is described as being about risk, with cyber incidents requiring stakeholders to come together, understand risk from their perspectives and work collectively to reduce it on a continuous basis.
The threat landscape is changing with AI and frontier AI, which reduce the need for threat actors to be highly sophisticated or hire extensive resources to carry out large-scale attacks at speed and cause operational chaos. Modern ransomware campaigns involving deepfake impersonations and AI-enabled malware continue to make headlines, but the report points to AI's use in accelerating reconnaissance, identifying vulnerabilities, creating convincing social-engineering content and pursuing multiple attack paths in parallel. Threat actors can do more with less, grinding not one business but hundreds to a halt, which creates urgency for businesses to pay ransoms rather than only having information stolen.
As a result, the report says, organizations are realizing that once solid business continuity plans will break down when needed most, not because of the security technology stack but because they are not coordinated and quick enough to lock down their most valuable data and move to recovery. The most mature customers have recovery point objectives, recovery time objectives and business impact analysis on their crown jewels, and they have created a vision of a Minimal Viable Business Objective. The bank in the example called it MVB, or minimal viable bank. During a crisis, communicating quickly what it takes to get the business back up and running is fundamental to removing risk and lowering the impact of the attack.
Legal and communication teams and executive leadership continue to be hurdles with different priorities that can lead to delays in responding to an attack, according to the research. It found that 90% of organizations would struggle to coordinate stakeholders during a significant incident, and 75% say delays or uncertainty around legal and communications involvement slow down decision-making when an incident happens, ultimately slowing recovery. The report says tabletop exercises allow major debates about priorities and role responsibilities so that, in a real crisis, risk-based decision-making is faster and removes friction so the company can respond as an integrated, full business response. Cyber resilience must be seen as foundational.