Why Australian businesses are still underestimating the time it takes to recover from a cyberattack
Mon, 21st Sep 2026 (Today)
MARTIN CREIGHAN
Vice President, Asia Pacific
Commvault
Australian organisations have invested heavily in strengthening their cyber defences. Yet many boards continue to overlook one critical question: how long would it actually take to recover if those defences failed?
New findings from Commvault's State of Data Resilience ANZ 2026 report reveal a persistent gap between business expectations and operational reality. While executives increasingly expect their organisations to return to operation within just a few days after a cyber incident, the reality is that recovery often takes weeks.
For Australian organisations navigating an increasingly complex threat landscape, that disconnect is no longer just an IT issue. It is becoming a governance, compliance and business resilience challenge.
The recovery gap is widening
Cybersecurity conversations have traditionally focused on preventing attacks. However, for many organisations, the more important question is 'what happens after a breach occurs'.
The research found that ransomware attacks, cloud outages, supply chain incidents and operational disruptions are now considered an inevitability rather than a possibility. It isn't a matter of 'If we suffer an incident' it is now a matter of 'when'.
As a result, resilience is no longer measured by whether an organisation experiences an incident. It is measured by how quickly it can restore the services that matter most.
The challenge is that business expectations often outpace operational reality.
Boards understandably expect critical systems to return quickly following an incident. Customers, regulators and investors increasingly expect the same. Yet today's technology environments are significantly more complex than they were only a few years ago. Organisations operate across multiple cloud platforms, SaaS applications, on premises infrastructure, data lakes, AI workloads and an expanding number of machine identities.
According to the report, data estates across Australia grew by 30 percent over the past year alone. At the same time, multi-cloud environments now represent the dominant infrastructure model for many organisations.
Each layer of complexity adds new dependencies that must be restored, validated and secured before normal operations can resume.
The result is that recovery remains far more difficult than many business leaders realise.
Regulators are increasingly focused on resilience
This challenge arrives as Australian regulators shift their focus from prevention towards resilience.
The introduction of APRA's CPS 230 Operational Risk Management standard represents a significant milestone in that transition. The regulation requires entities to identify critical business services, establish tolerance levels for disruption and demonstrate their ability to continue operating during severe incidents.
Importantly, CPS 230 is not simply concerned with whether controls exist. It also focuses on whether organisations can continue delivering critical services when those controls fail.
Similarly, CPS 234 requires organisations to maintain robust information security capabilities and protect critical information assets against evolving threats.
Together, these regulations reflect a broader recognition that disruptions will occur and that resilience must be actively demonstrated rather than assumed. Furthermore, they place more onus on individuals within the organisation as well, rather than just the company as a whole.
For boards and executive teams, the implication is clear; recovery capability is no longer just an IT responsibility. It is an organisational imperative.
Defining what matters most
One of the most revealing findings from the research concerns the concept of the Minimum Viable Company (MVC).
The MVC approach focuses on identifying the minimum set of people, processes, applications and data required to maintain essential operations during a crisis. Rather than attempting to recover everything at once, organisations should prioritise what matters most.
The report found that 63 percent of organisations have defined a minimum viable business capability. However, only 42 percent have actually mapped out the technology capabilities required to support it.
That gap may help explain why recovery expectations and recovery outcomes remain so far apart.
Business leaders may know which functions are critical, but unless technology teams have identified the infrastructure, applications, identity systems and data dependencies required to support those functions, recovery plans can quickly become overwhelmed by complexity.
The rise of ResOps
Preparing for recovery cannot remain an activity that begins after an incident.
Just as DevOps transformed software delivery and SecOps improved security operations, a resilience-first approach requires recovery readiness to become a continuous discipline rather than an emergency activity.
At Commvault, we refer to this resilience first approach as ResOps. Regardless of terminology, the principle is straightforward: organisations need to integrate cybersecurity, IT operations and data management around common recovery objectives.
In practice, this means continuously testing recovery plans, validating backup integrity, rehearsing recovery scenarios and understanding interdependencies before an incident occurs.
Recovery capability should be measured with the same discipline organisations apply to every other aspect of cyber risk.
Recovery confidence is becoming a business imperative
Perhaps the most important lesson from the past year's cyber incidents is that confidence matters.
When organisations are uncertain about recovery timelines, decision-making becomes harder. The pressure from customers, regulators, shareholders and internal stakeholders intensifies. Business disruptions become more costly and reputational risks increase.
Conversely, organisations that understand their recovery capabilities are able to respond more decisively and communicate more confidently during a crisis.
As Australian businesses continue navigating regulatory change, accelerating AI adoption and growing cyber threats, resilience is rapidly becoming a board-level priority.
The organisations that succeed will not necessarily be those that avoid every incident. They will be the ones that know exactly how long recovery will take, what needs to be restored first and how to keep critical services running when those disruptions inevitably occur.
In a business environment increasingly shaped by operational resilience requirements, closing the gap between expectation and reality may become one of the most important competitive advantages an organisation can possess.
Connect
Explore with AI
Image: Martin Creighan
Related stories
Top stories