Incident Response, Business continuity, AI/ML

Changing the game: How AI forces organizations to revisit assumptions about recovery and resilience

It's become quite clear that artificial intelligence is changing both sides of the cyber-resilience equation.

That's because attackers can use AI to automate their operations, discover vulnerabilities in high-profile targets and operate more persistently. This in turn increases pressure on defenders to keep ahead of their adversaries and shortens the time available to respond.

At the same time, businesses are embedding AI instances and agents into their own critical workflows, creating new systems and dependencies that themselves must be recoverable after a major outage or incident.

Yet recovery planning has not kept pace with the rapid evolution of AI. Cohesity's 2026 Global Cyber Resilience Report found that while 99% of the 3,200 IT and security decision-makers who were surveyed said they used AI, only 39% said that their cybersecurity response and recovery plans comprehensively accounted for attacks on AI systems, applications, workflows or machine-learning models.

"Less than half of organizations that we talked to had formally included their AI systems into their recovery plans," said Cohesity VP of Product and Solution Marketing Rob Sadowski in a recent interview with Enterprise Security Weekly's Jackie McGuire. "We have more and more of our critical operations being influenced or even driven by AI, yet they don't have it incorporated in the plan."

Meanwhile, 83% of survey respondents admitted their existing recovery plans would likely require moderate to significant changes to cope with advancing frontier-AI capabilities.

All the ways AI will change resilience and recovery

AI expands an already complicated attack surface. In the past 15 years, organizations moved from traditional on-premises infrastructures to cloud, hybrid, SaaS and API-first architectures. Today, AI agents and brand-new technologies such as MCP servers introduce still more connections and dependencies.

AI also enables adversaries to automate attacks and vulnerability discovery, making attacks faster and more relentless.

But AI is also becoming part of the business itself — and must become part of recovery plans and resilience efforts. Recovery can no longer focus only on restoring conventional applications and data. Companies must be able to restore AI models, workflows, agent infrastructure, configurations and the data those systems depend upon.

Fortunately, AI can also strengthen and accelerate recovery. Among the surveyed respondents who had recently experienced material cyberattacks, 80% said that AI-enabled tools helped with threat detection, root-cause analysis, recovery orchestration, identification of clean restore points and validation that restored systems were safe.

Why AI needs to be built into recovery plans

One nightmare AI scenario involves an agent doing something destructive without being compromised. Cohesity found that 56% of survey respondents said they were not well prepared to detect, contain and recover from unintended or incorrect actions by agents, copilots or AI workflows.

Recovery must therefore work in two directions at once. Organizations need to roll back affected business systems to the state preceding an agent's erroneous actions. But they may also need to recover the agent itself.

"What does the agent have access to? And if it makes a mistake or makes an error, does some unwanted action, can I go and roll those systems back to a state before the agent made that error?" Sadowski asked. "Can I actually roll back the agent itself back to a point in time when it was functioning according to spec?"

Long-running agents accumulate memory, configurations and database values. If bad code, data poisoning or another problem changes an agent's behavior, organizations need the ability to restore that agent to a point when it was functioning correctly.

How to adapt your recovery process for the AI age

The process of modernizing your restoration and resilience plans should begin by replacing system-centric recovery with. Cohesity's research found 78% of respondents said they focused their plans more on restoring IT systems than on maintaining critical operations and serving customers.

Organizations should instead define their "Minimum Viable Company": the smallest combination of applications, data and dependencies necessary to continue critical operations. They should map AI systems and their dependencies into that model and repeatedly test whether their new recovery plans truly work.

"If you don't know what are the minimum sets of systems and data and applications you need to keep the business running, it's going to be really hard to prioritize and drive action around those," Sadowski explained.

Automation can then accelerate labor-intensive recovery tasks such as clean-room recovery, data scanning and dependency validation. Humans can still make the critical decisions. Automation also makes frequent recovery testing more practical.

"When you have a reasonable amount of automation, it makes testing easier," said Sadowski. "And when you test and make sure that the process actually works, you gain more confidence. It's going to be less stressful."

Sadowski also recommends following Cohesity's "Five Steps of Cyber Resilience."

"Do you have all your data backed up? Do you have an immutable copy? Have you scanned that data regularly for threats?" he asked. "Have you automated the recovery process? Do you understand some of the new data risk that's coming into your organization at all times? And are you using that to reinforce a basic process that you can document and continue to drive progress against?"

AI is simultaneously a threat accelerator, a new category of critical infrastructure and a defensive tool. These triple aspects require organizations to revisit their existing recovery plans.

Organizations should take inventory of their AI assets, identify dependencies, protect AI models and agent states, maintain clean and immutable recovery points, automate repeatable recovery work, retain human control over consequential decisions, and regularly test the entire process.

"Have a methodology, make sure your plan reflects that, and keep working at it," said Sadowski. "That's it. It's a constantly evolving state that you need to focus on."

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Paul Wagenseil

Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds