The state of resilience in 2026: What the Data Health Check tells us

The Databarracks Data Health Check provides an annual snapshot of IT resilience in the UK, tracking how organisations prepare for and respond to disruption. 

Based on responses from 500 UK IT and resilience professionals, the 2026 report shows organisations preparing for a harsher resilience environment, where serious cyber disruption is no longer treated as a remote possibility. 

Below, we explore some of the key findings with commentary from Databarracks’ resilience experts: Chris Butler, Resilience Director, and Charlie Maclean-Bristol, Deputy Resilience Director.

Download the full report: Data Health Check 2026 – Databarracks 

 

65% of organisations say a serious cyber attack could threaten their survival 

The Data Health Check 2026 arrives after a year of high-profile cyber attacks across the UK, affecting major organisations including M&S, Co-op, Harrods and JLR. 

  • Our Anatomy of a Crisis reports break down the M&S and British Library incidents, looking at how disruption unfolded and the key lessons for resilience teams. 

Those incidents made the impact of cyber attacks impossible to ignore. This year’s findings show many organisations are contending with the same pressure: cyber is the leading cause of downtime for the fourth year running, while 65% of organisations say a serious cyber attack could threaten their survival. 

That figure would have been difficult to imagine even a few years ago. Today, it reflects a growing recognition that cyber incidents are no longer isolated technical events. 

The cost of recent attacks shows why the concern is justified. M&S estimated the cost of its cyber attack to be around £300 million, while the JLR incident is estimated to have cost the UK economy around £2 billion. Even for large businesses with deep pockets and reserves, these are staggering sums. Most organisations could not absorb losses on that scale. 

Evidence of organisations failing as a direct result of a cyber attack is still relatively limited, but it does happen. Knights of Old is a notable example: a 158-year-old UK logistics firm that entered administration following a ransomware attack.

Charlie Maclean-Bristol

How many organisations could survive a disruption costing £3.5 million a day? That’s what M&S were facing at one point last year. 

A serious cyber attack can stop trading and create knock-on effects across suppliers and partners. We saw that with CTS, where an attack on an IT provider left around 80 conveyancing firms unable to complete transactions. Travelex is another familiar example: it entered administration after the combined impact of a ransomware attack and COVID-19. 

So when organisations say a serious cyber attack could threaten their survival, that is not an overreaction. It reflects what they have seen happen in the real world.

Chris Butler 

AI-driven attacks have more than doubled in frequency 

AI-driven attacks have more than doubled in frequency in the last 12 months, rising from 12% in 2025 to 25% in 2026. 

They are also, by some distance, the most-cited resilience challenge organisations expect to face over the next 5 years. 

Resilience teams are broadly embracing the benefits of AI, but the threat is developing just as quickly. Deepfakes show how AI can turn familiar cyber risks – impersonation, fraud and social engineering – into something far more convincing and harder to challenge. 

We have already seen what that looks like in practice, from the Arup deepfake attack to the attempted impersonation of Ferrari’s CEO. The best defence is preparation: build verification checks into critical processes, train people to challenge what they see and hear and rehearse deepfake scenarios under pressure.

Chris Butler 

1 in 5 organisations admit not reporting a serious cyber incident 

The full scale of cyber disruption may not be visible. 20% of organisations say they have chosen not to report a serious cyber incident to avoid negative consequences. 

Reputation, customer confidence, regulatory scrutiny and commercial impact may all influence decisions about disclosure. 

This is one of the most concerning findings in the report. When serious cyber incidents go unreported, law enforcement and government agencies have a less complete picture of the threat landscape. That makes it harder to identify patterns across industries and regions, attribute attacks to specific threat actors and warn organisations that may be at risk.

The Cyber Security and Resilience Bill will update incident reporting requirements for regulated entities, but not every organisation or incident will be in scope. That is why incident reporting should be built into cyber response planning. As part of developing and testing cyber playbooks, organisations should identify the right law enforcement and regulatory contacts in advance and, where possible, establish those relationships before an incident occurs. This can improve the speed and effectiveness of reporting and support during a cyber incident.

Charlie Maclean-Bristol 

A quarter of organisations experienced a supplier-originated cyber incident, while half knowingly work with risky suppliers 

Supplier resilience is becoming harder to ignore. 26% of organisations experienced a cyber incident originating from a supplier or third party in the last 12 months, while 48% continue working with suppliers despite known resilience or security concerns. 

This is not always a failure of awareness. Often, organisations know where the risks are but lack simple alternatives. 

Changing suppliers can be difficult, especially where they provide a service that is integral to customer delivery. For many organisations, replacing a supplier with a poor security posture may require significant timecost and operational effort, which can lead to known risks being tolerated for longer than is ideal.

Charlie Maclean-Bristol 

Supplier resilience is part of your resilience, not someone else’s problem.

The risk runs both ways. A supplier incident can quickly become your incident. But if the attack is on your side, suppliers may also sever links to protect themselves from cross-contamination. At the moment you need critical services most, they may no longer be available.

That is why organisations need to understand their supply chain resilience options in advance. Which suppliers are critical? What access do they have? If you lose a critical supplier during an incident, who would you turn to?

Chris Butler 

Only 18% of organisations hit by ransomware paid the ransom 

Ransomware remains a serious threat, but the response picture is encouraging. 

1 in 4 organisations experienced a ransomware attack in the last 12 months. Of those, only 18% paid the ransom, while 59% recovered from backups. 

The findings also show a continued rise in adoption of air-gapped and immutable backups. 76% of organisations now have air-gapped backups, rising to 85% among large organisations. 63% now have immutable backups, up from 59% last year. 

Having air-gapped and immutable backups is one of the most important steps an organisation can take to improve its ability to recover from a cyber attack.

These backups can make the difference between recovering in hours or days, rather than the weeks or even months some organisations have required when both production systems and primary backups have been compromised at the same time.

Charlie Maclean-Bristol 

Every organisation should assume it may face a successful cyber attack. When that happens, the outcome depends on how well it can recover.

Put simply, if you don’t have recoverable backups, you’re not recovering any time soon.

Backups are not just an insurance policy. They are the foundation of recovery. But they need to be protected, tested and ready to use when the organisation is under pressure.

Chris Butler 

Backups brought GoAhead Group back from the brink after a ransomware attack in 2022, with Databarracks guiding the recovery. Read the case study. 

 

The #1 resilience priority in 2026 is integrating IT and business resilience 

This last finding brings the report into focus. 

Organisations are making progress in continuity planning and recovery capability, but the threats they face are becoming harder to manage through isolated teams, plans or controls. 

Integrating IT and business resilience is the top resilience priority for organisations in 2026, cited by 39% of all respondents and rising to 48% of large organisations. 

Resilience has to work across the organisation. A serious cyber attack is not just a cyber security issue. It can become an IT operations issue, a business continuity issue, a crisis communications issue, a supplier issue and a leadership issue all at once.

That is why integrating IT and business resilience matters. Plans, teams and controls are only useful if they work together under pressure. The organisations that respond best are the ones that have already connected those disciplines before an incident happens.

Chris Butler

Learn why building a unified resilience strategy is now critical: Why building a unified resilience strategy is now critical 

Download the full report to explore more findings from the Data Health Check 2026.