73% of UAE organisations hit by major cyberattacks: Cohesity
Cohesity’s research identified a significant gap between how organisations plan for recovery and what happens during an actual attack
23 September, 2026
TT
16
Nearly three-quarters of UAE organisations experienced a material impact from a cyberattack over the past 12 months, up sharply from a year earlier, according to new research from Cohesity.
The fifth annual Cohesity Global Cyber Resilience Report found that 73 per cent of UAE organisations suffered a material cyberattack in the past year, compared with 59 per cent in 2025. Almost nine in 10, or 88 per cent, said they had experienced such an attack at some point.
The findings point to a growing focus on recovery as organisations contend with increasingly complex attacks and seek to restore critical business operations with minimal disruption.
Nearly two-thirds, or 64 per cent, of UAE organisations said they have a cyber resilience strategy but recognise that it still needs improvement to address current threats and challenges. That compares with 54 per cent in 2025.
Johnny Karam, managing director, International Emerging Region at Cohesity, said: “UAE organisations are strengthening their cyber resilience even as attacks grow more frequent and sophisticated. What the research tells us is that many recovery strategies are still built for a version of an incident that doesn’t reflect what teams actually encounter once an attack hits. Closing that gap is the next stage of resilience maturity in the region.”
Recovery plans face real-world test
Cohesity’s research identified a significant gap between how organisations plan for recovery and what happens during an actual attack.
While 91 per cent of organisations’ recovery plans assume the process will follow a largely linear, step-by-step sequence without significant backtracking, 93 per cent of those that suffered a material attack in the past year said recovery required workarounds or improvisation.
Among organisations affected by an attack, 88 per cent identified gaps in how their recovery plans accounted for critical dependencies, including artificial intelligence (AI) systems, third-party integrations, security tools and workforce skills.
Another 71 per cent found that the scope of the attack extended beyond their initial assessment.
“Recovery rarely follows a linear path. Organisations need to adapt as attacks evolve and new dependencies emerge, and that’s reshaping how we should think about resilience,” Karam said.
Operational recovery remains a challenge
Restoring technology systems does not necessarily mean businesses can immediately return to normal operations, the report found.
Among UAE organisations experiencing a material cyberattack over the past year, 93 per cent said business recovery was delayed by dependencies between systems that had not been validated or were not functioning correctly.
Another 93 per cent cited a lack of confidence that restored data and systems were clean and safe to use, while 90 per cent reported that key systems or applications had been restored but were not yet fully functional or verified for use.
Despite those concerns, only 45 per cent of organisations that suffered a material attack in the past year conducted an independent forensic review to validate restored systems before reconnecting them to production environments.
The findings suggest cyber resilience is increasingly becoming a wider business continuity issue rather than solely an IT concern, with organisations facing pressure to restore operations quickly while ensuring recovered systems and data are safe to use.





















