Issue date: September 2026
The resilience gap is widening, and enterprises are running out of road to ignore it. Cloud adoption was supposed to simplify recovery. Instead, multi-cloud architectures, wider attack surfaces, and IT skills shortages are making full operational restoration slower, not faster.
Now in its fourth year, this report surveys 300 IT decision-makers and influencers - 200 in the U.S., 100 in the U.K. - across 10 industry sectors, all at organizations with 1,000+ employees. Fieldwork ran April 2026.
The cloud resilience illusion
Confidence in the cloud is rising faster than the cloud is delivering. 68% of organizations now believe operating in the cloud makes them inherently more resilient, up from 59% in 2025. 93% call disaster recovery a key strategic focus when managing cloud environments, up from 89% last year.
The data says otherwise. 74% of enterprises experienced meaningful IT-related business disruption in the past 12 months - flat against 73% in 2025. 71% report a rise in disruptions tied specifically to cloud architecture, ahead of cyber attacks (65%) and legacy on-premises systems (50%). And 79% say cloud-related outages now take longer to fully resolve than they did a year ago, up from 75% in 2025. Greater cloud reliance isn't buying faster recovery - it's buying longer outages.
The risk has moved from compliance to revenue
In 2025, compliance and regulatory penalties were the single biggest named risk of a failed recovery, cited by 64% of organizations. That's flipped. 70% of organizations now rank customer churn and revenue loss in their top three risks - up from 46% in 2025. Reputational damage follows at 60% (up from 52%), inability to recover from cyber attacks sits at 52% (down from 63%), and compliance penalties have dropped to fourth place at 48%.
Regulation hasn't disappeared as a driver, though - it's just working quietly in the background: 51% report a sharper strategic focus on DR because of it, 50% are scrutinizing IT partners and vendors more closely, and 49% have increased capital investment in disaster recovery as a direct result. When a failed recovery costs customers, not just a fine, incident response stops being a back-office metric and becomes a major incident management problem the whole business owns.
Confidence is outrunning testing
34% of organizations haven't updated their disaster recovery plans in over a year - up from 31% in 2025. Asked why, 31% point to "absolute confidence" in their existing plans (up sharply from 23% in 2025), 21% cite reliance on active/active infrastructure, and 20% cite resource constraints. Notably, "process complexity" - last year's top excuse - has fallen to fourth place, down from 31% to just 17%. The barrier isn't that updating plans is hard anymore. It's that teams believe their architecture makes updating unnecessary.
Automation works - but it's fragmented
88% of organizations agree automation investment improves recovery outcomes. But deployment is uneven: automation is highest for communication and collaboration tasks (54%) and manual repetitive tasks (50%), while integration with core systems - CMDB, ITSM, Infrastructure-as-Code - has dropped from 55% to just 39% in a year. The barriers: not knowing where to prioritize automation efforts (44%), lack of confidence scaling it (38%), and distrust of AI-driven recovery decisions (38%).
Agentic AI: advise, don't execute
97% of IT leaders expect agentic AI to reshape disaster recovery within two to three years, and 85% are enthusiastic about the efficiency gains - up from 81% in 2025. But where they'll let an agent act varies sharply by risk. Organizations are comfortable with agents synthesizing DR plans and runbooks from existing data (55%), analyzing post-event metrics to suggest improvements (54%), flagging alternative options mid-recovery (53%), and retrieving information for human operators (51%).
That comfort collapses once the agent's output becomes an action instead of a recommendation. Only 30% would trust an agent to make recovery sequencing decisions across systems, and just 30% would let one independently trigger failover or rollback. 90% say human oversight remains essential no matter how embedded agentic AI becomes in recovery. The agent analyzes and flags. The person decides.
What enterprises require before they'll adopt it
Trust isn't unconditional - it's contingent on specific guardrails. 53% want explainability and audit trails showing exactly why the agent took an action. 49% want identity and access controls limiting what systems it can touch. 47% want automatic compliance validation, 46% want automatic rollback safeguards, and 46% want mandatory human approval before any high-risk action executes. These aren't nice-to-haves - they're the conditions for governed AI adoption in recovery workflows.
Three imperatives for resilience leaders
Test continuously, not once a year - confidence in an active/active setup means nothing without ongoing validation. Connect automation instead of scattering it across one-off scripts that only alert, not act. And build agentic AI inside a governed model from day one: let it analyze and flag, but keep a human on the decision to pull the trigger.
Download the full report, or book a demo to see how Cutover puts governed, agentic control into practice for large, highly regulated enterprises.




.webp)
.webp)