A new report from Fastly shows that IT decision makers (ITDMs) are overly optimistic about how long it would take their organization to recover from a serious cyberattack.

The company conducted a survey involving 1,800 ITDMswho were responsible for cybersecurity in organizations in the Americas, Europe, the APAC region, and Japan.
See also: Parliament: Ambiguities and shadows in the Cybersecurity bill
According to the results, it takes an average of 7.34 months to fully recover from a cyberattack, although respondents predicted it would take an average of 5.85 months.
Recovery times are expected to be even longer (8.14 months) for organizations planning to reduce their cybersecurity investments. The gap between perception and reality (34%) is also greater, with these companies taking an average of 10.88 months to recover.
By the term "recovery," Fastly refers to activities such as:
- Implementing stronger security measures (mentioned by 43% of respondents)
- Offering additional training/education to employees (41%)
- Restore from backups (38%)
- Communication with stakeholders (34%)
- Research by cybersecurity experts (25%)
See also: Many businesses believe that employees lack “cybersecurity knowledge”
Around 86% of respondents said their organisation had changed something after a cyberattack (e.g. product updates), while over a quarter (29%) claimed they would consider changing security vendors.
Additionally, nearly half (48%) are reconsidering how they use existing cybersecurity tools .
“Full recovery from breaches doesn’t get any faster. The impact on revenue and reputation, and the time lost , permanently damage business relationships and drain resources from other areas of the business,” a Fastly executive argued.

Cyberattacks are increasing and becoming more sophisticated, so cybersecurity strategies “must be part of a holistic plan and not be jerky reactions.”
See also: Cybersecurity teams struggle to keep up with new attacks
To combat these challenges, companies must proactively invest in cybersecurity measures, such as employee training, regular system updates and patches , and implementing robust incident response plans. These efforts not only help prevent cyber incidents, but also allow companies to respond effectively in the event of an attack.
In conclusion, the recovery period for an organization after a cyberattack can be long and complex. In today's digital age, investing in strong cybersecurity measures is not just an option, but a necessity for companies that want to protect their data, operations, and reputation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.infosecurity-magazine.com
