Cyberattacks Now Directly Impact Financial Forecasts and Growth, New Study Reveals
A recent study by data security firm Cohesity, based on a September 2025 survey of 3,200 IT and security leaders, highlights the escalating financial and operational consequences of cyberattacks. The findings, detailed in the 2026 Global Cyber Resilience Report, reveal that 76% of organizations experienced a material cyberattack defined as an incident with measurable financial, reputational, or operational damage significant enough to influence quarterly business reviews.
For public companies, the fallout is immediate and visible: 70% adjusted earnings or financial guidance following an attack, while 68% saw their stock prices react. Cohesity CEO Sanjay Poonen emphasized that cyber resilience is no longer just an IT concern but a "business and financial imperative," with risks now appearing in board-level discussions rather than just security operations.
Private firms face quieter but equally damaging repercussions. A striking 73% diverted funds from innovation and growth to cover recovery costs expenses that rarely appear in public disclosures but erode competitive positioning over time. Separate research from Cohesity found that UK CEOs estimate a revenue loss of roughly 15% of annual income per incident, with most doubting their cyber insurance would fully cover the costs.
Legal and regulatory consequences are nearly universal among affected organizations, with 92% facing fines, lawsuits, or compliance penalties. Meanwhile, 81% of IT and security leaders admit that generative AI is outpacing their ability to manage its risks, and only 47% express full confidence in their resilience.
The study underscores a shift in how businesses must approach cybersecurity: quantifying financial exposure upfront, funding immutable recovery systems as capital expenditures, and aligning insurance coverage with real-world recovery costs. The data suggests that without proactive measures, the financial and operational toll of cyberattacks will continue to reshape corporate budgets and strategies.
Source: https://www.cybersecurity-insiders.com/cyber-resilience-earnings-guidance-cohesity/
Cohesity cybersecurity rating report: https://www.rankiteo.com/company/cohesity
"id": "COH1789057679",
"linkid": "cohesity",
"type": "Cyber Attack",
"date": "9/2025",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'location': 'Global',
'type': ['public companies', 'private firms']}],
'date_publicly_disclosed': '2025-09',
'description': 'A study by Cohesity reveals that 76% of organizations '
'experienced a material cyberattack with measurable financial, '
'reputational, or operational damage significant enough to '
'influence quarterly business reviews. The report highlights '
'the financial and operational consequences of cyberattacks, '
'including adjustments to earnings, stock price reactions, '
'diversion of innovation funds, and legal/regulatory '
'penalties.',
'impact': {'brand_reputation_impact': 'Measurable reputational damage',
'financial_loss': '15% of annual income per incident (estimated by '
'UK CEOs)',
'legal_liabilities': '92% of affected organizations faced fines, '
'lawsuits, or compliance penalties',
'operational_impact': 'Diverted funds from innovation and growth '
'to cover recovery costs',
'revenue_loss': '15% of annual income per incident (estimated by '
'UK CEOs)'},
'lessons_learned': 'Cyber resilience is a business and financial imperative, '
'requiring proactive measures such as quantifying '
'financial exposure upfront, funding immutable recovery '
'systems, and aligning insurance coverage with real-world '
'recovery costs.',
'post_incident_analysis': {'root_causes': 'Generative AI outpacing risk '
'management capabilities (81% of '
'IT/security leaders admit this)'},
'recommendations': ['Quantify financial exposure upfront',
'Fund immutable recovery systems as capital expenditures',
'Align insurance coverage with real-world recovery costs'],
'references': [{'source': 'Cohesity 2026 Global Cyber Resilience Report'}],
'regulatory_compliance': {'fines_imposed': '92% of affected organizations '
'faced fines',
'legal_actions': '92% of affected organizations '
'faced lawsuits or compliance '
'penalties'},
'response': {'recovery_measures': 'Funding immutable recovery systems as '
'capital expenditures'},
'title': 'Global Cyber Resilience Report 2026 - Material Cyberattacks Impact '
'on Financial Forecasts',
'type': ['cyberattack', 'data breach']}