Organisations across Australia and New Zealand are increasingly identifying the business functions they need to maintain during a cyber crisis, but many have yet to establish which technology systems and data are required to keep those functions operating.
New research from Commvault has revealed a significant gap between business continuity planning and technology recovery readiness.
Commvault’s State of Data Resilience ANZ 2026 report found that 61% of ANZ organisations have defined the minimum business functions required to continue operating during a cyber crisis.
However, only 43% have identified the technology environments needed to support those functions.
The gap could create significant challenges during a ransomware attack or other major cyber incident. Knowing which business functions are essential is only part of the recovery equation. Organisations also need to understand which applications, systems and data underpin those functions and whether they can actually be recovered.
Organisations that define both their minimum business functions and the technology required to support them are significantly more likely to maintain operations and recover faster following a cyberattack, according to the research.
“Organisations need to stop making recovery decisions during a crisis and start building resilience before one occurs,” said Gareth Russell, Field CTO, Security, Asia Pacific at Commvault.
“The conversation needs to shift from ‘How do we recover everything?’ to ‘What must we recover first?'”
Russell said organisations that establish a Minimum Viable Company before an attack can identify the people, applications, systems and data required to keep operating during a disruption.
“They’ve already proven they can recover them. That’s how you reduce downtime, remove uncertainty and avoid treating ransomware payments as a recovery strategy,” he said.
The findings come as organisations continue to expand their technology environments, adopt artificial intelligence and manage increasingly large and complex data estates.
Commvault says this makes prioritising critical systems and data increasingly important. Attempting to recover everything simultaneously following a cyberattack can introduce further uncertainty, while clearly defined recovery priorities can help organisations restore the operations that matter most first.
The research highlights the need for organisations to connect business continuity planning with technology recovery planning, ensuring that critical business functions are supported by clearly defined and tested recovery capabilities.
The research was independently conducted by TRA, now part of Omdia, surveying 411 organisations across Australia and New Zealand. Respondents included CIOs, CISOs, IT leaders, IT decision makers and their direct reports.








