Research Notes

OpenText 2025 Ransomware Survey: Confidence Is High, But Does It Reflect the Reality of Recovery?

Research Finder

Find by Keyword

OpenText 2025 Ransomware Survey: Confidence Is High, But Does It Reflect the Reality of Recovery?

Survey exposes the widening gap between perceived readiness and actual recovery performance

Key Highlights:

  • OpenText Cybersecurity surveyed 1,773 IT and security leaders across six countries. While 95% said they were confident they could recover from ransomware, only 15% of those attacked fully recovered.
  • AI-driven attacks and third-party risks are accelerating: 52% reported phishing or ransomware incidents tied to AI, and 25% traced an attack to a software partner.
  • 88% of organizations allow GenAI tools, yet only 48% have a formal AI-use policy, illustrating a governance gap.
  • 71% of respondents said ransomware is now a top-three business risk at the board level.
  • The results reinforce HyperFRAME Research’s findings that enterprise resilience maturity depends on tested recovery assurance rather than perception of preparedness.

The News

  • OpenText released its 2025 Global Ransomware Survey, revealing that most organizations remain overly confident in their ability to recover from an attack. Nearly every respondent expressed confidence, yet only 15% of those who experienced a ransomware event achieved full recovery.

    The report also highlights how AI and third-party exposure are reshaping enterprise risk. More than half of respondents reported AI-assisted phishing or impersonation attempts, while one in four said a ransomware incident originated through a supplier or software vendor. Despite this, 88% of organizations allow GenAI use within the business, and fewer than half have a formal policy to govern it.

    Leadership awareness is increasing: 71% of respondents said ransomware now ranks among their top three business risks, while 64% said customers or partners have asked about their recovery posture. Read the OpenText announcement for more information.

Analyst Take

OpenText’s findings confirm what we at HyperFRAME Research have been tracking across the data-platform market: confidence does not equal capability. Most enterprises have invested in protection tools, yet few can demonstrate verified, repeatable recovery.

We have been watching the convergence of these trends closely, identifying a clear confidence gap and highlighting verifiable recovery as a competitive benchmark. The market is evolving from storage-level snapshots to platform-level recovery services that isolate and validate clean data. AI and governance are converging within resilience offerings, a dynamic reflected in OpenText’s survey data on AI-enabled threats.

The OpenText findings reflect a shift in the data resilience landscape. Enterprises have invested heavily in protection technologies, but most still lack the automation and validation layers that make recovery predictable. Resilience is no longer defined by backup success but by verified, automated recovery. The industry is at a turning point, and vendors are responding to help organizations move from confidence in prevention to confidence in outcomes.

As the threat surface expands with AI and supplier complexity, true resilience depends on how quickly and cleanly organizations can recover. OpenText positioned the study as part of its broader effort to raise awareness of “rising confidence meeting a growing AI threat,” reinforcing its focus on secure information management and operational trust. We concur. Enterprises may believe they are resilient, but few have validated recovery processes to prove it.

Looking Ahead

It’s clear that enterprise resilience remains uneven at best, and that the next stage of maturity will focus on verification and automation.

The OpenText survey shows that organizations continue to equate preparedness with protection. Recovery plans are often documented but rarely exercised under real conditions, leaving a disconnect between perception and operational reality. The fact that only 15% of organizations fully recovered from a ransomware attack confirms the gap. True resilience now requires continuous validation, running controlled recovery drills, verifying clean-data integrity, and measuring mean time-to-restore (MTTR) as rigorously as uptime. The organizations leading in this area treat recovery as a recurring performance test rather than an after-incident process.

The rapid adoption of generative AI without governance controls presents an emerging compliance and trust challenge. Many need look no further than their own organization to confirm this. The fact that 88% of companies allow GenAI use while fewer than half have a formal policy indicates that enterprises are moving faster than their governance frameworks can adapt. This imbalance is drawing regulatory attention as the provenance and privacy of AI-processed data become audit priorities. Enterprises must now design resilience into AI operations, ensuring not only that data can be recovered, but that it remains accurate, accountable, and compliant after AI interaction.

Ultimately, resilience is moving from a security outcome to a business differentiator. As vendors integrate governance, protection, and recovery into unified data platforms, the metric that matters most will be verified recovery assurance. Many are already defining this direction by embedding resilience within their core architectures. The advantage will go to those who can demonstrate verifiable recovery, proving through automation and transparency that data can be restored quickly, cleanly, and consistently across environments. In an era shaped by AI and regulatory scrutiny, operational assurance has become not just an IT priority but the foundation of enterprise trust.

Author Information

Don Gentile | Analyst-in-Residence -- Storage & Data Resiliency

Don Gentile brings three decades of experience turning complex enterprise technologies into clear, differentiated narratives that drive competitive relevance and market leadership. He has helped shape iconic infrastructure platforms including IBM z16 and z17 mainframes, HPE ProLiant servers, and HPE GreenLake — guiding strategies that connect technology innovation with customer needs and fast-moving market dynamics. 

His current focus spans flash storage, storage area networking, hyperconverged infrastructure (HCI), software-defined storage (SDS), hybrid cloud storage, Ceph/open source, cyber resiliency, and emerging models for integrating AI workloads across storage and compute. By applying deep knowledge of infrastructure technologies with proven skills in positioning, content strategy, and thought leadership, Don helps vendors sharpen their story, differentiate their offerings, and achieve stronger competitive standing across business, media, and technical audiences.