Despite years of digital transformation, IT resilience remains a critical vulnerability for UK enterprises.
According to the latest research from Asanti, 72% of senior IT decision makers reported experiencing significant disruption or downtime in the past year due to IT resilience issues with only 31% expressing extreme confidence in their current disaster recovery and business continuity plans.
The research, conducted by Vanson Bourne, surveyed 100 senior IT leaders across public and private sector organisations. The findings reveal a concerning disconnect between perceived and actual resilience performance.
The study revealed major gaps in recovery preparedness, with only 56% of organisations surveyed having fully defined and regularly tested recovery time objectives (RTOs), and just 36% say the same for recovery point objectives – the core thresholds set for acceptable downtime and data loss.
It also revealed significant operational fallout, with 60% of businesses struggling to return to normal operations after a major resilience disruption, while 58% admitted to suffering substantial financial losses.
This is all contributing to crisis of confidence when it comes to risk recovery, as over half of respondents reported only low or medium confidence in handling major risks like cyber breaches (54%), data centre outages (61%), or unauthorised physical access (62%).
The research also identifies a “resilience competency gap”, where critical planning, testing and investment decisions are lagging behind the complexity and frequency of modern IT threats. Despite widespread cloud adoption, 51% still view cloud service outages as one of the top risks to operations – surpassing even traditional IT system failures (49%).
“Too many organisations assume they’re more resilient than they actually are,” commented Stewart Laing, CEO of Asanti. “This research makes clear that real resilience isn’t about where your systems live – it’s about how well you’ve prepared to keep them running. Without clearly defined recovery objectives, rigorous testing and a culture of proactive risk management, even the most advanced infrastructure can fail. Business leaders must move beyond surface-level confidence and embed resilience into every layer of operations.”
Recommended reading
- ITSX Summit | Sustaining and Enhancing Service Delivery Amid Disruption
- CISOs Rely on AI To Reduce Costs and Enhance Cyber Resilience
- Cloud Outages Top Risk for UK IT Leaders, New Study Finds
The Human Factor
The study found that 89% of respondents believe human oversight is a critical vulnerability in their resilience strategy, while 91% agreed that operational failures due to human error could compromise backup power capabilities.
While 59% of those respondents said that they test their business continuity and disaster recovery plans at least every six months, these exercises often lack the depth required to reveal systemic resilience weaknesses. Only 31% of respondents felt extremely confident in their current business continuity and disaster recovery plans – a sobering indicator of widespread fragility.
Downtime’s Impact
Although most firms track downtime (77%) and financial impact (73%) of resilience incidents, softer yet critical indicators like reputational impact (54%) and impact on digital transformation goals (57%) are often overlooked.
“Measurement is the foundation of resilience,” added Laing. “If you’re only tracking outages and costs, you’re missing the true business impact. Resilience must be strategic, tested and integrated across infrastructure, operations and leadership thinking.”





