Economist Research Supported by AT&T Business Finds 90% of U.S. Firms Don’t Detect Third-Party Disruptions Until After They Begin

Key Takeaways:
- Based on a U.S. survey of more than 1,000 senior technology and operations executives, research from Economist Enterprise, with contributions from AT&T Business, uncovers how mid-market and large organizations are approaching technology resilience and where gaps remain.
- The research finds that while companies continue to prioritize cybersecurity investments, many of the disruptions causing the greatest operational impact stem from third-party dependencies, supply chain failures, and technology ecosystem complexity.
- Resilient organizations are better positioned to maintain customer trust, respond to disruption, and adapt as operating conditions change.
- Greater visibility, resilient connectivity, and regularly tested recovery can help businesses reduce operational exposure and be prepared for disruption.
Technology Resilience Index: Are US firms ready for today’s technology hazards?– a new Economist Enterprise whitepaper, supported by AT&T Business, was published today. It seeks to define technology resilience in practice. Based on a survey of 1,020 senior technology and operations executives, the report examines how U.S. mid-market and large organizations are adapting to an increasingly integrated technology landscape, where resiliency gaps remain, and what lessons can be learned.

“Technology resilience is no longer just an IT concern. It’s a business imperative,” said Zee Hussain, senior vice president of Global Enterprise Solutions, AT&T Business. “Organizations that invest in visibility, resilient connectivity, and recovery readiness are better positioned to maintain customer trust, respond to disruption, and adapt to change. As AI becomes embedded into business operations, the conversation is moving beyond the traditional wide area network (WAN) toward intelligent, resilient platforms that provide the connectivity, observability, and automation needed to support AI-driven enterprises.”
Five Key Learnings on Where Tech Resilience Gaps Remain
Nine in 10 respondents said their organization only discovered a third-party or supply chain failure once disruption had already begun. As connectivity binds today’s economy together, a failure involving a vendor, network connection, or software update can quickly spread across operations. Yet many organizations remain focused on familiar risks, while vulnerabilities emerge at the points where suppliers, legacy systems, networks, and new technologies intersect. The research identifies five areas where resilience strategies are falling short of today’s disruption risks:
- Resilience priorities do not match disruption realities. More than one-third of surveyed organizations cited third-party and supply chain failures as the primary cause of their most significant technology disruption over the past year, ahead of internal system failures and cybersecurity incidents. Despite this, cybersecurity continues to receive the largest share of resilience-related spending.
- Trust stands in for verification. More than half of respondents assess the resilience of critical technology suppliers based primarily on reputation or assurances rather than evidence. The research found that documented resilience plans are common, but comprehensive testing remains less prevalent.
- Larger firms have more resources, but more ground to cover. Bigger companies typically invest more heavily in resilience and have access to greater expertise, but only 5% reported avoiding a major technology incident in the past year, compared with 27% of mid-market firms. The report points to legacy systems and interconnected dependencies as potential sources of additional exposure. Meanwhile, smaller organizations face greater reliance on external support and a more challenging market for technology talent.
- AI adoption is moving faster than resilience preparation. Although relatively few (4%) organizations identified AI or automation failures as the cause of their most significant disruption, the research indicates organizations further along the AI adoption curve have already experienced at least one AI-related incident last year. Preparedness for AI-related risks remains behind many other resilience capabilities.
- Stronger resilience is associated with three habits. Survey results indicate that organizations with stronger resilience capabilities are more likely to learn from disruptions, regularly test response and recovery plans, and establish clear executive ownership for resilience initiatives. Almost three quarters reported testing cyber response, against just 15% who have rehearsed a geopolitical or trade disruption.
The Business Impact of Resilience
Technology resilience has implications far beyond IT. It helps financial institutions keep critical transactions and services accessible, healthcare organizations maintain connected clinical systems, and retailers and manufacturers sustain customer-facing and operational processes during disruption. As businesses become more digitally connected, resilient connectivity can help keep these essential functions available. Building redundancy, visibility, and recovery into the network can help businesses limit downtime and maintain the experiences customers and stakeholders depend on.
No organization can eliminate disruption entirely, but those that identify dependencies early, improve visibility, and regularly test their response will be better positioned to preserve market confidence and turn disruption into opportunity.
Read the full white paper here:
Research Methodology
The Technology Resilience Index: Are US firms ready for today’s technology hazards? is an Economist Enterprise whitepaper supported by AT&T Business, based on a survey and expert interview program, informed by an initial phase of desk research to define technology resilience in practice. The survey polled 1,020 senior technology and operations executives at mid-sized (100-9,999 employees) and large (10,000+ employees) U.S. enterprises across seven sectors – healthcare, manufacturing, financial services, retail, hospitality, professional services and technology – between June and July 2026.



