<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

The State of Software Resilience 2026

Verified 2026 statistics on software and vendor failure, downtime costs, SaaS dependence, and the DORA and NIS2 rules making continuity a legal requirement.
Ben Espach
Last updated:

Look under the hood of almost any company today, and you'll find it running on software it doesn't own. The finance team works inside one vendor's platform, that platform runs on someone else's cloud, and a dozen smaller tools fill the space between, most of them from companies your staff couldn't name.

For years that's been the norm. It's cheaper than building your own and easy to hand off to someone else as long as it works. It also exposes you to more risk.

Software resilience refers to your ability to keep running when those dependent systems fail, are attacked, or ship something broken. The truth is, most industries are built on concentration risk. True software resilience is not all that common.

This post shows the current state of software resilience across six key industries, highlighting how much they depend on outside software, how often it fails, who attacks it, and what it's costing those industries.

Most of the software you run belongs to someone else

Let's start with how much businesses are handing off to outsiders, since that sets the foundation of exposure for everything else. In the EU, 77.5% of the enterprises that buy cloud services run core work — finance, ERP, daily operations — on systems they rent rather than own.

Renting would not be such an issue if the services were spread across thousands of suppliers. They're not. The market leans on the same few. In late 2025, European regulators named 19 companies, among them AWS, Microsoft Azure, and Google Cloud, that have become dangerously central to the EU's financial system.

Other sectors have run this to its limit. Almost every US non-federal acute hospital, 99.4% of them, keeps patient records in a certified electronic system, and just three companies supply 80% of that market.

So whatever continuity plan a hospital has written up depends on the same three release schedules and the same three security teams that every other hospital relies on.

And these systems are known to fail. Cloudflare sits in front of 23.4% of all websites, so when one configuration file broke last November, X, Spotify, and literal millions of other sites across the globe went dark simultaneously.

» Find out exactly how Cloudflare's faulty config crashed over 20% of the internet

Software vendors fail faster than most businesses

So much rides on so few companies that their staying power intimately affects your own. And the overall track record isn't looking great. The Bureau of Labor Statistics tracks it business by business: 65.3% of new US businesses close within ten years; a fifth in the first year alone, half by year five.

Narrow it to software companies, and the odds get worse. In the information sector, which comprises most of the software industry, only 29.1% of the businesses founded in 2013 were still trading a decade later. That is the second-worst ten-year survival rate of the 19 industries the Bureau of Labor Statistics tracks, beaten only by mining.

What the averages don't show is how abruptly those businesses tend to close. Bench, a bookkeeping platform that had raised $113 million, shut down on December 27, 2024. It did not issue any warning; customers found out on the same day, locking roughly 12 000 businesses out of their records right before year-end.

Two weeks earlier, its salespeople were still on the phone renewing contracts. The company health you're checking during procurement is a snapshot that goes stale fast.

Company size doesn't offer any reassurances either. Other airlines flew through the December 2022 storm and recovered. Southwest's crew-scheduling software could not keep pace, and the meltdown canceled 16 900 flights and drew a $140 million federal penalty — the largest consumer-protection penalty in US aviation history, and 30 times larger than any the Department of Transportation had issued before.

Failure wears more than one face. For two decades the UK Post Office falsely prosecuted around 1 000 subpostmasters for theft, using data from its own Horizon system as evidence. The public inquiry found that Post Office employees knew Horizon produced false shortfalls, and that the organization "maintained the fiction that its data was always accurate" anyway. The presumption that computer evidence is reliable is now under formal review in UK law.

Cyber attackers aim where downtime hurts most

A vendor doesn't even have to collapse for you to lose your systems. Someone can simply hold them ransom. Attacks cluster where being offline is least survivable, because that's where victims pay fastest to make it stop.

In the EU, ransomware now accounts for 81.1% of the incidents ENISA ties to plain criminal profit rather than espionage or activism. In Australia, someone files a cybercrime report roughly every six minutes, around the clock — 84 700 of them were recorded in a single year.

And there are no signs of the situation calming down. The FBI's ransomware complaints have climbed for three years running, from 2 825 in 2023 to 3 611 in 2025, and hit 14 of the 16 sectors the US labels critical infrastructure. 

Healthcare is the most-attacked critical infrastructure sector in FBI reporting, with 460 ransomware complaints in 2025. And when attackers went after Australian healthcare, they succeeded 95% of the time, against 52% across all sectors.

» Discover how escrow solves healthcare's digital dependency problem

Software failure now has a public price tag

Software failure costs used to appear only in vendors’ own marketing material. Regulators, statistical agencies, central banks, and companies’ own filings now record specific losses from cyber incidents and software failure, revealing the true impact in the tens of billions and even measurable hits to national growth.

The headline figure is blunt enough on its own. The FBI puts reported US cybercrime losses at $20.877 billion in 2025, a 26% jump in a single year.

The real weight, though, lands in single incidents. One of them rewired part of the US health system: the ransomware attack on UnitedHealth's Change Healthcare unit carried a total impact of $3.1 billion and reached about 190 million people, stalling pharmacies and hospitals for weeks.

One security vendor's faulty 2024 update crashed 8.5 million machines worldwide. For Delta Air Lines alone it meant five days down, 7 000 canceled flights, 40 000 servers reset by hand, and a $550 million loss reported to the SEC.

The 2025 Jaguar Land Rover attack cost the UK an estimated £1.9 billion, drew a £1.5 billion loan guarantee, and reached the Bank of England's monetary policy report as a drag on GDP.

Once one company's outage moves a national growth figure and needs a £1.5 billion state loan guarantee to keep its suppliers solvent, software resilience has stopped being a line item in procurement. It's become a matter of public policy.

How the risk splits by industry

None of this lands evenly. The same forces — rented software, thin survival odds, attackers hunting downtime — hit some industries far harder than others, and the shape shifts depending on which business you're in.

Industry 10-year survival rate Recent incidents
Healthcare 35.6%

•  460 US ransomware complaints, the most-hit sector

• Australian healthcare ransomware incidents doubled in a year

•  +264% large ransomware breaches since 2018

Finance 37.5% • 258 US ransomware complaints, the third most-hit
• DBS Bank: five 2023 outages drew ~S$1.6 billion in extra regulatory capital
The first sector to get its own ENISA threat report
Manufacturing 43.7% • 59.3% of EU manufacturing incidents are cybercrime, the highest share
• 355 US ransomware complaints, second only to healthcare
• Toyota: 14 plants halted when a server filled its disk and the backup failed with it
Transport 34.1% KNP Logistics: 730 jobs lost after ransomware wiped its systems and backups
• Southwest: $1.1 billion+ total cost from a 2022 scheduling meltdown
• 80 US ransomware complaints against transportation
Public sector n/a (surveys exclude government) Synnovis: 11 000+ NHS appointments and procedures delayed
• Atos: French state bought its Bull computing arm for €404M after near-insolvency
• Horizon: £600 000 fixed settlement per quashed conviction
Retail 41.7% M&S: ~£300 million profit hit, online orders down 46 days
McDonald's: one configuration change closed restaurants across four continents in a day
E-commerce is 16.8% of US retail, ~$320 billion a quarter

This is a slice of the full story. Our full The State of Software Resilience research report maps all four threats, adding compliance exposure and defect risk, across every industry here. Click the link at the bottom of this page to see the full report. 

Regulators are now demanding proof of recovery ability

Damage this large, across this many industries, doesn't stay unregulated for long. Across four jurisdictions, the new rules share one core idea: they've stopped asking whether you have security in place and now demand evidence that you have tested a full recovery.

Regulation Where In force from Penalty ceiling
DORA EU Jan 2025 Up to 1% of daily worldwide turnover (critical providers)
NIS2 EU Oct 2024 €10M or 2% of global turnover
Cyber Resilience Act EU Dec 2027 €15M or 2.5% of global turnover
GDPR Art. 32 EU Active €20M or 4% of global turnover
CPS 230 Australia Jul 2025 Supervisory enforcement
HIPAA Security Rule US Active Civil monetary penalties

These aren't empty threats. US health regulators have built an enforcement drive around a single failing: firms that never analyzed their own security risks. Settlements run from $10 000 for a Michigan surgical group to $3 million for a national medical supplier — and the penalty is for never having checked, not for being breached.

Enforcement has raced out ahead of readiness, though. Only four of the 27 EU states met the NIS2 transposition deadline, and in a DORA reporting dry run, just 6.5% of 947 registers passed every data-quality check. And worse yet, just 25% of UK businesses keep a formal incident response plan, in a year when 43% of them were attacked.

» See what the new regulatory wave means for your software security compliance

How to get your software resilient with escrow

The reason so few businesses can show proof they'd be able to recover is that the assets their recovery depends on are held by the vendor. When a provider fails or is hit, they take source code, data, and configurations with them. You cannot prove recovery if everything you need is inside someone else’s systems.

Software escrow solves that by backing up those assets in a neutral environment ahead of time. A third party holds your source code, data, and full operating environments, updated through automated syncs, so a vendor failure does not remove your ability to recover.

But just storing a copy isn't enough. Roughly 90% of untested escrow deposits fail when someone eventually tries to rebuild from them. That is what verification build tests exist to catch.

Codekeeper's Certified verification tier will rebuild the full system in a remote environment for you, to ensure nothing breaks. You're then issued a Software Resilience Certificate you can use as evidence under DORA, NIS2, CPS 230, HIPAA, ISO 27001, and GDPR.

The one investment you can't make late

Every headline number in this post is a recovery bill, and nearly all of it came due after the failure. The billions went to lawyers, cleanup, ransoms, and lost business, all spent trying to buy back something that was already gone.

And yet none of that money reached the thing that decides the outcome: the source code, data, and environments your recovery runs on. Once a vendor fails, no budget conjures those back.

Money spent early closes that door. With critical software assets already in your hands, a vendor's collapse has nothing to hold over you, no ransom worth weighing, no legal bill run up in a panic, because your way out was secured well before you needed it.

Take a look at our full breakdown of the current state of software resilience.

Download "The State of Software Resilience" report for free!

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo