More than half of senior African executives believe they could recover clean, usable data after a ransomware attack. Yet, nearly a third have never performed a full technical recovery test, or haven’t done so in over a year. This disconnect sits at the core of a new ITWeb and Veeam survey on data trust and AI readiness. The study assessed how confident organisations across the continent are in their data quality, visibility, and traceability. It also looked at how prepared they are to adopt and scale enterprise-wide AI initiatives.
The survey gathered insights from 140 senior IT, data, and cyber security leaders. These respondents worked at medium and large organisations across 14 African countries. Just under 70% of the participants were based in South Africa. The group represented a broad range of sectors, including financial services, retail, mining, telecommunications, media, and the public sector. They are the decision-makers responsible for IT, data, AI, and cyber security strategy.
Confidence Without Proof
While 52% of executives say they are very or extremely confident in their recovery capabilities, a further 33% are moderately confident. However, the data reveals a troubling pattern. 32% have either never performed a full technical recovery test, have not tested in more than a year, or do not know when their last test took place. Even among organisations that have completed an end-to-end recovery test, 45% reported only partial success, significant gaps, or outright failure.
Tahir Latif, data trust and governance lead for EMEA East at Veeam, notes that the study highlights a critical distinction. “The survey reveals that confidence is high, but confidence is not the same as capability. True data trust comes from proving that systems, processes and recovery strategies work when organisations need them most.” He warns that without regular, realistic testing, there is no guarantee that critical data can actually be restored. For organisations facing increasingly sophisticated ransomware, recovery needs to move beyond a theoretical capability and become a demonstrable one.
AI adoption is also fragmented across the region. About 36% of organisations are running approved AI tools in selected functions, while 27% remain at the pilot or experimentation stage. Just 14% have embedded AI into core business operations or autonomous workflows. At the same time, 11% of organisations report that employees are using unapproved public AI tools. This indicates that AI adoption is not always waiting for organisational approval.
The Governance Gap
This uncontrolled usage creates a growing data trust challenge. AI governance and data trust cannot be treated as something that follows adoption. They must develop alongside it. Organisations need to enable employees to use AI productively while ensuring that sensitive data, intellectual property, and business information are not being exposed through uncontrolled tools. Latif emphasizes that if organisations cannot reliably trace what happened to their data, it becomes difficult to establish data trust across the organisation.
Read Also: Suno trains v6 AI music with Warner BMG
Without trust in the data, there can be no trust in the outputs, decisions, and recommendations generated by AI systems. This is particularly concerning as AI becomes embedded in more business processes. The quality, security, and governance of the underlying data become increasingly important.
The main barriers to maintaining confidence in data are skills shortages (32%), inconsistent data classification (28%), budget constraints (27%), lack of visibility into critical data (26%), and legacy infrastructure (25%). Visibility is a particular weak point. Only 37% of respondents say they can produce an accurate audit trail across all critical systems covering the previous seven days. Just over half (55%) can do this only partially or across selected systems, while 8% cannot produce an audit trail or do not know whether they can.
Investment and Maturity Trends
The encouraging finding from the survey is that organisations appear to recognise the scale of the challenge. About 68% expect their budgets for data protection, cyber resilience, and AI governance to increase over the next 12 months. Backup and recovery (54%) top the investment priority list, followed by AI governance (42%), identity and access controls (41%), and data discovery and classification (36%). Latif says this suggests organisations are beginning to move beyond simply acquiring new technology. Instead, they are investing in the foundations required to build and maintain data trust at scale.
The research also points to differences in maturity depending on how organisations operate.
These findings suggest that scale, complexity, and exposure across multiple markets may be encouraging organisations to develop more mature approaches to data and technology governance.
To bridge the gap between perceived confidence and demonstrable capability, organisations must focus on building data trust through visibility, governance, resilience, and accountability. Latif concludes that only when leaders can trust their data can they confidently scale AI across the enterprise.
