Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

AI can help attackers scale or accelerate parts of cyber activity, but current evidence does not show that every attack now moves at “machine speed” or that most organizations have inadequate recovery plans. The practical response is to make recovery a tested operational capability: know who activates it, how affected systems are isolated, which clean copies can be restored, and what must come back online first.

What the latest breach figure does—and doesn’t—show

IBM’s 2026 Cost of a Data Breach study reported that one in four malicious breaches in its study were AI-enabled, with an average cost of $6 million for those breaches. Ponemon Institute conducted the study, which IBM sponsored and analyzed. Its evidence window ran from March 2025 through February 2026 and covered breaches experienced by 602 organizations globally. These are study findings, not a census or universal rate for all organizations or cyberattacks. IBM’s study announcement

The finding is a reason to account for AI-enabled activity in risk planning, not proof that all attackers operate at machine speed. The sources do not provide a universal, apples-to-apples measure of attacker action time versus organizational recovery time. Nor do they establish what share of organizations have untested or inadequate recovery plans. IBM vice president Suja Viswesan said, “The priority now is to eliminate that lag—building remediation into development workflows, securing identity at runtime, and fixing risks at the speed attackers are already moving.” That is an executive’s view, not an independent standard or regulator finding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use current guidance to assess ransomware readiness

NIST published its final Ransomware Risk Management profile, IR 8374r1, on June 11, 2026. It is intended to help organizations assess defenses and prioritize resilience improvements, making it a useful current anchor for ransomware risk management and recovery planning.

Recovery is more than prevention or detection. A plan needs to describe how the organization will restore operations after disruption, and how that work connects to incident response. Use the profile to identify gaps and prioritize actions rather than treating a completed assessment as proof that recovery will work.

#1 Best Overall
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

Build a recovery plan around operational decisions

Write down the decisions and dependencies responders will face during an incident. The plan should be usable by the people responsible for security, IT operations, continuity, communications, and affected business or production functions.

  1. Set activation and authority. Name who can initiate recovery, who can authorize isolation or restoration decisions, and how recovery relates to the incident-response process.
  2. Contain affected systems. Define how responders will isolate impacted systems and coordinate that work with teams responsible for business operations. Avoid restoring a system before responders have assessed whether it is safe to reconnect.
  3. Choose and restore clean copies. Identify backup copies and the process for determining whether they are suitable for restoration. Copies that can be disconnected from the network can reduce exposure to network-level compromise, but separation alone does not establish that a copy is clean, protected, or restorable. IBM describes hard drives and other devices that IT can disconnect from the network as examples of backup and disaster-recovery copies in its ransomware guidance.
  4. Set restoration order. Document which systems and dependencies must be recovered first, who validates them, and how the organization will resume operations. Include communications and business dependencies in the sequence, not just technical infrastructure.
  5. Test the procedures. Exercise the restore process so teams can find gaps in access, dependencies, decision-making, and recovery steps before an incident. A backup is useful only if the organization can restore from it in the conditions its plan assumes.

Account for AI systems and operational technology

Restoring an AI-enabled system may involve dependencies beyond its application or model, so identify what the system relies on and what restoration entails. NIST’s Cybersecurity Framework Profile for Artificial Intelligence is an initial public draft; it discusses additional considerations for AI-related recovery, but should not be presented as final normative guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
SecuX PUFido® Drive Clife Key USB C Security Key with PUF Technology and Built in Flash Drive, FIDO2 U2F Certified Hardware Rooted Unclonable Security for Passwordless Login and 2FA Authentication (1)
  • Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
  • FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
  • Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
  • Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
  • Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.

For manufacturing and other operational technology environments, recovery choices can affect production and safety as well as information systems. Connect restoration decisions to operational and safety responsibilities. NIST’s SP 1800-41 manufacturing-sector practice guide is also an initial public draft, rather than established final guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Recovery-readiness checklist

  • A named person or role can activate recovery and coordinate it with incident response.
  • Responders know how to isolate affected systems and who approves restoration and reconnection.
  • Recovery copies, including any disconnected copies, are protected and their restore process is tested.
  • The plan identifies restoration order, system dependencies, validation responsibilities, and communications needs.
  • AI-system dependencies and operational or safety consequences are included where relevant.
  • Exercises test the actual recovery procedures and expose gaps that can be assigned and prioritized.

If the recovery design calls for disconnected backup media, an external hard drive may be one component; the choice depends on the organization’s recovery requirements and procedures. A drive by itself does not provide enterprise-grade resilience or prove recoverability.

Rank #4
Thetis Pro FIDO2 Security Key Passkey with Complex Pin [PinPlex], Hardware Device Supports USB A, Type C &NFC, TOTP/HOTP Authenticator APP, PIV Certificates, FIDO 2.0 Two Factor Authentication 2FA MFA
  • Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
  • NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
  • FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
  • Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
  • Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.
Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.