A stressed operations team monitors global alerts and cybersecurity dashboards in a dim control room.
Object First’s September 22, 2026 survey reports that 91% of 1,100 IT and security professionals across the United States, United Kingdom and Germany feel uncomfortably stressed over security risks, putting staffing, recovery complexity and confidence in incident response on the agenda for IT managers. The headline figure is higher than the company’s 2025 result, although an expanded international sample complicates a straight year-over-year comparison. More immediately useful for employers is the combination of pressures respondents describe: fear of attacks, stretched teams, demanding uptime expectations and recovery tools that require specialist expertise.

TechRadar’s reporting on the new findings adds an important operational detail: workloads and understaffing rank alongside cyberattack risk as leading sources of stress. That makes this a story about how organizations resource and run IT, as well as how they defend it. The evidence supports reviewing those working conditions; it provides considerably less justification for treating a storage purchase as the answer.

Object First’s 91% stress figure needs its sample attached​

The September announcement describes a survey of 1,100 IT and security professionals in three countries. That is a narrower population than the broad term “workers” used in TechRadar’s coverage: the findings concern people whose professional responsibilities put them close to technology and security risk. They should not be generalized to the entire workforce.

Object First’s October 1, 2025 announcement reported that 84% of 500 U.S. IT and security workers felt uncomfortably stressed at work because of security risks. Its published methodology identified Dynata as the survey provider and included respondents from entry-level through executive positions at companies of all sizes.

The difference between 84% and 91% is seven percentage points. But the geographic coverage and sample size changed, so the headline increase is not a clean like-for-like trend. Establishing that would require comparable results for the same populations, or methodological information showing how the samples were made comparable.

This changes the appropriate conclusion. The surveys provide evidence that reported stress is widespread among their respondents in both years. The aggregate figures alone cannot tell a U.S. IT director that stress among comparable American professionals rose by precisely seven percentage points.

The sponsor also belongs in the interpretation. Object First sells backup-storage products, including appliances built for Veeam users, and has a commercial interest in recovery-related concerns. Its survey remains useful evidence of respondents’ experiences, but their preferences and perceptions should be kept separate from proof that a particular product improves mental health or operational outcomes.

AI anxiety shares the stage with understaffing and uptime​

According to TechRadar’s September 22 reporting, 90% of respondents said AI tools had improved their productivity, while 70% identified growing AI-powered threats as a key source of stress. Only 24% believed their organization was suitably equipped to handle those threats.

Those answers describe two different experiences that can coexist. Someone can find AI useful in their own work while worrying about its use by attackers. The productivity result therefore offers no reason to dismiss the security concern, and the security concern offers no basis for concluding that respondents want to abandon AI tools.

The broader stress findings make an AI-only explanation especially unhelpful:

Reported source of stressShare of respondents
Risk of cyberattacks50%
High workloads and understaffing50%
Pressure to maintain uptime44%
Gaps in backup and recovery effectiveness41%

These figures, reported by TechRadar, put organizational capacity alongside technical threats. They should be read as separate reported concerns, not added together into a single measure of stress.

For an IT manager, the practical inference is that an AI-security discussion should include staffing and service expectations. A team that identifies workload as a major pressure needs a workload decision—such as which responsibilities take priority—not simply another explanation of emerging attacks.

Likewise, the 24% preparedness figure measures respondents’ confidence in their organizations. It is not an audit of security controls or a measurement of how many organizations would successfully resist an AI-assisted attack. Its immediate value is as a prompt to investigate why staff lack confidence: the survey’s other responses suggest that capacity, usability and recovery expectations deserve attention alongside prevention.

Recovery-tool complexity turns resilience into a staffing question​

TechRadar reports that 74% of respondents found recovery tools difficult to use without security expertise. The same percentage appeared in Object First’s 2025 survey, where respondents said their data-recovery tools were too complex to use without that expertise.

Because these are IT and security respondents, the finding deserves a more precise interpretation than “ordinary employees cannot restore their data.” It points to a perceived expertise requirement within the professional teams themselves. It does not establish that all recovery products are difficult, or that every respondent has personally failed a restoration.

That distinction matters when deciding what to improve. The relevant management question is whether the people expected to perform recovery have the knowledge, authority and support required for their assigned responsibilities. Simplifying an interface may help with one part of that problem; identifying who can carry out the work addresses another.

A reasonable operational response is to review the handoff between security specialists and the administrators responsible for service restoration. Managers can ask staff to identify the recovery tasks they feel equipped to perform and those that depend on another person’s expertise. That is a management recommendation drawn from the findings, not a tested intervention reported by the survey.

The 2025 results offer useful context for purchasing decisions. In that survey, 67% believed faster, higher-performing backup solutions that minimized downtime would improve productivity and confidence. Another 67% said independently tested technology would enhance productivity and confidence in recovery. These are preferences worth investigating during evaluation, rather than measured evidence that buying faster storage reduces stress.

The procurement implication is to translate “easier recovery” into the actual responsibilities of the intended operators. A proposed solution should be assessed against the work the organization needs its staff to accomplish, rather than treating a vendor’s general promise of simplicity as an operational result.

Reported performance problems make employee support an IT concern​

The consequences extend beyond discomfort. TechRadar reports that 78% of respondents said stress had negatively affected their job performance, 39% had considered quitting, and 19% felt hopeless and overwhelmed during or after an incident.

These are self-reported experiences and intentions. They are not measurements of productivity loss, actual departures or clinical diagnoses. Even within that boundary, they give employers a concrete reason to include staff experience in discussions about incident readiness and recovery.

Object First’s 2025 survey provides a related warning about accountability. It found that 78% feared being personally blamed for security incidents, while 47% felt pressure from leadership to “fix everything” afterward. Those are previous-year findings, not additional results from the September 2026 sample.

For managers, a useful inference is to make expectations explicit before an incident. Clarifying who makes recovery decisions, who performs the work and who communicates with leadership can expose responsibilities that have otherwise accumulated around a single individual. The survey does not quantify the benefit of that approach, but its findings identify the pressures such a review should examine.

Employee support also deserves its own attention. In 2025, half of respondents said their companies did not consistently prioritize employee well-being and mental health. Respondents identified employee assistance programs, flexible schedules, comprehensive benefits, mental-health support and paid time off as valuable resources when available. That is a broader set of needs than a technology replacement can address.

IT managers should review recovery expectations before adding another tool​

Start by asking the people responsible for incident response which demands they cannot reliably meet with their current time, staffing and expertise. That produces a more actionable discussion than asking whether the organization’s stress level matches a vendor-sponsored international average.

The survey suggests several concrete priorities:

  • Treat the 91% figure as a finding about surveyed IT and security professionals, not all employees or a diagnosis of your own workforce.
  • Keep the change from a U.S.-only sample to a three-country sample visible when presenting the seven-percentage-point increase.
  • Discuss workload and staffing alongside attack risk, because both were reported as leading sources of stress by 50% of respondents.
  • Review which recovery responsibilities depend on specialist expertise, and whether the staff assigned those responsibilities feel equipped to carry them out.
  • Evaluate proposed backup investments against specific recovery difficulties without assuming that a product purchase will resolve workload, accountability or well-being concerns.

The strongest decision supported by Object First’s findings is to bring the people doing recovery into the resilience discussion early. Their reported difficulties identify where leadership can investigate: excessive workload, unclear expectations, specialist dependencies and limited confidence in preparedness. Addressing those conditions gives an organization a more concrete starting point than either an alarming survey headline or a promise that stronger storage alone will relieve the pressure.