Only 4 of 800+ Clients Came Close to Their Ransomware Recovery Targets

Fenix24 ransomware cyber resilience https://www.pexels.com/photo/antelope-canyon-illustration-1533505/

Disaster recovery company Fenix24 recently released a report, “The State of Recoverability 2026,” exploring the resilience of organizations against ransomware threats through how well they meet ransomware recovery targets. Examining engagements with more than 800 clients, the report reveals the gaps between security and true resilience. When clients document recovery targets, they usually aim for 24-48 hours, but only four of those examined in the report came close to this goal. None of the client organizations were able to hit full operational capacity for several weeks. According to the “Redefining Cyber Resilience” survey from Accenture, 81% of executives assume that critical downtime after an incident will be 10 days of less, while actual recovery averages 3-6 months.

Plans Built for Natural Disasters

The Fenix24 report points out that disaster recovery broadly assumes that the environment outside of the event is honest and the loss stems from an event like a flood or earthquake causing system failure. Ransomware is a cyber incident that challenges that fundamental assumption and creates difficulties for traditional disaster recovery. In ransomware attacks, 65% of initial access is identity-based, and Active Directory is typically the first major system to be compromised in these events.

According to field data from Fenix24, 99.2% of clients have no documented plan for identity recovery, and none of the plans in place for the remaining 0.8% survived actual contact with the attacker. A staggering 95% lack meaningful multifactor authentication (MFA) on critical infrastructure consoles. Conversely, only 15% fail to implement effective controls at network perimeter entry.

Surviving Backups Still Fail

Even when organizations have backups in place, it does not guarantee safety or recovery: 94% of clients run backups that are joined to the very directory that is first compromised by the attacker. Attackers often take steps to destroy the path to restoration in order to turn an IT incident into an opportunity for extortion. “Recovery can depend on the same login system an attacker has compromised,” says Jason Soroko, Senior Fellow at Sectigo, a Scottsdale, Arizona-based provider of comprehensive certificate lifecycle management (CLM). “These figures describe Fenix24’s engagements, not every business, but they identify a failure organizations should test for. Teams need a way to restore identity systems without first requiring those systems to be working.”

Of the incidents in which backups survive the attack intact, 38% were still unable to carry out recovery efforts. These backups are often outdated, incomplete, or corrupted prior to the attack, or else they are too slow for effective recovery or the wrong type of data. These statistics underscore the vital distinction between the existence, survivability, and usability of data backups as three separate properties that each matter in their own way.

Supply Chain Maps Lacking Visibility

Of the clients analyzed for the report, not a single one was able to recover with a complete map of its applications and dependencies. The pace of recovery is consistently set by whichever link in the chain is slowest, blocking or stalling recovery efforts. Some of the most common impeding factors are storage shortages, found in 82% of engagements, and thin bandwidth, found in 38%.

According to the Identity Theft Resource Center, third parties are now involved in around 30% of breaches, doubling the figure from 2021. A report from Allianz states that contingent business interruption supply chain events more than doubled between 2024 and 2025, from making up 6% of large cyber claims to 15%. The increasingly sprawling and interconnected webs of supply chains present significant risk via a vector that is almost always less visible and less monitored than it should be.

Downtime Exacerbates Costs

Based on data from cyber insurance providers, the majority of the value of large claims comes down to business interruption. The average cost of claims with a component of business interruption is 650% higher than those without. Numbers from the FBI’s Internet Crime Complaint Center place reported ransomware losses at $32 million; when compared with the Cyentia Institute’s ransomware loss estimate of $95 billion, this highlights how much operational downtime goes uncounted and unaccounted for. A cyber insurance policy can only help make up financial losses—it cannot provide the capability to prevent or meaningfully recover data losses.

Insurance Market Trends and Board Engagement

Data from the National Association of Insurance Commissioners reveals that cyber claims increased by nearly 40% in 2024, while average premium rates declined by 5% in the same time period. Regulators are shifting their focus from requiring that organizations have a plan filed for recovery to asking them to prove that their restoration plan will work.

The Fenix24 report also draws attention to increased board involvement in security efforts. The World Economic Forum’s Global Cybersecurity Outlook 2026 report reveals that 99% of highly resilient organizations show board-level cybersecurity engagement. Boards are now asking not whether the organization is secure, but how long business would be down in the event of a security incident. Organizations’ self-reporting shows that 64% are meeting minimum requirements for resilience and 19% are exceeding them.

Measuring What Survives

This report emphasizes the vital importance of prioritizing recovery capability. Decades of strategy and instrumentation has been built to protect against attacks, to keep threat actors out, with comparatively very little put into recovery. The new standard demands both continuous measurement of restoration capability and execution of recovery.

The report outlines ten recurring factors that consistently block recovery, all of which are knowable prior to the incident occurring. Paying attention to and managing these potential hindrances is key to ensuring sufficient recovery is possible. Organizations should be able to run the full restore end to end at least once annually to stand up to both audits and attacks.

Author
  • Contributing Writer, Security Buzz
    PJ Bradley is a writer from southeast Michigan with a Bachelor's degree in history from Oakland University. She has a background in school-age care and experience tutoring college history students.