• 4 minuti
  • Pubblicato

Ransomware recovery plans fail to restore business operations

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Ransomware recovery plans fail to restore business operations QWERTYmag © www.qwertymag.it
Ransomware recovery plans fail to restore business operations © www.qwertymag.it

A Fenix24 report reveals that most organizations hit by ransomware cannot fully recover operations even if they refuse to pay, exposing critical gaps in identity and infrastructure recovery planning.

Most organizations hit by ransomware struggle to restore even partial business operations, according to new data from Fenix24. The idea that refusing to pay a ransom leads to a quick recovery does not hold up: out of 800 cases analyzed, only four managed partial recovery. The rest remain stuck with broken systems and compromised identities.

For years, law enforcement and cybersecurity experts have advised against paying ransoms. The reasoning is straightforward-there is no guarantee hackers will keep their word, and paying encourages more attacks. But the Fenix24 State of Recoverability report shows that even organizations that refuse to pay face a harsh reality: backups alone are not enough to bring business back online.

Identity recovery is often overlooked

Modern ransomware attacks go beyond encrypting files. Attackers now target administrator accounts, disrupt authentication systems, and damage the core infrastructure organizations need to function. Fenix24 found that 99.2% of its clients lacked a documented identity recovery plan, leaving them unable to regain control over user accounts and digital assets. This gap turns recovery into a long, difficult process. About 20% of the first 48 hours after an attack are spent just re-establishing a single trusted authentication point, showing that identity infrastructure is often the main obstacle, not file restoration.

Restoring files from backups is only the beginning. Without a clear process for recovering identities, credentials, and access controls, organizations can be locked out of their own systems. This leads to a prolonged crisis that can overwhelm even experienced IT teams. The latest guidance from the Agenzia per la Cybersicurezza Nazionale (ACN) recommends restoring identity, admin access, and management systems before bringing user-facing services back online, in line with best practices across the EU.

Industry data from 2026 shows a worsening trend: only 39% of ransomware victims were able to recover at least 75% of their data after an incident, compared to 57% the previous year. This decline underscores the growing complexity of attacks and the inadequacy of traditional backup strategies.
DatacenterNews Asia, Industry Analysis (source)

Negotiation rarely leads to full recovery

Some organizations try to negotiate with ransomware groups or obtain decryption tools, hoping for a quick fix. The Fenix24 report shows this rarely works. Even when decryption keys are provided, the underlying infrastructure is often still damaged, credentials remain compromised, and there is no guarantee attackers have not kept copies of sensitive data. Recovery drags on, and business continuity remains at risk.

Recent cases, such as those reported earlier, show that ransomware is now about more than just encrypted files. Attackers combine data theft, credential compromise, and infrastructure sabotage to maximize their leverage and the damage done.

Backup strategies alone fall short

Fenix24's findings reveal a dangerous gap in how organizations prepare for ransomware. Many rely on backup strategies that are not isolated or regularly tested. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and European regulators like ACN now recommend keeping offline, regularly tested backups of critical data and verifying their integrity and accessibility. This is essential, but as Fenix24's data shows, it is not enough without a tested, end-to-end recovery process for identity and infrastructure. For more details, see the ACN backup guidelines.

Even when data can be restored, the lack of a comprehensive recovery plan for applications, infrastructure, and business processes can leave organizations unable to resume normal operations. The latest SpyCloud Identity Threat Report 2026 notes that identity recovery is now a distinct area of industry focus, with maturity measured by detection, remediation, and governance of identity risks.

Ransomware now tests the real strength of disaster recovery plans. Organizations need to move past the belief that backups alone will save them. Regular testing, isolation of backup systems, and detailed recovery procedures for every layer of the digital environment are now essential. Best practices also require that recovery only begins after confirming the attack vector is closed and that the same administrative setup exploited by attackers is not reintroduced during restoration.

The evidence is clear: simple ransomware responses are no longer enough. Organizations that do not invest in full recovery planning-including data, identities, credentials, and infrastructure-are taking a major risk. The Fenix24 report is a warning for any business that still relies on outdated recovery strategies. In today's threat environment, operational resilience is not just a formality-it can be the difference between a temporary setback and a business-ending event.

Articoli correlati