• 3 minuti
  • Pubblicato

Ransomware recovery targets collapse for nearly all companies

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Ransomware recovery targets collapse for nearly all companies QWERTYmag © www.qwertymag.it
Ransomware recovery targets collapse for nearly all companies © www.qwertymag.it

Fenix24's new report reveals that almost every company fails to meet its own ransomware recovery targets, with identity management and backup systems routinely sabotaging efforts to restore operations within days.

When ransomware hits, most companies are offline for weeks, not days. According to Fenix24's latest State of Recoverability report, out of more than 800 organizations attacked, only four came close to meeting their own 24 to 48-hour recovery goals. None managed to return to full capacity in less than several weeks.

  • Identity management sabotages recovery

    The main obstacle is identity. Fenix24 found that 99.2% of organizations had no documented plan for recovering identity systems. Even the few that did saw those plans fail as soon as attackers got inside. Active Directory, which handles authentication for most businesses, was usually the first thing to break. In 94% of cases, backup systems were directly connected to the same compromised directory, turning backups into another point of failure. Nearly 20% of the first 48 hours after an attack was spent just trying to clean up authentication sources enough to use them again. It often took another three days before companies could start rebuilding the basic infrastructure needed to operate.

  • Backups fail when needed most

    Even when backups survived, they rarely worked as intended. In 38% of cases with intact backups, companies still couldn't restore operations. Some backups were outdated, others were corrupted or incomplete, and many were stored in formats that took longer to restore than rebuilding from scratch. So-called "immutable" backups often sat on hardware that didn't live up to the name. No company had a complete, current map of its application dependencies; most had to improvise during the crisis, deciding which systems to restore first as they went. Storage shortages affected 82% of organizations, forcing tough choices between restoring data and preserving forensic evidence. In over a third of cases, network capacity couldn't handle the volume of data needed for recovery.

  • The Fenix24 report highlights that backup availability does not guarantee recoverability: in 38% of cases, even intact backups could not be used to restore business operations, often due to authentication failures or dependency mapping gaps. - Fenix24, Cybersecurity Vendor (source)
  • Simulations and dependency mapping are not optional

    Fenix24's advice is direct: organizations need to identify their most critical service, create a full dependency map-including third parties-and run real-world restore drills against current targets. Untested plans and paper exercises don't prepare teams for the confusion of an actual attack. This lesson matches recent incidents, such as those reported elsewhere, where attackers took advantage of overlooked weaknesses.

    Despite all the talk about resilience, most companies are still unprepared. Identity systems and backup strategies that look solid on paper often fail under real pressure, leaving businesses offline for weeks. Until organizations treat recovery as a live-fire exercise-testing every assumption, mapping every dependency, and refusing to trust unproven plans-ransomware will keep setting the terms. The era of theoretical recoverability is over; only those who prepare for the worst in practice will avoid becoming the next cautionary tale.

    Italian organizations should also review the latest ACN guidelines on backup and recovery, which stress the need to isolate identity systems and regularly test restore procedures, in line with Fenix24's findings.

  • Articoli correlati