Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: + –
5 minutes reading time (1095 words)
Featured

Your Backups Might Not Save You: What a New Ransomware Recovery Study Means for Small and Mid-Sized Businesses

A new field study of 800+ real-world ransomware recoveries found that only four organizations hit their 24-48 hour recovery target — and the reason usually wasn't missing backups, it was an untested, incomplete recovery plan.

If you run IT for a small or mid-sized business, you have probably been told for years that backups are your safety net. New data released this month suggests that safety net has a lot more holes in it than most leadership teams realize — and the gap has almost nothing to do with whether backups exist and everything to do with whether anyone has ever actually tried to use them under pressure.

The Study: 800 Recoveries, Almost None on Schedule

On September 15, 2026, cyber-incident recovery firm Fenix24 released its State of Recoverability 2026 report, drawn from data on more than 500 ransomware recoveries and 800 client engagements. The headline number is stark: only four of those 800-plus organizations came close to hitting a 24-48 hour recovery target, and even those only achieved partial restoration — none reached full operational capacity for weeks.

The report's other findings explain why:

  • •99.2% of organizations arrived at recovery with no documented plan for restoring their identity systems (the logins and directory services everything else depends on).
  • •94% had their backup infrastructure tied to the same Active Directory environment the attacker had already compromised — meaning the "safety net" was sitting inside the blast radius the whole time.
  • •95% lacked multifactor authentication on the consoles controlling their critical infrastructure.
  • •38% of backups that survived an attack still couldn't be used for recovery, due to corruption, incompatible formats, or immutability settings that worked against them instead of for them.
  • •82% ran into storage capacity shortages mid-recovery, and 0% had a complete map of how their applications depended on one another.

As Fenix24 co-founder and CEO Mark Grazman put it, the old question — "are we going to get attacked?" — is "the wrong question now, because every organization eventually faces an attack." The question that actually matters is whether you can prove, today, that you could recover.

Missed Recovery Targets

Why This Lands Hardest on Smaller Organizations

Large enterprises have dedicated disaster recovery teams and the budget to run full-scale restoration drills. Most SMBs don't and independent research backs up just how wide that gap is. The UK government's most recent Cyber Security Breaches Survey found that only 41% of small businesses had completed any kind of cyber risk assessment in the past year, and just 44% had a business continuity plan that even accounts for a cyber incident. Separately, threat-intelligence reviews published this month note that fewer than half of organizations across the board have tested a recovery plan in the last twelve months, and only about a third have a genuinely clean, isolated environment to recover into.

Put those two data sets together and the picture is uncomfortable: the businesses least equipped to survive an extended outage are, on average, the ones least likely to have rehearsed one. A ransomware incident that a well-prepared enterprise treats as a bad week can put an unprepared small business out of commission for a month and outages of that length are exactly what put companies out of business entirely.

The Compliance Angle: This Isn't Just Best Practice, It's the Requirement

For organizations operating under a regulatory framework, this study is a direct hit on core obligations, not just a security nice-to-have:

  • •NIST Cybersecurity Framework (CSF): The "Recover" function explicitly requires recovery planning, improvements, and communications not just backup existence, but demonstrated restoration capability.
  • •CIS Controls: Control 11 (Data Recovery) calls for automated, tested backups with defined recovery time objectives the exact discipline the Fenix24 data shows most organizations lack.
  • •HIPAA: The Security Rule's contingency planning requirements (45 CFR §164.308(a)(7)) obligate covered entities and business associates to maintain, and test, data backup, disaster recovery, and emergency-mode operation plans.
  • •CMMC: Recovery and incident response practices sit inside multiple domains of the framework, and auditors increasingly expect evidence of tested recovery, not a plan document that has never left the shelf.
  • •FERPA: Schools and edtech vendors handling student records face the same underlying expectation that data can actually be restored, not merely stored redundantly.

An auditor or regulator asking "can you produce your last recovery test results" is now a completely reasonable question and for most organizations, based on this data, the honest answer is "we don't have any."

What SMBs Should Actually Do This Quarter 

None of this requires an enterprise budget. It requires treating recovery as something you verify, not something you assume. A few concrete starting points:

  • 1.Isolate backup infrastructure from production identity. If your backup system authenticates through the same Active Directory an attacker could compromise, your backups are not as separate as they feel.
  • 2.Put MFA on every console that controls critical infrastructure backup consoles, hypervisors, network gear not just user email and VPN logins.
  • 3.Map your application dependencies before an incident forces you to do it live. Knowing that your billing system depends on a database that depends on an identity service that depends on a domain controller is the difference between a two-day recovery and a two-week one.
  • 4.Run an actual restore test, on a schedule. Not a checklist review an end-to-end simulation that restores real systems and measures real time against your stated recovery objective.
Document (and rehearse) identity recovery specifically. Given that 99.2% of studied organizations had no plan for this single point, it is very likely the biggest blind spot in most environments right now.
Information System Backup Checklist

The Bottom Line 

Ransomware defenses get most of the attention and most of the budget, firewalls, endpoint detection, employee training. All of that matters. But this month's data is a reminder that prevention eventually fails somewhere, for someone, and when it does, recovery speed is what determines whether a business absorbs the hit or doesn't survive it. For SMBs juggling limited IT staff and tight budgets, a recovery plan that has never been tested is functionally the same as no plan at all.

If it has been more than a year since your organization ran a real restoration test, or if you're not sure your backups are actually isolated from the systems most likely to be compromised, that's worth a conversation before an incident forces the issue.

Related Resources

 Fenix24 Releases The State of Recoverability 2026, Finding 99.2% of Organizations Have No Documented Plan to Recover Identity Systems After an Attack. PR Newswire, September 15, 2026

The First AI-Agent Data Breach Is Here: What Spain...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024