www.infosecurity-magazine.com 15 Sept 2026, 14:30 UTC

Most Firms Missed Their Ransomware Recovery Targets, Report Finds

Most Firms Missed Their Ransomware Recovery Targets, Report Finds
CyberSIXT Evidence Panel Source marked as original reporting

ONLY four of more than 800 organisations assessed by incident response firm Fenix24 came close to meeting their own 24- to 48-hour ransomware recovery targets, and only for part of their operations. None regained full operational capacity until several weeks after the incident. The findings come from Fenix24’s first State of Recoverability report, published on 15 September 2026 and based on more than 500 ransomware recoveries. The company said recovery plans often appeared sound on paper but failed after attackers gained access.

Identity systems were a major obstacle. Fenix24 reported that 99.2% of clients had no documented identity recovery plan, while 94% had connected their backup systems to Active Directory, which was usually among the first major systems compromised. Around 20% of the first two days was spent restoring a trusted authentication source, followed by at least another 72 hours to establish minimum viable infrastructure.

The report also found that 95% lacked meaningful multifactor authentication on critical infrastructure consoles, compared with 15% at network ingress. Sectigo’s Jason Soroko cautioned that the figures reflect Fenix24’s engagements rather than all businesses.

Backups also frequently failed to support recovery. In 38% of cases where backups survived intact or nearly intact, they were unusable because they were outdated, corrupt, incomplete, in the wrong format or too slow to restore. Fenix24 said 82% of engagements faced insufficient storage, while 38% lacked network capacity to move data at recovery scale.

It recommended mapping dependencies for the most revenue-critical service, including third parties, and testing the complete restoration process against current recovery targets.

View full article

Article by CyberSIXT