{
  "id": 492658,
  "title": "Why recovery readiness has become the new standard for cyber resilience",
  "url": "https://urgent.news/2026/08/10/why-recovery-readiness-has-become-the-new-standard-for-cyber",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-10T18:56:00.000Z",
  "source": {
    "name": "ZDNet",
    "slug": "zdnet",
    "url": "https://www.zdnet.com/article/why-recovery-readiness-has-become-the-new-standard-for-cyber-resilience/"
  },
  "original_language": "en",
  "account": "Recent ransomware reports indicate that over 90% of attacks now attempt to delete or alter backups before deploying the ransomware payload, and nearly 60% of these attacks succeed in compromising backups. Outages are no longer mere IT concerns; they pose a significant risk to the entire enterprise. Prolonged recovery times lead to disrupted business processes, decreased productivity, and potential permanent loss of customers.\n\nA common misconception among organizations is that backup is synonymous with recovery. Research shows that 94% of surveyed SMB leaders believed their enterprise would survive a disaster, yet only a quarter had the necessary recovery infrastructure in place. The distinction between backup and recovery is crucial. Backups create duplicate copies of data, while recovery ensures that when a ransomware attack occurs or a system fails, the organization can quickly restore operations to prevent extended downtime, financial losses, and damage to customer trust.\n\nAttackers exploit this flawed assumption, often tampering with backups before breaching the rest of the IT system. Many threat groups target backups first before attacking other parts of the IT infrastructure. Modern resilience strategies require implementing secure, immutable backups combined with rapid recovery capabilities.\n\nHybrid environments, where on-prem hardware is integrated with cloud resources, have become the norm due to increasing on-prem acquisition costs. Attackers can now bypass traditional defenses by gaining access to business applications through compromised cloud identities, bypassing multi-factor authentication (MFA), hijacking live sessions, and exploiting email security vulnerabilities. Ransomware attacks now frequently begin with identity-based methods, often targeting backup repositories before striking other systems.\n\nCloud service providers, such as Microsoft and Google, operate under a Shared Responsibility Model, meaning they maintain service availability while entrusting customers to protect their data. However, built-in features like recycle bins, version history, and retention policies are primarily designed for uptime and do not guarantee recovery from ransomware or accidental data deletions. Attackers capitalize on this lack of additional recovery safeguards.\n\nMany organizations rely on a fragmented defense approach, employing a mix of native and standalone solutions to extend Recovery Time Objectives (RTO). Only 1 in 5 organizations report unified backup protection across hybrid environments, according to a Redmond/Kaseya survey of 200 IT professionals. Preparation is essential. While backup jobs may report success, they may fail to restore applications, virtual machines (VMs), or encrypted data. Tools like Datto's Screenshot Verification can anticipate these issues by verifying that systems can boot automatically after each backup, providing visual proof of success.\n\nBeyond merely copying files for backup, organizations must consider identity layers, such as email accounts, to ensure that recovery processes are not hampered. When large-scale software or cloud infrastructure is compromised, rebuilding a clean version is often more feasible than salvaging the existing one. Leading Managed Service Providers (MSPs) are adopting immutable, isolated backups with independent credentials and rehearsed recovery plans to mitigate these risks.\n\nThe consequences of inadequate recovery planning are severe, leading to lost trust, revenue, and extended downtime during critical moments. Cyber liability insurance has become more challenging to obtain and imposes stricter requirements, including accurate representation of Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs). Regulatory frameworks such as CMMC, GDPR, NIS2, and DORA emphasize resilience as a mandatory obligation, rather than a best practice.\n\nTo assess your organization's resilience, consider using a low-commitment checklist to evaluate your readiness. If you are prepared to explore recovery readiness in practice, consider utilizing tools that provide independent, automated recovery across platforms like Microsoft 365 and other systems.",
  "summary": "As outages become more expensive and frequent, recovery readiness is emerging as the true measure of resilience.",
  "key_points": [
    "Over 90% of ransomware attacks attempt to delete or alter backups.",
    "Nearly 60% of these attacks successfully compromise backups.",
    "Only 1 in 5 organizations have unified backup protection across hybrid environments."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}