Boards should ask when a critical service was last restored using the people, access, and infrastructure likely to remain available after an attack. The answer should include what failed and how long the business would have been unable to operate.
Without that evidence, a recovery target is an estimate that may already be shaping decisions as though it were a guarantee.
Object First and Omdia surveyed 700 leaders and found that just 39% of organizations recovered at least three-quarters of their affected data, compared with 57% in its 2024 research. For most respondents, the damage also exceeded what they had planned for: 76% lost more data than their recovery targets allowed, and 64% took longer to restore operations than expected (Object First and Omdia, 2026). If management believes systems can return within a few hours, it plans around a few hours of disruption. Suppliers, customers, and employees absorb the consequences when that estimate proves a bit too optimistic.
Backup coverage can look reassuring while concealing dependencies that leave recovery exposed to the same attack as production. Compromised credentials may give attackers access to backup repositories; taking down shared infrastructure may also disable the tools needed to restore them. In Object First’s commissioned research, 93% of technology leaders wanted backup storage that would remain protected even if credentials were compromised, but only 16% said their current storage met that requirement. The gap suggests that much of the confidence placed in backups still rests on the security of the environment they are supposed to help recover.
Even when backups remain usable, restoring operations can be very costly. Sophos’ 2026 study of 2,158 respondents across 17 countries found that attackers encrypted data in 56% of ransomware incidents. Among organizations affected by encryption, 66% used backups to recover data, up from 54% the previous year. Yet average recovery costs rose 11% to $1.7 million, excluding ransom payments (Sophos, 2026). So, the wider use of backups does not necessarily translate into a less disruptive recovery. Teams still have to determine which data predates the compromise, validate systems, and restore the services other applications depend on. Each unresolved dependency can prolong the outage, even after the underlying data has been recovered.
Ransomware appeared in 48% of breaches analyzed in Verizon’s 2026 DBIR. Exploiting software vulnerabilities was the leading route in, accounting for 31% of initial access, while generative AI supported 15% of observed attack techniques. These findings do not explain why recovery is falling short, but they underline how much businesses are asking their recovery arrangements to withstand (Verizon, 2026). Ransomware crews have more ways into the network and more ways to accelerate reconnaissance once they arrive.
Organizations must understand how much clean data can the organization restore, how quickly critical services can return, and how much of that process has been tested under realistic conditions. A recovery plan written for an audit gives limited comfort when production systems are down at 3 a.m. Even though plenty of companies have backups, far fewer seem able to recover most of their data when an attacker tests those backups.