
The latest research from Fenix24, their first-ever State of Recoverability Report, offers insight on how recovery plans often look solid on paper, but fall apart when facing a genuine attack. Companies often plan around encryption and ransom demands, but the recoveries themselves are decided by things nobody accounted for, such as compromised identity systems and backups that technically survived but are unable to perform a full restoration.
The gap between the recovery plan and what recovery requires is where companies lose weeks. Some examples from the report show:
- Only 4 of 800+ engagements came close to companies' own 24–48-hour recovery targets, with none hitting full operational capacity for weeks.
- 99.2 percent had no documented plan to recover identity systems, and the few plans that existed didn't survive contact with the attacker.
- 95 percent reported no meaningful MFA on infrastructure consoles, vs. 15 percent lacking it at the network perimeter, highlighting that the front door is guarded, the house is not.
- 38 percent of "surviving" backups still couldn't carry a recovery.
Boards, insurers, and regulators are all realizing that "we have a plan" is no longer enough. Insurers are pricing recovery posture directly into premiums. Regulators are starting to require proof of tested recovery, not filed plans. Boards have shifted from asking "are we secure" to "how long would we be down."
Fenix24's report argues that the industry has spent 20 years focusing on what can be attacked, and none for what survives. Industry stakeholders offered their thoughts on these findings.
Jason Soroko, Senior Fellow at Sectigo
"Fenix24’s finding that 94 percent of its clients ran backup systems joined to their production directory deserves attention. Recovery can depend on the same login system an attacker has compromised. These figures describe Fenix24’s engagements, not every business, but they identify a failure organizations should test for.
"Teams need a way to restore identity systems without first requiring those systems to be working. Microsoft’s recovery guidance documents dependencies that can prevent this. They also need to verify that restoring systems and accounts will not give the attacker access again.
"Security teams should work with IT and business owners to rehearse recovery with normal login services unavailable or untrusted. Separate backup administration from production accounts and require multifactor authentication on infrastructure consoles.
"Keep recovery instructions and emergency credentials securely accessible outside the systems being restored. Map the systems needed to deliver one essential business service, including outside providers, then restore that service in an isolated test environment. Measure the storage, bandwidth and time required. Have staff demonstrate that they can process an order or run payroll.
"Boards should receive those tested recovery times, the level of service restored and the obstacles still unresolved."
Matthieu Chan Tsin, SVP and GM at Cowbell Resiliency Services
"The organizations that actually hold up under pressure aren't the ones with the most tools or the biggest budgets — they're the ones that continuously test their assumptions, know what 'normal' looks like well enough to spot when something's off, and have practiced the bad day before it happens.
"That means reframing resilience conversations around exposure and recovery, not just prevention: assume something will get through, and make sure you can detect it fast, contain it, and keep the business running while you clean up. It also means giving technical debt and third-party risk the same ongoing attention you give new threats, instead of episodic cleanup projects.
"Resilience isn't a checkbox you clear once leadership signs off — to be effective, it must be an ongoing set of behaviors."
Shane Barney, CISO at Keeper Security
"Backups are no longer isolated infrastructure. They are administered through the same identity systems that govern the rest of the environment, which means if an attacker compromises a privileged identity, access to the backup console often follows.
"The issue is not that backups are suddenly vulnerable – it’s that they now sit behind identity controls, and identity compromise is increasingly common. That shifts backups from being purely a recovery mechanism to another system that must be governed carefully.
"Backup systems have been targeted for years, but what has changed is how attackers reach them. Instead of exploiting software vulnerabilities, many have shifted to using stolen credentials obtained through phishing scams, token theft, or social engineering.
"When access is achieved through valid identities, the activity blends in. From the platform’s perspective, the threat actor appears to be an administrator making configuration changes. That’s the real shift. Identity has become the access layer for cloud, SaaS applications and backup systems alike. Backups are not a new target. Credential-driven access is simply a more efficient path to reach them."
Mark Odom, Senior Solutions Engineer at Black Duck
"For many organizations, the answer is not choosing one model over the other but finding the right balance. A hybrid approach that leverages the cloud for backup, disaster recovery, and resilience while running day-to-day operations on internal infrastructure, can deliver both financial benefits and operational flexibility.
"Ultimately, the key is having a robust disaster recovery strategy that allows organizations to capitalize on the cloud’s strengths while optimizing costs where it makes the most business sense."






















