Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How Labour can reform Britain’s pensions triple lock | State pensions

    September 25, 2026

    Trump’s plans for massive arch move ahead

    September 25, 2026

    OpenAI investigating ‘dozens’ of instances of agents acting improperly

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How Labour can reform Britain’s pensions triple lock | State pensions
    • Trump’s plans for massive arch move ahead
    • OpenAI investigating ‘dozens’ of instances of agents acting improperly
    • Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
    • U.S. SEC’s steadiest crypto advocate, Hester Peirce, to depart next week
    • First stellar stream beyond the Milky Way could reveal dark matter
    • Cheetah cubs at Prague Zoo are doing well after a period of strong storms and their mother’s illness
    • Australian interconnector granted final approval before construction
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Technology

    Why recovery readiness has become the new standard for cyber resilience

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Technology No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    ZDNET composite; Getty Images / D3Damon

    More than 90% of ransomware attacks now try to delete or tamper with backups before a payload ever fires, according to a recent ransomware report. And nearly 60% of the attacks that go after backups succeed. Outages are no longer just IT headaches; they’re a risk for the entire enterprise.

    Delayed recoveries bring business-critical processes to a halt, hamper team productivity, and lead to permanent customer losses. Many service disruptions result from a common, albeit costly misconception: Backup isn’t recovery. In one U.S. Chamber of Commerce report, for example, 94% of surveyed SMB leaders believed their enterprise would survive a disaster, even though only a quarter had the recovery infrastructure in place.

    The distinction between backup and recovery extends beyond semantics. While the former creates duplicate copies of business data, the latter ensures that when a ransomware attack strikes or a system fails, the organization can restore its operations quickly enough to avoid prolonged downtime, lost revenue, and lasting damage to customer trust.

    The breaking point in backup assumptions 

    Attackers count on this flawed assumption, and often understand the difference better than the companies they target. Many threat groups tamper with backups first before breaching the rest of the IT stack.

    Organizations that treat backups as their disaster recovery strategy, therefore, are merely protecting their data, not their business. Closing that gap demands modern resilience strategies, which combine secure, immutable backups with rapid recovery capabilities, an approach reflected in platforms like Datto.

    Attackers no longer break in, they walk in

    Hybrid environments are no longer a choice. On-prem hardware acquisition costs have risen in recent years, pushing organizations to deploy new and refreshed workloads in the cloud — and widening the identity attack surface in the process. Attackers no longer need to get through the firewall to reach business applications; they log in. They bypass MFA, hijack live sessions, and slip past email security, sometimes after researching targets on LinkedIn for the ones most likely to hold elevated or administrative access.

    It’s not anecdotal, either. About four in five ransomware attacks begin with identity-based approaches, and more importantly, most of these strike backup repositories first, cutting off the only survival route for organizations without a recovery plan.

    Your cloud provider won’t back you up 

    This exposure is wider than most teams might assume. Of the SaaS accounts monitored in 2025, 69% were guest accounts rather than licensed users, and only 27% of SMBs were actively enforcing MFA, according to the Kaseya 2026 SaaS Security Report. 

    Cloud providers like Microsoft and Google operate under a Shared Responsibility Model, where they keep the service running, but the data is yours to protect. Their built-in recycle bins, version history, and retention policies are made for uptime, not operational recovery from ransomware or large-scale accidental deletions. Modern attackers are counting on that absence of additional recovery safeguards.

    Most organizations fall back to a fragmented defense and depend on a complex mix of native and standalone solutions, stretching out Recovery Time Objectives timelines beyond what’s feasible. Only 1 in 5 organizations report unified backup protection across hybrid environments, according to a Redmond/Kaseya survey of 200 IT professionals.

    From backup volume to recovery readiness 

    Preparation pays. Building resilience isn’t only insurance for unforeseen incidents; it also fosters long-term growth. However, hosting backups isn’t the same as being able to recover. In the Redmond/Kaseya report, 53% of the surveyed IT professionals said they were only somewhat confident they could restore their environment, and just 18% test that assumption monthly.

    Without a tested recovery plan in place, backup jobs will report success and still leave you stranded with application data and VM images that won’t open, decrypt, or boot. Take tools like Datto’s Screenshot Verification, for instance. It anticipates these gaps before an emergency hits. It even verifies that every system is tested to boot automatically after each backup, with a screenshot to prove it worked.

    But merely copying files to store as backups isn’t enough. If identity layers, like email accounts, remain locked, nobody works and productivity tanks, regardless of how clean the backups are. When large-scale software or cloud infrastructure is compromised, rebuilding a clean version is often faster than salvaging the old one, and dedicated recovery tools make that pivot survivable. That is why leading Managed Service Providers (MSPs) are already moving to immutable, isolated backups with independent credentials and rehearsed recovery plans. 

    Where this hits hardest

    For any IT organization, an unclear recovery plan converts into lost trust, lost revenue, and longer downtime at the worst possible moment. Cyber liability coverage has gotten harder to obtain and carries more requirements, and insurers increasingly expect organizations to represent their RTOs and RPOs accurately, which is difficult to do honestly without tested recovery.

    Regulation is moving in the same direction. CMMC, GDPR, NIS2’s business continuity requirements, and DORA’s logical separation mandate all treat resilience as an obligation, rather than a best practice.

    Not sure where you stand? Start with this low-commitment checklist to assess whether your organization is truly resilient. And if you’re ready to see what recovery readiness looks like in practice, take the Datto SaaS Protection product tour to explore how independent, automated recovery works across Microsoft 365 and other systems.

    Cyber readiness recovery resilience Standard
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI investigating ‘dozens’ of instances of agents acting improperly

    Anthropic to pay Akamai $11.6 billion over seven years in cloud deal

    Meta opens early access program for new Muse features

    Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’

    Phones don’t have lights | The Verge

    This one WatchOS 27 feature just solved my biggest issue with Apple Watch

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How Labour can reform Britain’s pensions triple lock | State pensions

    September 25, 2026

    Trump’s plans for massive arch move ahead

    September 25, 2026

    OpenAI investigating ‘dozens’ of instances of agents acting improperly

    September 25, 2026

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    September 25, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How Labour can reform Britain’s pensions triple lock | State pensions

    September 25, 2026

    Trump’s plans for massive arch move ahead

    September 25, 2026

    OpenAI investigating ‘dozens’ of instances of agents acting improperly

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.