Ransomware Recovery Plans Fail When It Matters Most, Report Finds
A new report from incident response firm Fenix24 has found that only 0.5% of clients it assessed came close to meeting their own 24 to 48 hour ransomware recovery targets, and even then only for partial operations. None reached full recovery until weeks after the attack.
The report, based on more than 500 ransomware recoveries, found that 99.2% of clients had no documented plan for restoring identity systems such as Active Directory. In 94% of cases, backup systems were tied to the same directory service the attacker had already compromised, meaning recovery depended on rebuilding trust in a system the attacker controlled. Around 20% of the first two days of recovery was spent just cleaning up a single trustworthy login source.
Even when backups survived an attack, 38% of them could not actually be used for recovery due to being outdated, corrupted, in the wrong format, or too slow to restore. The report also found 95% of clients lacked meaningful multifactor authentication on critical infrastructure consoles, and none had a full, accurate picture of their applications and system dependencies before the attack hit.