Four in 800 recovered on time
If someone asked your board today whether the business could recover from ransomware, the honest answer is probably "yes, we have backups and a plan." That answer is usually sincere and usually wrong, not because the backups do not exist, but because nobody has tested the two things that actually decide how fast you get back up: whether your recovery plan depends on a system the attacker will seize first, and whether the people managing your infrastructure are protected as well as the people logging into their email.
New data from the incident response firm Fenix24 puts numbers on that gap. Drawn from more than 500 ransomware recoveries, its first State of Recoverability report found that only 4 of over 800 clients assessed, 0.5%, came close to their own 24 to 48 hour recovery target, and even then only for part of the business. None reached full operational capacity until several weeks after the attack. The report, covered by Infosecurity Magazine, names two specific, checkable reasons recovery plans failed.
The directory that runs everything is also the first thing to fall
Active Directory is the system that checks who is allowed to log into what across your network: it is how a laptop knows an employee's password is correct and which files, servers, and systems they are allowed to reach. Almost every other system, including the backup software itself, usually asks Active Directory for permission before it does anything.
Fenix24 found that 94% of clients had tied their backup systems to that same directory. Attackers know this too, which is why Active Directory is usually the first major system they go after. Once it falls, the backups that depend on it for permissions fall with it, and the business spends its first hours rebuilding the identity system everything else needs, not restoring data. Roughly a fifth of the opening two days went on identity alone, before minimum viable infrastructure could even begin, and 99.2% of clients had no documented plan for that step at all.
The fix is not a new tool. It is knowing, in writing, whether your recovery plan can stand up an authentication system independent of the one an attacker has just taken, and whether your backup access needs the directory that is down.
The consoles that run your infrastructure are barely protected
The second finding is about multi-factor authentication, the extra verification step, typically a code on your phone, that you enter after your password. Most businesses have it switched on for staff logging into email or a laptop. Far fewer have it on the consoles used to manage servers, backup systems, and network equipment, the tools an administrator uses to configure and control the infrastructure itself.
Fenix24 found 95% of clients had no meaningful multi-factor authentication on those infrastructure management consoles, against just 15% missing it at the network's outer edge. The front door is comparatively well guarded. The room with the keys to everything is often not guarded at all. An attacker who reaches an unprotected admin console does not need to break anything further; they can simply log in and start disabling defences or deleting backups directly.
There is a third finding worth a sentence: even where backups survived the attack, 38% still could not carry the recovery, because they were the wrong format, quietly corrupt, or slower to restore than rebuilding from scratch. Sound backups on paper and a working restore are not the same claim, which is exactly why this data does not repeat "have backups" as the advice.
How Steelwise can help
Working out whether your recovery plan quietly depends on Active Directory, and whether multi-factor authentication actually covers your infrastructure consoles rather than just user logins, is the kind of security review we do with clients. Get in touch.
What to do
- Ask whoever runs your backups, in writing, whether the backup system needs Active Directory to work. If yes, ask how you would recover it if the directory itself were down.
- Check multi-factor authentication is switched on for every console used to manage servers, backup systems, and network equipment, not just staff email and laptop logins.
- Identify the one business service you could least afford to lose, and confirm you have a full list of everything it depends on, including third parties.
Further reading
- Infosecurity Magazine: Most firms unable to recover quickly from ransomware
- NCSC: Mitigating malware and ransomware attacks