In a recent report released by the incident response firm Fenix24, alarming insights were presented regarding the effectiveness of ransomware recovery among businesses. Out of over 800 assessed clients, only four—representing a mere 0.5%—came close to meeting their 24 to 48-hour recovery targets. Notably, even these successful cases only achieved partial operational capacity. Unfortunately, full recovery for none of the clients occurred until several weeks after they were initially struck by the ransomware attack.
The findings were included in Fenix24’s inaugural State of Recoverability report, which analyzed data from more than 500 ransomware recovery efforts and was published on September 15. One of the striking observations made in the report was that the recovery plans, which appeared robust on paper, consistently fell apart once an attacker gained access to the organization’s systems.
### Identity Systems Complicate Recovery Efforts
A significant issue highlighted in the findings was related to identity recovery plans, or the lack thereof. An astonishing 99.2% of clients arrived without a documented strategy for recovering compromised identity systems. Even the few organizations that possessed such plans found them ineffective once faced with a real threat actor.
Jason Soroko, a senior fellow at Sectigo, commented on the situation, stating, “Recovery can depend on the same login system an attacker has compromised.” While he clarified that these findings reflect Fenix24’s specific engagements rather than every organization, they underscore a critical failure point that businesses should rigorously test for in their own cybersecurity measures.
Further complicating recovery was the dominance of Active Directory—the first major system compromised in nearly all cases. Fenix24 reported that a staggering 94% of clients had interlinked their backup systems to the very directory that attackers had infiltrated, making the restoration process particularly challenging.
The initial two days of recovery efforts were overwhelmingly focused on identity-related issues, consuming around 20% of the time simply to clean a single authentication source sufficiently for trust. Establishing a functional infrastructure that could be deemed “minimum viable” took an additional 72 hours, highlighting the time-consuming nature of recovery efforts.
Moreover, the report revealed that a staggering 95% of clients lacked effective multifactor authentication on critical infrastructure consoles, although a slightly better 15% had implemented such controls at the network entry points.
### Backups Fail to Deliver Effective Recovery
Another critical finding from the report was the ineffectiveness of surviving backups in facilitating business continuity. In 38% of cases where backups remained intact or nearly so, the recovery process still encountered challenges. Some of the backup sets were outdated, others were corrupted or incomplete prior to the attack, while some appeared in formats that rendered them unusable or took longer to restore than simply rebuilding the systems from scratch. Some backups were even on hardware labeled as immutable but unable to fulfill recovery needs.
Perhaps most concerning was that not a single client had a comprehensive understanding of their complete application and dependency landscape. The closest approximations existed in configuration databases, which also fell victim during the intrusion, or were created in real-time during recovery efforts as organizations scrambled to prioritize which systems to restore first.
Additionally, physical constraints played a significant role in hindering recovery success. Fenix24 noted that storage shortages affected 82% of engagements, often leaving restored data with no place to go without risking the integrity of forensic records. In 38% of cases, the networks were unable to accommodate the necessary scale of data transfer during recovery.
To mitigate these ongoing challenges, Fenix24 advises organizations to pinpoint their most revenue-critical services and demand comprehensive dependency maps for these, including third-party systems. Organizations should run full restore simulations end to end against current recovery targets to better prepare for future threats, advocating for rigorous testing of existing recovery plans and scenarios.
In conclusion, Fenix24’s report conveys a stark message about the vulnerabilities faced by organizations in the modern cybersecurity landscape. With a significant percentage of businesses struggling to recover effectively from ransomware attacks, the findings urge a more strategic approach to planning and preparedness in the face of an increasingly sophisticated threat environment.
