Enterprises have spent years investing in the people, processes and technology that reduce the impact and the odds of a ransomware attack. Nevertheless, efforts to bolster defenses have come up short, according to research commissioned by backup storage vendor Object First.
Research firm Omdia, a Channel Dive sister company, surveyed 700 organizations with 1,000 or more employees and found that ransomware incidents increased and recoveries became more difficult in the last two years. More than 4 in 5 respondents said their organization experienced an attack that disrupted services, compared with 66% in similar 2024 research. Three-quarters of organizations suffered more than one ransomware disruption in the last 24 months.
Defender measures are losing ground, crippling post-incident recoveries, Omdia found. Only 39% of organizations successfully restored at least three-quarters of the data from ransomware attacks, compared with 57% in 2024. Meanwhile, 76% of respondents said the data lost during their worst ransomware incident exceeded the amount permitted under their recovery point objective.
Recovery problems extended beyond production systems. Once inside an environment, attackers can encrypt, corrupt or destroy backups, depriving organizations of the clean data they need to restore operations. Rather than linking direct attacks on backups to drops in recovery rates, the survey indicated a correlation between compromised recovery infrastructure and the extent of ransomware damage.
Defining ‘immutable’
While organizations are giving themselves more time to recover, they are still missing their targets, the survey found. Fewer than 2 in 5 respondents maintained recovery time objectives of five business days or less, compared to 49% in 2024. Nearly two-thirds said their longest ransomware outage lasted longer than their established RTO.
When ransomware renders both production data and backup copies unavailable, a cybersecurity incident can develop into a prolonged operational problem that reaches customers, employees and business partners. Most organizations that suffered attacks — 87% — said their most disruptive ransomware incident caused at least moderate harm to the business.
The research found a significant mismatch between what organizations describe as immutable storage and how well those backups are actually protected. More than three-quarters of respondents said their primary backup solution uses immutable storage. Yet 83% of that group acknowledged at least one limitation that could leave the data vulnerable to change or deletion. Such limitations included delays before data become immutable, inadequate controls over who can authorize changes and storage configurations that allow users with sufficient permissions to modify protected data.
Inadequate data backups have deep consequences when attackers obtain privileged credentials. Storage protections that depend on administrative permissions can remain vulnerable even when an organization considers its backups immutable. Omdia drew a line between absolute immutability, which protects backups from alteration or deletion by attackers with an organization’s IT credentials, and less secure strategies. Only 16% of respondents said their current environment provides absolute immutability.
Progress toward more resilient data backups is underway. Half of IT leaders said they expect to change backup storage types during their next refresh. Yet, a refresh could be years away, according to Omdia. Asked what could prompt an earlier change, the most common answer — cited by 39% of respondents — was a cyberattack that compromised the backup environment.
Waiting for an incident is a risky strategy, according to Simon Robinson, principal analyst at Omdia.
“Ransomware can lead to a business continuity crisis, and the data shows that many organizations fall short when it comes to reliable recovery,” Robinson said in a release accompanying the report.
The vendor landscape also presents challenges. Most respondents — 89% — said vendors’ immutability claims need independent verification, yet only 56% used third-party testing to validate products.
After Omdia explained the difference between immutable and absolutely immutable storage, 73% of line-of-business leaders said they were more likely to require technology vendors that can provide stronger protection.