Why recovery readiness has become the new standard for cyber resilience

59 minutes ago 5
datto-backup
ZDNET composite; Getty Images / D3Damon

More than 90% of ransomware attacks now try to delete or tamper with backups before a payload ever fires, according to a recent ransomware report. And nearly 60% of the attacks that go after backups succeed. Outages are no longer just IT headaches; they're a risk for the entire enterprise.

Delayed recoveries bring business-critical processes to a halt, hamper team productivity, and lead to permanent customer losses. Many service disruptions result from a common, albeit costly misconception: Backup isn't recovery. In one U.S. Chamber of Commerce report, for example, 94% of surveyed SMB leaders believed their enterprise would survive a disaster, even though only a quarter had the recovery infrastructure in place.

The distinction between backup and recovery extends beyond semantics. While the former creates duplicate copies of business data, the latter ensures that when a ransomware attack strikes or a system fails, the organization can restore its operations quickly enough to avoid prolonged downtime, lost revenue, and lasting damage to customer trust.

The breaking point in backup assumptions 

Attackers count on this flawed assumption, and often understand the difference better than the companies they target. Many threat groups tamper with backups first before breaching the rest of the IT stack.

Organizations that treat backups as their disaster recovery strategy, therefore, are merely protecting their data, not their business. Closing that gap demands modern resilience strategies, which combine secure, immutable backups with rapid recovery capabilities, an approach reflected in platforms like Datto.

Attackers no longer break in, they walk in

Hybrid environments are no longer a choice. On-prem hardware acquisition costs have risen in recent years, pushing organizations to deploy new and refreshed workloads in the cloud -- and widening the identity attack surface in the process. Attackers no longer need to get through the firewall to reach business applications; they log in. They bypass MFA, hijack live sessions, and slip past email security, sometimes after researching targets on LinkedIn for the ones most likely to hold elevated or administrative access.

It's not anecdotal, either. About four in five ransomware attacks begin with identity-based approaches, and more importantly, most of these strike backup repositories first, cutting off the only survival route for organizations without a recovery plan.

Your cloud provider won't back you up 

This exposure is wider than most teams might assume. Of the SaaS accounts monitored in 2025, 69% were guest accounts rather than licensed users, and only 27% of SMBs were actively enforcing MFA, according to the Kaseya 2026 SaaS Security Report

Cloud providers like Microsoft and Google operate under a Shared Responsibility Model, where they keep the service running, but the data is yours to protect. Their built-in recycle bins, version history, and retention policies are made for uptime, not operational recovery from ransomware or large-scale accidental deletions. Modern attackers are counting on that absence of additional recovery safeguards.

Most organizations fall back to a fragmented defense and depend on a complex mix of native and standalone solutions, stretching out Recovery Time Objectives timelines beyond what's feasible. Only 1 in 5 organizations report unified backup protection across hybrid environments, according to a Redmond/Kaseya survey of 200 IT professionals.

From backup volume to recovery readiness 

Preparation pays. Building resilience isn't only insurance for unforeseen incidents; it also fosters long-term growth. However, hosting backups isn't the same as being able to recover. In the Redmond/Kaseya report, 53% of the surveyed IT professionals said they were only somewhat confident they could restore their environment, and just 18% test that assumption monthly.

Without a tested recovery plan in place, backup jobs will report success and still leave you stranded with application data and VM images that won't open, decrypt, or boot. Take tools like Datto's Screenshot Verification, for instance. It anticipates these gaps before an emergency hits. It even verifies that every system is tested to boot automatically after each backup, with a screenshot to prove it worked.

But merely copying files to store as backups isn't enough. If identity layers, like email accounts, remain locked, nobody works and productivity tanks, regardless of how clean the backups are. When large-scale software or cloud infrastructure is compromised, rebuilding a clean version is often faster than salvaging the old one, and dedicated recovery tools make that pivot survivable. That is why leading Managed Service Providers (MSPs) are already moving to immutable, isolated backups with independent credentials and rehearsed recovery plans. 

Where this hits hardest

For any IT organization, an unclear recovery plan converts into lost trust, lost revenue, and longer downtime at the worst possible moment. Cyber liability coverage has gotten harder to obtain and carries more requirements, and insurers increasingly expect organizations to represent their RTOs and RPOs accurately, which is difficult to do honestly without tested recovery.

Regulation is moving in the same direction. CMMC, GDPR, NIS2's business continuity requirements, and DORA's logical separation mandate all treat resilience as an obligation, rather than a best practice.

Not sure where you stand? Start with this low-commitment checklist to assess whether your organization is truly resilient. And if you're ready to see what recovery readiness looks like in practice, take the Datto SaaS Protection product tour to explore how independent, automated recovery works across Microsoft 365 and other systems.

Read Entire Article