A new report from incident response firm Fenix24 indicates that very few organizations are able to recover quickly from ransomware attacks, with only a tiny fraction achieving even partial operational capacity within their target recovery windows. The firm's first "State of Recoverability" report, released on September 15, analyzed over 500 ransomware recovery engagements and found that none of its clients reached full operational capacity until several weeks after an incident.
Out of more than 800 clients assessed, only 0.5% (four organizations) came close to their self-imposed 24 to 48-hour recovery targets, and even then, only for partial business operations. The report attributes these widespread recovery failures to critical shortcomings in planning and infrastructure, particularly concerning identity systems and backups.
A significant hurdle identified was the compromise of identity systems. Fenix24 found that 99.2% of clients lacked a documented identity recovery plan, and any existing plans proved ineffective once an attacker gained access. Active Directory was frequently the initial major system to be compromised, and 94% of clients had linked their backup systems to the very directory seized by the attackers. This meant that roughly 20% of the initial two days of recovery efforts were dedicated solely to establishing a trustworthy authentication source.
Furthermore, the report highlighted a severe lack of multifactor authentication (MFA) on critical infrastructure consoles, with 95% of clients having no meaningful MFA controls in place for these systems, compared to 15% at network ingress points. Reaching a minimum viable infrastructure typically required at least an additional 72 hours after identity issues were addressed.
Even when backups survived an attack, they often failed to facilitate recovery. In 38% of engagements where backups were largely intact, they still could not support the restoration process. Reasons included backups being outdated, corrupt, partial, or in an incompatible format. Some backups were also found on hardware with immutable labels that prevented their delivery.
A pervasive issue was the lack of a comprehensive understanding of application dependencies. No client possessed a complete map of their applications and their interdependencies. The closest equivalents were configuration databases that were often compromised alongside other systems, or these maps had to be created ad-hoc during recovery as businesses prioritized which services to restore first.
Physical constraints also routinely impeded recovery efforts. In 82% of engagements, organizations faced a shortage of storage space, making it difficult to restore data without overwriting forensic evidence. Additionally, in 38% of cases, the network infrastructure was unable to handle data movement at the scale required for recovery.
To mitigate these issues, Fenix24 recommends that organizations identify their most revenue-critical business services and develop a complete dependency map for them, including third-party components. They also advise running full, end-to-end restore paths against current recovery targets, emphasizing that simulations and untested plans are insufficient.






