LIVE · cybersecurity feed
Live wire
ransomware

Most Firms Unable to Recover Quickly from Ransomware

Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours

zeroday.news ·

A new report from incident response firm Fenix24 indicates that very few organizations are able to recover quickly from ransomware attacks, with only a tiny fraction achieving even partial operational capacity within their target recovery windows. The firm's first "State of Recoverability" report, released on September 15, analyzed over 500 ransomware recovery engagements and found that none of its clients reached full operational capacity until several weeks after an incident.

Out of more than 800 clients assessed, only 0.5% (four organizations) came close to their self-imposed 24 to 48-hour recovery targets, and even then, only for partial business operations. The report attributes these widespread recovery failures to critical shortcomings in planning and infrastructure, particularly concerning identity systems and backups.

A significant hurdle identified was the compromise of identity systems. Fenix24 found that 99.2% of clients lacked a documented identity recovery plan, and any existing plans proved ineffective once an attacker gained access. Active Directory was frequently the initial major system to be compromised, and 94% of clients had linked their backup systems to the very directory seized by the attackers. This meant that roughly 20% of the initial two days of recovery efforts were dedicated solely to establishing a trustworthy authentication source.

Furthermore, the report highlighted a severe lack of multifactor authentication (MFA) on critical infrastructure consoles, with 95% of clients having no meaningful MFA controls in place for these systems, compared to 15% at network ingress points. Reaching a minimum viable infrastructure typically required at least an additional 72 hours after identity issues were addressed.

Even when backups survived an attack, they often failed to facilitate recovery. In 38% of engagements where backups were largely intact, they still could not support the restoration process. Reasons included backups being outdated, corrupt, partial, or in an incompatible format. Some backups were also found on hardware with immutable labels that prevented their delivery.

A pervasive issue was the lack of a comprehensive understanding of application dependencies. No client possessed a complete map of their applications and their interdependencies. The closest equivalents were configuration databases that were often compromised alongside other systems, or these maps had to be created ad-hoc during recovery as businesses prioritized which services to restore first.

Physical constraints also routinely impeded recovery efforts. In 82% of engagements, organizations faced a shortage of storage space, making it difficult to restore data without overwriting forensic evidence. Additionally, in 38% of cases, the network infrastructure was unable to handle data movement at the scale required for recovery.

To mitigate these issues, Fenix24 recommends that organizations identify their most revenue-critical business services and develop a complete dependency map for them, including third-party components. They also advise running full, end-to-end restore paths against current recovery targets, emphasizing that simulations and untested plans are insufficient.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s