Ask the average business owner how they would react to a company-wide virus takedown. Even if, by some miracle, this particular owner didn’t have their head completely in the sand, they would probably mutter something like “Well, we’ve got a backup system.”
Well done for having backups at least. That’s a start.
The reality is, having backups and being able to recover, are two very different things.
The numbers most businesses don’t want to hear
Earlier this month, the incident response firm Fenix24 published a State of Recoverability report. Based on more than 800 client assessments and over 500 real ransomware recoveries, the headline finding was that only 4 of those 800+ organizations – about 0.5% – met a 24–48 hour recovery target.
That is embarrassingly low.
But it gets worse…
A few other findings from the report stood out:
- 38% of those organizations that actually had a backup strategy still couldn’t fully restore operations in a 24–48 hour window. They had their data but could not thread the systems around it back together fast enough.
- 94% had backup systems tied to the same login system (Active Directory) that attackers had compromised. The ransomware that locked the business out often held the keys to the backups too. Whoops.
- 99.2% had no documented plan for restoring their user logins and permissions after an attack with key personnel and employees left twiddling their thumbs until the IT department caught up.
- And 82% ran out of storage space in the middle of their data recovery. Incurring more additional expense on top of an already stressful situation.
These figures don’t relate to every business of course. The organizations sampled in this particular study were already in trouble. However, another recent survey – this time from Arcserve – paints the same picture.
This one asked IT professionals how confident they were that they would recover from a ransomware attack within 48 hours. 65% said they were confident. When tested, however, just 35% actually hit their targets.
And nearly a quarter had never tested a full recovery at all. They merely assumed it would all good.
The key point here is that most businesses overestimate full recoverability. They map out a process, but then never actually test it to ensure validity.
Why “backups” aren’t enough
The cold reality is that backups are only one piece of your business recovery story.
And here’s why…
1. Backups are often attacked too! Most modern ransomware attacks don’t just go after active files. Quite often, they’ll actually look for your backup files first. And if your backup system uses the same admin accounts as your main network, the hacker will absolutely love that! They’ll take the insurance policy out first before they trigger their main the attack.
2. No one in your organisation has tested whether the backups actually work. Backups can quietly fail for months because of corrupted files, missed jobs or formats that won’t restore correctly. You won’t find out until the day you need them.
3. You can’t restore into a network that’s still infected. If there’s no clean environment to rebuild into, restored systems can be reinfected right away.
4. You need valid user accounts to restore to. Before your team can start using restored files, email accounts or applications, you will need clean, working and trustworthy accounts to re-populate into. Quite often, rebuilding logins and permissions alone takes about 20% of the first two days.
5. Cloud data isn’t automatically protected. Arcserve found that 19% of organizations have no backup at all for data in cloud (SaaS) apps. Microsoft keeps its services running, but protecting your own data inside Microsoft 365 is still your job. Not a lot of people know that.
6. Your business recovery plan only exists in someone’s head. When your systems get taken down and everyone is panicking, responsibility falls on the person in the business with the plan in their head or on their computer. What happens if they are OOO at the time or their own machine is compromised in the chaos?
What a real recovery plan should look like
Here’s what RAPID IT recommends to every business we work with.
1. Follow the 3-2-1-1 rule
Keep three copies of your critical data, on two different types of storage, with one copy offsite and one copy that is immutable (it can’t be changed or deleted, even by an admin) or physically disconnected from your network.
2. Separate your backup logins from everything else
Your backup system should never share accounts with your main network. Give it its own credentials and require multi-factor authentication on backup and admin consoles. This is the single most common gap attackers exploit and the first gap you should look to close.
3. Test restores on a schedule
Run a real test restore of files and at least one critical system every 3 months. At least once a year, run a full exercise and time your recovery. You need to identify how long it actually takes to recovery fully (business as usual), not how long you expect or wish it will take.
4. Define your recovery targets
Establish two KPI numbers for each critical system:
- RTO (Recovery Time Objective): how long you can afford to be down before the business starts breaking.
- RPO (Recovery Point Objective): how much data you can afford to lose on a time basis – for example 1 hour or 24 hours worth of active data.
These decide how often you need to schedule your system back up and what kind of recovery setup you need.
5. Back up Microsoft 365 and other cloud apps
If you’re using and storing data inside Microsoft products like Email, OneDrive, SharePoint and Teams, you will need to have a backup policy for these, separate from Microsoft’s. They won’t be held accountable, it’s your responsibility.
6. Write it down and print it
Document your policy and procedure. When the situation goes south, who does what, in what order, and who to call. Your IT provider, your cybersecurity insurer, legal counsel, your bank. Keep a printed copy offsite (ideally secure but easily reachable) because a plan saved on an encrypted server or on a USB in your PA’s kitchen draw won’t be useful at the time.
A South Florida bonus: hackers and hurricanes
As a business owner in Florida, you’ll be aware we’re in hurricane season right now. A ransomware attack and a Category 3 storm have one thing in common: either can leave your office systems unreachable for days.
Having a robust data backup and recovery plan accounts for either threat. Offsite, immutable backups, a tested restore process and a written recovery playbook are all crucial parts for getting you back online fast – whether you’ve been hacked or hurricaned. If you’ve never tested your disaster recovery, this is a good time to do it.
Quick business backup self-check
Can you answer “yes” to all five of these questions?
- We have at least one backup copy that can’t be deleted or changed, even by an admin.
- Our backup system uses separate logins, protected by 2FA authentication.
- We’ve carried out a successful test restore in the last 90 days.
- We know how many hours of downtime and data loss our business can tolerate.
- Our recovery plan is written down, and a copy is stored outside our network.
If you answered “no” or “not sure” to any of these questions you have a recovery gap.
Find out how long your recovery might take
RAPID IT has helped South Florida businesses build robust backup and restore processes since 2006. We’ll review your current backup setup, run a test restore, and tell you plainly how long a true recovery would take today.
Book your free recovery readiness check →
Sources: Fenix24, State of Recoverability 2026, via Infosecurity Magazine; Arcserve 2026 Data Resilience Report.

