Here's an uncomfortable number for World Backup Day 2026: 69 percent of organizations hit by ransomware last year considered themselves well-prepared beforehand according to Veeam 2025 Ransomware Trends Report. After the attack, only one in ten recovered more than 90 percent of their Server. This isn't a backup technology problem. It's a recovery capability problem.
A Backup Without a Tested Recovery Process Is a Promise You Can't Keep
I see this pattern repeatedly in client projects: backup jobs have been running reliably for years, retention policies are cleanly configured, storage consumption is monitored monthly. What's missing is restore testing under realistic conditions, a defined RTO (Recovery Time Objective), and a documented process for when things actually go wrong.
The threat landscape makes this gap worse. Ransomware operators now deliberately target backup infrastructure before launching the main attack — encrypting or deleting repositories to cut off the escape route. According to Veeam only 32% of repositories are Immutable.
What Recovery Readiness Actually Means
Recovery readiness isn't a product or a feature. It's a demonstrated state across four dimensions:
- Technical integrity: Backups must be immutably stored, isolated (air-gapped or logically separated), and regularly verified for restorability.
- Measurable recovery capability: RTO and RPO (Recovery Point Objective) must be defined and backed by real tests — not restoring a single file, but full-system recovery under time pressure.
- Process clarity: Who owns the recovery decision? Which systems come back first? Who gets notified and when? These questions need written answers before an incident happens, not during one.
- Clean isolation: According to Veeam, only 28 percent of organizations restored data to a sandbox environment and scanned for integrity before moving to production (Veeam 2025 Ransomware Trends Report, p. 12). Without this step, organizations risk reintroducing malware directly from backup into production.
NIS2 and DORA Turn Recovery Into a Documented Obligation
What used to be best practice is increasingly becoming a regulatory requirement. The EU's NIS2 Directive mandates that affected organizations implement and demonstrate measures for business continuity and recovery after security incidents. It covers entities in critical and important sectors — from energy and healthcare to digital infrastructure and IT services.
DORA (Digital Operational Resilience Act) applies to financial entities and their IT service providers, and has been fully enforceable since January 17, 2025. It explicitly requires regular resilience testing — not just having backups, but demonstrating that systems can be restored within defined timeframes.
Cyber insurers are moving in the same direction. Most carriers now require proof of MFA on backup consoles and documented immutable copies as a condition for coverage. Organizations that cannot demonstrate this face higher premiums — or no coverage at all.
Conclusion: Recovery readiness determines whether an organization survives an attack
Backup is necessary. Recovery readiness determines whether an organization survives an attack. The difference doesn't come down to technology — it comes down to documentation, testing, and process. NIS2, DORA, and cyber insurance requirements are forcing this shift now. Organizations that address it proactively will be in a fundamentally stronger position than those waiting for external pressure to act.
If you'd like to understand where your organization stands on recovery readiness, get in touch. Our Cyber Resilience Assessment helps you identify the gaps — before someone else finds them for you.
Sources
- Veeam: “2025 Ransomware Trends and Proactive Strategies,” Veeam Insights, 2025. Verified data: 69% of victims considered themselves prepared (p. 11); <10% recovered >90% of servers within expectations (p. 12); 28% use sandbox recovery (p. 12); 89% of backup repositories were targeted (p. 12). Available at: https://go.veeam.com/ransomware-trends-2025
- European Union: Directive (EU) 2022/2555 (NIS2), in force since 16 January 2023. Member state implementation deadline: 17 October 2024. Status of German transposition law (NIS2UmsuCG): pending.
- European Parliament: Regulation (EU) 2022/2554 (DORA), applicable from 17 January 2025. Available at: https://eur-lex.europa.eu