Updated
Updated · ZDNet · Aug 10
Ransomware Hits 90% of Backups, Pushing Recovery Readiness as New Standard
Updated
Updated · ZDNet · Aug 10

Ransomware Hits 90% of Backups, Pushing Recovery Readiness as New Standard

3 articles · Updated · ZDNet · Aug 10

Summary

  • More than 90% of ransomware attacks now try to delete or tamper with backups before deploying payloads, and nearly 60% of those backup-focused attacks succeed.
  • That shift is exposing a core weakness: backup copies alone do not ensure operations can restart fast enough to avoid downtime, lost revenue and customer churn.
  • About four in five ransomware attacks now begin with identity-based access, while cloud and SaaS setups add risk—69% of monitored 2025 SaaS accounts were guest accounts and only 27% of SMBs enforced MFA.
  • Recovery readiness remains thin across many firms: only 1 in 5 organizations report unified backup protection in hybrid environments, 53% of IT professionals are only somewhat confident in restoration, and just 18% test monthly.
  • Insurers and regulators are raising the stakes, with frameworks including CMMC, GDPR, NIS2 and DORA increasingly treating tested recovery, accurate RTOs and business continuity as obligations.

Insights

If 90% of ransomware attacks target backups first, how can you be sure your organization's safety net hasn't already been compromised?
Since cloud providers don't guarantee operational recovery, who is truly responsible when a major cyberattack permanently erases your critical data?