Skip to main content
Home » Power of Data & AI » Delaying recovery investments raises business risk
Sponsored

Pete Hannah

VP Sales, Western Europe, Object First.

As ransomware attacks become more common and recovery outcomes worsen, organisations must prioritise resilient backup and recovery strategies.


Economic uncertainty is forcing organisations to scrutinise every technology investment. Rising operating costs, supply chain pressures and growing investment in AI initiatives are prompting many businesses to postpone infrastructure upgrades.

Recovery matters most

Backup and recovery systems can appear to be an easy target for budget reductions, particularly when organisations are focused on prevention technologies. However, an IDC Spotlight published in June 2026 suggests that delaying backup and recovery investments may pose greater risks than the savings they yield.1

Security controls help to reduce the attack surface, but no organisation can assume prevention alone will stop every attack. When cybercriminals gain access to production environments, the ability to recover data quickly and reliably becomes the foundation of cyber resilience.

In practice, recovery capabilities determine how effectively an organisation can withstand operational disruption, limit financial losses and maintain customer trust following a cyber incident.

Strong backup architecture should combine immutable storage,
controlled access and regularly tested recovery processes

Ransomware recovery is worsening

The case for continued investment is reinforced by recent industry research. A study conducted by Omdia found that 83% of organisations experienced a successful ransomware attack during the previous 24 months. Recovery is often slow: in 79% of cases, it took more than five working days, overrunning the organisation’s Recovery Time Objective (RTO) in most instances. On average, just 61% of the affected data was recovered. Worryingly, the study points to declining recovery performance compared with previous surveys.2

The research also revealed that many organisations understand the importance of recoverability but have not modernised the underlying infrastructure needed to deliver it.

The value of immutability

Attackers increasingly target backup repositories because they recognise that recovery is often the last line of defence. Cyber criminals target backup repositories in 89% of cyberattacks and modify or delete one-third of the repositories targeted.3 If backup data can be encrypted, deleted or altered, recovery becomes difficult or impossible.

The IDC Spotlight analysis distinguishes between software-based immutability and hardware-enforced immutability.1 Software controls can potentially be disabled or bypassed if attackers gain privileged access. Hardware enforced approaches are designed to prevent changes to protected backup data during the retention period, helping preserve recovery points against tampering or deletion.

Strong backup architecture should combine immutable storage, controlled access and regularly tested recovery processes. Together, these capabilities help organisations recover faster and reduce the operational and financial consequences of cyber incidents.

The cost of waiting

Many organisations delay modernisation projects while waiting for economic conditions to improve. Yet, cyber threats do not slow down during periods of financial pressure. The costs associated with ransomware, including downtime, lost productivity, recovery efforts, reputational damage and potential regulatory consequences, can quickly exceed the investment required to establish a resilient recovery framework.

Organisations face growing expectations from regulators, customers and business stakeholders to demonstrate that they can withstand and recover from cyber incidents. The UK’s Cyber Security and Resilience Bill reinforces the importance of protecting the continuity of essential and digital services. For business leaders, this strengthens the case for treating recovery readiness as a business priority, with investment decisions grounded in proven recovery capabilities.4

Taken together, the research findings and the UK’s regulatory direction strengthen the case for treating backup and recovery investment as a business resilience priority.5 When prevention fails, recovery capabilities determine how quickly the business can return to normal operations. Waiting to strengthen those capabilities may ultimately prove far more expensive than acting now.


[1] IDC Spotlight, sponsored by Object First. (2026, June). The Danger of Deferring Backup and Recovery Investments (Doc. #US54572026).
[2] Omdia Research, commissioned by Object First. (2026). 2026 Ransomware Recovery Study. tinyurl.com/y2t4mf92.
[3] Object First. (n.d.). Cyber Security and Resilience Bill: Compliance Guide & Checklist. tinyurl.com/bdfp7n32
[4] Object First. (n.d.). Cyber Security and Resilience Bill: What It Is and Who It Affects. tinyurl.com/5fr2e9pz
[5] Veeam. (2025). 2025 Ransomware Trends Report. tinyurl.com/3s4w3nb

Next article