Opens in a new tab
vmblog logo 2024 wht (updated)

What Omdia’s Latest Data Reveals About the State of Ransomware Recovery – VMblog QA

Share: 

David Marshall | Published: September 17, 2026
interviews objectfirst anthony cusimano

Ransomware is no longer a matter of if, but when—and according to new research from Omdia, commissioned by Object First, most organizations still aren’t prepared for what comes after an attack hits. The numbers tell a troubling story: 83% of organizations have experienced a service-impacting ransomware attack in the past 24 months, up sharply from 66% in 2024, while recovery outcomes have simultaneously gotten worse. Only 39% of organizations were able to recover at least 75% of their data following an attack, a steep drop from 57% just a year earlier.

At the center of this widening gap is a false sense of security around backup immutability. While 93% of IT leaders say their backup storage should be protected from deletion or modification even when credentials are compromised, only 16% actually have what the research defines as Absolute Immutability. Worse, many organizations that believe their backups are already immutable are operating with hidden limitations—delayed immutability windows, administrative overrides, or configurations that still leave protected data vulnerable.

To unpack what’s driving this disconnect between perceived and actual protection, VMblog spoke with Anthony Cusimano, Senior Director of Solutions Marketing at Object First, about why attackers currently hold the advantage, what questions IT leaders should be asking vendors to verify true immutability, and how data sovereignty and recovery infrastructure fit into a resilient backup strategy.

++

VMblog: Omdia found that 83% of organizations experienced a service-impacting ransomware attack in the last 24 months, up from 66% in 2024. What does that increase tell you about the current balance between attackers and defenders?

Anthony Cusimano: Attackers clearly have the edge today, and the gap in capabilities between attackers and defenders is widening. The likelihood of a successful, service-impacting attack has increased significantly since 2024, while 75% of organizations that were successfully attacked experienced multiple attacks. That tells us that ransomware is becoming more common and widespread, with organizations facing repeated disruption and the fear that their data is next. Despite years of investment in people, processes and technologies designed to reduce both attack likelihood and impact, the data shows that business continuity outcomes are still moving in the wrong direction. Prevention remains important, but disruption is increasingly a matter of when, not if. Organizations need to prioritize recovery alongside prevention if they want to improve cyber resilience and not remain vulnerable to the plethora of ongoing ransomware tactics that emerge and evolve daily.

VMblog: Recovery performance also appears to be deteriorating: only 39% of organizations recovered at least 75% of their data after ransomware attacks, compared with 57% in 2024. Why are organizations struggling to recover even after years of investment in cyber resilience?

Cusimano: Ransomware attacks are impacting more organizations, and when those compromises happen, organizations are having a harder time recovering.  Bad actors are deliberately targeting, corrupting, destroying or encrypting both production data and backups, which can make complete recoverability impossible for IT teams. Since backups are widely viewed as the last line of defense against ransomware, if an organization’s backup data can also be compromised, they may have no reliable, clean recovery point to return to. Therefore, recovery infrastructure has to be treated as a core part of cyber resilience rather than something organizations rely on only after prevention fails.

VMblog: While 93% of IT leaders say backup storage should protect data from deletion or modification even when credentials are compromised, only 16% currently have what the research defines as Absolute Immutability. What is preventing organizations from closing that gap?

Cusimano: Although IT leaders recognize that Absolute Immutability is a critical requirement, many factors prevent enterprises from closing that gap: Deployments have lagged, and organizations are often relying on forms of immutability that still include limitations such as delayed immutability, administrative controls or configurations that still allow protected data to be modified or deleted. Organizations also lack the time and resources to independently validate vendor claims, contributing to the gap between the protection they want and what they have deployed today.

VMblog: Many organizations believe they already have immutable backups, yet Omdia found that 83% of those deployments still have limitations—from delayed immutability to administrative controls that can allow protected data to be changed. What should IT leaders be asking vendors to determine whether their backups are truly immutable?

Cusimano: IT leaders should start by asking exactly how and when immutability is enforced. Backup data should become immutable the moment it is written, and no administrator or attacker with compromised credentials should be able to alter or delete it. They should also evaluate whether there is separation between the backup software and target appliance, whether Zero Access to destructive actions is enforced, and whether protected objects can still be modified through administrative modes or permissions. Another important question is whether the vendor can provide independent validation of those claims. Ultimately, organizations should not take the word “immutable” at face value; they need evidence that the backup environment remains protected even when every other layer of defense has been compromised.

VMblog: Data sovereignty and regulatory requirements are becoming increasingly important as organizations decide where and how sensitive data is stored. How should concerns around data residency, sovereignty and organizational control influence an enterprise’s backup and recovery architecture, particularly when choosing between on-premises and cloud-based approaches?

Cusimano: Data sovereignty can reduce dependency on external providers, strengthen compliance efforts and give organizations greater control over how sensitive information is accessed and governed. But sovereignty addresses only one side of the equation: if it solves the access problem, resilience and recovery solve the availability problem. Ransomware does not discriminate based on where data is hosted, so moving data to sovereign infrastructure does not automatically ensure that it can be recovered after an attack. Organizations need an architecture that supports both control and recoverability, with immutable backups that preserve a clean recovery point even if credentials are compromised. Absolute Immutability strengthens that model by ensuring backup data cannot be modified, encrypted or deleted, while purpose-built on-premises backup storage provides strong alignment with the strictest interpretation of data sovereignty.

VMblog: One of the more striking findings is that 39% of IT leaders said a successful cyberattack compromising their backup environment would be the biggest reason to change backup storage outside the normal refresh cycle. How can security leaders make the business case for strengthening recovery infrastructure before an incident forces the decision?

Cusimano: The first step is to shift the conversation from the cost of replacing backup infrastructure to the business cost of major data loss and extended downtime. The research shows that recovery outcomes are already deteriorating, with organizations experiencing rising data loss, longer outages, and missed RPO and RTO targets. Waiting until the next normal hardware refresh could mean delaying change for multiple years, even as the threat environment continues to worsen. Organizations should actively weigh that risk against the cost of moving sooner to ransomware-proof backup storage. Only 4% of respondents said nothing would cause them to consider an off-cycle refresh, which suggests there is an opportunity for security leaders to build a compelling case before an incident occurs. The goal should be to make recovery infrastructure an intentional resilience investment, rather than waiting for a successful attack to force the decision.

##