Most large organisations are terrified of being hit by a cyber attack. The headlines are all too familiar… “Company X hit by ransomware attack.”
The attack sounds like the disaster. It isn’t.
The disaster is what happens next – the 24 days offline. The restore that fails again and again. The backup that was “successful” every single night for a year and still won’t come back clean. Attacks are a single, dramatic event. Recovery is where businesses actually die, slowly, in front of their customers, their staff, and the board.
If you want to know whether your organisation will survive a cyber-attack, you need to start asking one question: Do you know for certain that you can get your critical systems back?
The numbers should scare you more than the attack does
- Ransomware attacks rose 50% in 2025, hitting nearly 7,900 publicly claimed incidents – and 2026 is running over 30% hotter still.
- The average ransomware incident now costs $5.08 million once downtime, remediation and lost business are taken into account.
- Enterprise downtime runs at roughly $300,000 per hour. For mid-market businesses, it’s still $50,000 – $100,000 an hour. That’s not a bad quarter – that’s a business unravelling in real time.
- Only 53% of organisations fully recovered within a week in 2025. Read that the other way round: nearly half of all businesses hit are still not operational seven days later.
Here’s the one that should really keep you up at night: Predatar has found previously undetected malware inside the backups of more than 90% of its customers – organisations that, in most cases, already had best-in-class security stacks. Not gaps in defence. Gaps in the thing everyone assumed would save them.

The lie of the green tick
For too long, the entire backup industry has run on an assumption that nobody ever stress-tests: if the backup job reports success, recovery will work too.
The reality is that a backup platform can report a clean green tick every night for a year and still fail you on the one day it matters. Restore jobs stall halfway through. Recovery performance collapses under load. Authentication breaks. Application dependencies don’t hold. RTOs that looked good in a slide deck turn into days, or weeks, once you’re actually trying to bring a production estate back from nothing.
Under normal conditions, roughly 8% of backups fail to recover. During an actual cyberattack – with corrupted volumes, dormant malware, and infrastructure under strain – that failure rate can explode ten-fold, to as high as 84%.
That gap between what businesses assume they can recover and what they can actually recover has a name: the Recovery Gap. Most organisations don’t know theirs exists until the worst possible moment reveals it – when production is already down and the safety net is full of holes.
Your SLA is not a recovery plan
Somewhere in a contract, there’s a number: an RTO of 4 hours, an RPO of 15 minutes, a vendor SLA with financial penalties attached if it’s missed. It feels like protection. It isn’t proof of anything.
An SLA is a promise. A guarantee is a sentence in a document. Neither one has ever actually restored a single terabyte of data at 2am while your board is asking for hourly updates and your customers are finding out on social media. SLAs describe what’s supposed to happen. They say nothing about whether it will.
The businesses that go dark for weeks after an attack almost always had a DR plan. Almost always had backups. Almost always had an SLA. What they didn’t have was evidence – tested, current, repeated evidence – that any of it actually worked under real conditions.
Confidence isn’t a feeling. It’s a test result.
There’s a reason ransomware payments fell 35% year-on-year even as attacks kept climbing: more organisations are refusing to pay. Not because they’re braver. Because they’ve actually tested their recovery and know it holds up. When you can prove you’ll get your systems back without the attacker’s help, their entire leverage disappears.
That’s the shift that matters here. Stop asking “do we have backups?” That question was solved a decade ago and it was never the right one. Start asking: “Have we proven – recently, repeatedly, under realistic conditions – that we can recover, that recovery lands inside our RTOs, and that what comes back isn’t still infected?”
Hoping your recovery plan works is not a strategy. It’s a bet on the worst day of your business’s life, placed on evidence you’ve never actually checked.
Backups you haven’t tested aren’t a safety net. They’re an assumption wearing a safety net’s clothing. The businesses that walk away from an attack aren’t the ones with the best-worded SLA – they’re the ones who already knew, beyond doubt, exactly how fast and how clean their recovery would be, because they’d proven it before the attackers ever showed up.
It’s time to get recovery confident!
Don’t find out which one you are during an incident. Find out now.
Discover Recovery Assurance from Predatar