The ability to recover immutable backup data is now one of the most decisive factors in whether an organization can recover from a ransomware attack. Prevention alone isn’t enough, and Omdia’s latest research—commissioned by Object First—shows that many organizations are struggling to recover quickly, cleanly, and confidently when attacks occur.
The results show that cyber recovery is getting harder, attacks are becoming more disruptive, and the gap between perceived data immutability and actual protection is widening.
This blog highlights a few of the most important findings, but it only scratches the surface of what we discovered. If you want the complete dataset, analysis, and recommendations, you can download the full Omdia eBook or grab the executive one‑pager for a quick overview.
Cyber recovery is becoming harder to achieve for most organizations
Omdia surveyed 700 leaders across multiple regions and industries. The results show that ransomware attacks are becoming more disruptive and more difficult to recover from. Omdia found that 83% of organizations experienced a successful ransomware attack in the last 24 months. Many of those organizations were hit more than once, and 87% reported measurable business disruption. These disruptions affected customers, employees, and partners, showing how deeply cyber recovery challenges impact operations.
Line‑of‑business leaders are increasingly aware of these risks. 96% said attackers regularly target backups, which makes cyber recovery even more difficult when production systems are compromised.
Organizations are recovering less data post-attack
Omdia discovered a noticeable drop in recoverability compared to earlier research. In 2024, 57% of organizations recovered at least three quarters of the data affected during an attack. But in 2026, that number fell to 39%. Cyber recovery depends on having clean, intact backups, but attackers are increasingly corrupting or destroying backup data to prevent restoration.
Participants in the study also reported that their recovery objectives are slipping. 76% experienced data loss that exceeded their RPO targets, and 64% faced outages that lasted longer than their RTO targets. For reference, these trends point to cyber recovery challenges that stem from compromised or incomplete backups rather than from process or staffing issues.
Cyber recovery depends on having backup data that hasn’t been altered, deleted, or stolen. It has to be tamper-proof and absolutely immutable. When attackers gain access to backups, recovery becomes slow, unpredictable, or impossible.
What is the immutability gap and how does it affect cyber recovery?
The “immutability gap” refers to the significant gap between what leaders expect from their backup storage and what their systems actually provide. 93% of technology leaders said backup storage must prevent deletion or modification even if credentials are compromised. Only 16% said their current storage meets that requirement.
Many organizations rely on solutions that appear immutable but still allow administrative access to backup data or provide delayed protection. These loopholes are detrimental weaknesses. They create opportunities for attackers to alter or remove backup data, which directly affects cyber recovery outcomes. Fireproof cyber recovery requires backup storage that cannot be changed under any circumstances.
Strengthening cyber recovery with Absolute Immutability
Object First created Ootbi to address the immutability gap. With Absolute Immutability at the storage layer, organizations gain backup data that remains protected even if attackers gain access to credentials or compromise production systems. Our solution supports reliable cyber recovery and helps reduce the risk of extended outages or unrecoverable data loss.
If you want to understand how Absolute Immutability supports cyber recovery, the Omdia research provides a detailed breakdown of the trends and risks. Download the eBook to learn more.
