Key Takeaways

  • Just 16% of surveyed organisations reported their backup environment provides absolute immutability, although 93% consider it critical for ransomware protection.
  • Recovery performance has deteriorated, with only 39% recovering at least 75% of their data after an attack.
  • Independent validation, restore testing, and separation of backup administration are becoming central to resilience planning.

Object First has published commissioned Omdia research highlighting a substantial divide between how businesses value immutable backup storage and the protection they actually have. The survey covered 700 IT decision-makers and business leaders at organisations with 1,000 to 9,999 employees across the US, UK, Ireland, France, and the DACH region.

The headline numbers are stark. Some 93% of respondents said absolutely immutable backup storage is critical to ransomware protection, yet only 16% believed their existing environment met that standard. Omdia calls the difference an immutability gap, reflecting the distance between assumed protection and storage that administrators or attackers using compromised credentials cannot alter or delete.

That distinction matters because backup repositories are increasingly part of the attack surface. Veeam's Data Protection Trends research found that 96% of ransomware attacks attempted to compromise backup repositories, with 76% of those attempts succeeding. Separate ESG/Omdia findings showed that 41% of affected organisations said attackers directly targeted backup infrastructure, making it the most common focus reported.

Meanwhile, attack frequency and recovery performance appear to be moving in opposite directions. In the survey, 83% of organisations said they had experienced a successful ransomware attack during the previous two years, up from 66% in 2024. Only 39% recovered at least 75% of their data, compared with 57% in 2024.

Possessing backup technology does not automatically guarantee a recoverable business. Sophos research found that only 53% of enterprises used backups to restore encrypted data in 2025, down from 73% in 2024. Organisations whose backups were compromised also faced median recovery costs of $3 million, eight times the $375,000 recorded where backups remained intact.

Operational targets show another side of the problem. The researchers found that 64% of organisations experienced an outage exceeding their Recovery Time Objective, while 76% said their largest data-loss incident breached their Recovery Point Objective. Three-quarters of attacked organisations experienced multiple service interruptions. Only 39% maintained an RTO of five days or less, down from 49% in 2024.

When the recovery system shares credentials, administrative paths, or security weaknesses with the production environment it is supposed to rescue, a backup may remain technically present but become deleted, encrypted, corrupted, or operationally inaccessible. CrowdStrike's Ransomware Readiness survey similarly found that nearly 4 in 10 victims could not fully restore lost data from backups after an incident despite having backup solutions.

Supplier trust is therefore becoming part of procurement. Some 89% of respondents said immutability claims need independent third-party validation before they can be trusted. The concern has also reached senior management: 73% of line-of-business leaders and C-suite executives said absolute immutability is required for an effective resilience strategy, while 83% of all respondents described backup storage as ransomware's last line of defence.

Immutability serves as one control rather than a complete recovery programme. CISA's #StopRansomware guidance supports resilient, offline, and immutable backups, alongside approaches such as the 3-2-1 and 3-2-1-1-0 rules. These approaches typically combine multiple copies and storage types with an offline or immutable copy, then add verification that backup jobs completed without errors. NIST-aligned authentication and data-protection controls can further reduce exposure around privileged access.

The principal analyst at Omdia stated that closing the gap between perceived and absolute immutability is important for organisations seeking confidence that data will remain recoverable. The chief executive officer of Object First likewise argued that recovery should not depend on backups that attackers can alter or delete. For buyers, the practical test is increasingly evidence: independently validated immutability, separated administrative control, clean recovery environments, and repeated restoration exercises that demonstrate critical services can return within stated RTO and RPO limits.