Does your disaster recovery plan survive ransomware?
A disaster recovery plan built for fires and power cuts often fails against ransomware, because attackers go after the backups first. A plan that holds up keeps at least one copy offline or immutable, sets a recovery time and recovery point for each system, and proves them with regular test restores. According to Sophos, when backups were compromised the median recovery cost was $3 million, against $375,000 when they were not.
Why does ransomware break a normal disaster recovery plan?
A traditional disaster recovery plan assumes the disaster is physical: a flood, a failed array, a lost site. The backups sit somewhere else and are fine. Ransomware is different, because the attacker is already inside your network and can reach anything your administrators can reach, including the backup server.
CISA's #StopRansomware Guide says it plainly: ransomware hunts for and deletes backups, so keep offline, encrypted backups and regularly test restoring them. The numbers back that up. In Sophos's 2024 survey of state and local government, 99% of attacks tried to compromise backups, and 51% succeeded.
That is why the backup question now decides the outcome. Sophos found that organizations whose backups were compromised had a median recovery cost of $3 million, eight times the $375,000 for those whose backups survived.
How bad are ransomware attacks right now?
Sophos's State of Ransomware 2025 surveyed 3,400 victims in 17 countries in early 2025:
- Average recovery cost was $1.53 million, excluding any ransom, down from $2.73 million the year before.
- Nearly 50% paid the ransom; the median payment was $1 million.
- Only 54% used backups to restore, the lowest in six years.
- 53% fully recovered within a week; 18% took more than a month.
- The most common root causes were exploited vulnerabilities (32%) and compromised credentials (23%).
The 2026 edition focused on organizations with 100 to 5,000 employees (2,158 respondents). Data was encrypted in 56% of attacks, the median ransom was $769,000, average recovery cost was $1.7 million, and only 1 in 3 smaller organizations stopped the attack before encryption.
Local government and healthcare
In the 2025 survey, state and local government paid the highest median ransom of any sector, $2.5 million; healthcare paid the lowest, $150,000. Sophos's most recent dedicated state and local government report we could find is from 2024: 34% were hit, 98% of attacks encrypted data, and mean recovery cost rose to $2.83 million from $1.21 million. For a city or county, the disaster recovery plan is not an IT document; it decides whether residents can pay a bill or get a permit next week.
What are RTO and RPO, and how do you set them?
Two numbers turn a disaster recovery plan from a hope into a specification. NIST SP 800-34 defines them:
- Recovery time objective (RTO): "the overall length of time an information system's components can be in the recovery phase before negatively impacting the organization's mission." In plain terms, how long can this system be down?
- Recovery point objective (RPO): "the point in time to which data must be recovered after an outage." In plain terms, how much recent data can you afford to lose?
Set them per system, with the people who run the business, not just IT. Payroll and your ERP may need an RTO of hours; an archive of old project files can wait days. The tighter the numbers, the more the recovery setup costs, so the tiering is where the budget conversation belongs.
| Tier | Example systems | What it usually needs |
|---|---|---|
| 1: must run | ERP, billing, dispatch, core databases | Replication to a second site with tested failover |
| 2: needed this week | Email, reporting, document management | Frequent immutable backups and a rehearsed restore |
| 3: can wait | Archives, test systems | Offline backups, restored when tiers 1 and 2 are back |
What kind of backups survive a ransomware attack?
Start with CISA's 3-2-1 rule: keep 3 copies of your data, on 2 different media types, with 1 kept offsite. Then add what ransomware specifically demands:
- Offline or immutable copies. Recent CISA advisories say backups should be "encrypted, immutable… and cover the entire organization's data infrastructure." Immutable means nobody, including an attacker with admin rights, can change or delete the copy until its retention period ends.
- Separate credentials. Compromised credentials were the root cause in 23% of attacks in Sophos's 2025 data. Backup systems should not share logins with the network they protect.
- Whole-infrastructure coverage. Servers alone are not enough. Include configurations, identity systems and anything needed to rebuild.
- Tested restores. A backup you have never restored is an assumption. Only 54% of victims in the 2025 survey restored from backups at all.
What does a ransomware recovery look like when the plan works?
One case from Liberty Center One, the Royal Oak, Michigan data center we work with: it restored the databases and the entire computing infrastructure of a municipality after a ransomware attack. In a separate case, it made a 100 TB storage array available to a customer within 24 hours. Both are summarized on our results page.
Cost is usually the objection to a real second site, so here is a published comparison. One organization was told by Microsoft and Amazon that a disaster recovery service would cost more than $1 million a year; Liberty Center One's alternative came in at about 75% less. The same provider backs up every virtual machine by default: nightly snapshots kept for 30 days in-region, plus snapshots every 4 hours copied to a second region, immutable and encrypted. That is the kind of design that survives an attacker who goes looking for the backups.
The point is not the speed on its own. It is that recovery was possible without paying. Nearly half of Sophos's 2025 respondents paid.
How do you start a ransomware-ready disaster recovery plan?
You can make real progress this quarter:
- List your systems and tier them, with an RTO and RPO for each, agreed with the business owners.
- Check each backup against 3-2-1 and ask of every copy: could an attacker with our admin password delete this?
- Run a real restore of one tier-1 system to a clean environment, and time it against its RTO.
- Write down who decides during an incident: who declares it, who calls counsel and insurers, who talks to staff or residents.
- Close the common doors: patch exploited vulnerabilities and put stronger authentication on remote access and admin accounts.
- Decide whether a second site is worth it for tier 1, run by you or by a provider.
If you want that second site handled for you, Liberty Center One's disaster recovery offers 5-minute failover with one-click self-service, and its engineers are available 24/7. We introduce companies and public bodies to it; Liberty Center One pays us if an engagement goes ahead, and you pay us nothing. The details are on our infrastructure page.
Sources
- Liberty Center One, "Disaster Recovery" and "Automatic Data Protection" pages (libertycenterone.com, accessed September 2026)
- Sophos, "Nearly half of companies opt to pay the ransom, Sophos report finds" (June 2025)
- Sophos, "The State of Ransomware 2025" (June 2025)
- Sophos, "The State of Ransomware 2026" (2026)
- Sophos, "The State of Ransomware in State and Local Government 2024" (2024)
- Sophos, "The Impact of Compromised Backups on Ransomware Outcomes"
- CISA, "#StopRansomware Guide" (May 2023)
- CISA, "#StopRansomware: Interlock" (advisory AA25-203A, July 2025)
- CISA, "Data Backup Options"
- CISA, "Back Up Government Data" (state, local, tribal and territorial government)
- NIST CSRC Glossary, "Recovery Time Objective"
- NIST CSRC Glossary, "Recovery Point Objective"