94% of SMBs believe they can survive a disaster, but only a quarter are ready

More than 90% of ransomware attacks attempt to delete or corrupt backups before the payload ever fires, and nearly 60% of those attempts succeed, according to a recent report. The fallout extends far beyond the IT department: halted business processes, lost productivity, and permanent customer churn are direct consequences of delayed recovery.
The root cause is a widespread misconception that backup equals recovery. A U.S. Chamber of Commerce report found that 94% of surveyed SMB leaders believed their enterprise would survive a disaster, even though only a quarter had the recovery infrastructure in place. The distinction is not just semantic: backup creates duplicate copies of data, while recovery ensures that after an attack or failure, an organization can restore operations quickly enough to avoid prolonged downtime, lost revenue, and lasting damage to customer trust.
Attackers understand this gap well, often better than their targets. Many threat groups strike backup repositories first before breaching the rest of the IT stack. Organizations that treat backups as their disaster recovery strategy are merely protecting data, not the business itself. A modern approach requires combining immutable backups with rapid recovery capabilities, a principle embodied in platforms like Datto.
Hybrid environments are no longer optional: rising on-premises hardware costs are pushing organizations to move new and refreshed workloads to the cloud, widening the identity attack surface in the process. Attackers no longer need to break through the firewall to reach business applications — they simply log in. They bypass MFA, hijack live sessions, and slip past email security, sometimes after researching targets on LinkedIn for users most likely to hold elevated or administrative access.
About four in five ransomware attacks begin with identity-based methods, and most of these strike backup repositories first, cutting off the only survival route for organizations without a full recovery strategy. This turns recovery readiness from an optional measure into a mandatory standard for cyber resilience.


