Object First released a commissioned Omdia study revealing that 83% of organizations experienced a successful ransomware attack within the past 24 months. The research also found that recovery is becoming more difficult, with just 39% of organizations recovering at least 75% of their data after an attack, down from 57% in 2024.
The Omdia Research survey reinforces that outages from ransomware are no longer a matter of “if”, but “when”, and that organizations are increasingly prioritizing provable recovery from absolutely immutable backup storage as the ultimate defense. According to Omdia, “Absolute Immutability means that no one can modify or delete backup data, not even the most privileged admin at an organization or an attacker with access to all IT secrets.” 93% of leaders surveyed consider Absolute Immutability as a critical backup storage requirement, yet only 16% say their current backup storage environment meets this standard, suggesting an “immutability gap” is putting organizations at increased risk.
Key Omdia Research Findings
- Technology leaders are losing ground to ransomware attackers: 83% of organizations fell victim to a successful ransomware attack in the last 24 months, up from 66% in 2024. Of those attacked, 75% experienced multiple service interruptions.
- Data recoverability is declining: Only 39% recovered at least 75% of their data after an attack, down from 57% in 2024. 76% reported their largest data loss event exceeded their Recovery Point Objective (RPO) targets.
- It’s taking longer to restore operations: 39% maintained a Recovery Time Objective (RTO) of five days or less, down from 49% in 2024. 64% experienced an outage that exceeded their RTO targets.
- Absolute Immutability is essential for effective recovery: 83% view backup storage as the last line of defense against ransomware, and 93% want backup storage with Absolute Immutability, but only 16% said their backup storage meets that standard. · Vendor claims require independent proof: 89% say vendor claims of immutability cannot be taken at face value and require third-party validation before they can be trusted.
- Line-of-Business and C-Suite executives want business resilience: 73% of line-of-business leaders and executives view backups with Absolute Immutability as a requirement for an effective enterprise resilience strategy.
”Ransomware can lead to a business continuity crisis, and the data shows that many organizations fall short when it comes to reliable recovery,” said Simon Robinson, Principal Analyst, Omdia. “While most technology leaders recognize the importance of immutable backups, the research points to a clear gap between perceived immutability and Absolute Immutability. Closing that gap is essential for organizations that need confidence their backup data will remain recoverable when attacks occur.”
“When ransomware strikes, recovery can’t depend on backups that can still be altered, deleted, or compromised,” said David Bennett, CEO, Object First. “Omdia’s research reinforces what we hear from our customers every day: absolutely immutable backup storage is the last line of defense against ransomware. Organizations need confidence that even if attackers gain access to IT credentials or compromise production systems, their backup data remains protected and recoverable.”
On Wednesday, September 23, 2026, join Simon Robinson, Principal Analyst, Omdia, and Anthony Cusimano, Chief Evangelist and Senior Director of Solutions Marketing, Object First, to learn why closing the immutability gap is critical to recovering from and limiting the impact of ransomware attacks.
Related News:
Top 10 File and Object Storage Platforms
World Backup Day 2026 : Recovery and Resilience
About the Research
Omdia surveyed 700 respondents at organizations in the US, UK, Ireland, France, and the DACH region with 1,000–9,999 employees between February 26–March 25, 2026. Respondents included 500 IT decision makers influential in cybersecurity, data center infrastructure, and BC/DR purchasing, plus 200 line-of-business leaders (director level and above) familiar with their organizations’ BC/DR and cybersecurity policies.