Sean Deuby, Principal Technologist of Semperis discusses World Backup Day in this ISJ exclusive.
It’s been 15 years since the first World Backup Day, and it’s fair to say times have changed somewhat.
While the very first event was precipitated by a user losing their hard drive, today the narrative has evolved into warnings primarily about ransomware.
This distinction matters because the threat landscape in 2026 is an unforgiving place that demands businesses place a renewed focus on cyber-resilience.
A watertight backup and recovery strategy must sit right at the heart of these efforts, and its identity systems have to be restored first if disaster strikes.
Why resilience matters
While Semperis’ 2025 Ransomware Risk Report found slight decreases year-over-year in companies paying ransoms.
It’s still causing enough trouble to make boardrooms sit up and take notice.
Ransomware-as-a-Service (RaaS) and initial access brokers (IABs) have lowered the bar for opportunistic extortionists.
AI is doing the same by upskilling novice cyber-criminals in social engineering, victim reconnaissance and even vulnerability research and exploitation.
They have the advantage of surprise and a large and growing cyber-attack surface to target.
Increasingly, they don’t even need malware: the cyber-crime underground is overflowing with compromised credentials.
Infostealer malware led to the estimated theft of over 1.8 billion credentials in the first half of 2025 alone, according to one report.
Once inside networks, attackers waste no time. One study suggests the average breakout time is down to just 34 minutes.
Don’t be fooled either that ransomware is not raking in as much cryptocurrency.
Even if organisations manage to pull the plug before their adversaries can encrypt data, as Co-op Group did last year, they may still be hit by business interruption, reputational damage and the cost of incident response and recovery.
If they don’t detect an intrusion quickly enough, the impact could be even worse.
Marks & Spencer has already seen profits for the first half of 2025 wiped out by a ransomware breach last Easter. According to the Cyber Monitoring Centre (CMC), average daily spend plummeted 22% in the weeks that followed.
Co-op, meanwhile, lost a reported £206 million in sales following the cyber-attack in April 2025, despite narrowly avoiding ransomware being deployed in its networks.
Understanding the minimum viable company
With threat actors holding many of the ace cards, and security breaches potentially this damaging, many boards are starting to embrace the idea of a Minimum Viable Company (MVC).
This is a relatively new approach to resilience, which starts by defining the smallest version of the company that must continue operating for it to survive an incident.
It looks at the essential services that must be kept running, the internal processes and the people that support those services, as well as the tier-zero infrastructure required to make this possible.
This helps organisations understand where their preventative security efforts should be focused and then which systems to prioritise for recovery.
Tabletop exercises help guide them through this process, working out what matters most to ensure survival at all costs.
Identity comes first
No matter what type of organisation it is, identity systems must be among the first to be restored following a serious security breach.
That’s because they’re usually the first to be compromised after an intrusion – enabling adversaries to achieve persistence, privilege escalation and access to high-value assets.
In this context, backing up is important but recovery of identity systems to a trustworthy state is critical.
No other part of the business can function until users can authenticate and log on.
According to our data, 83% of attacks compromise identity infrastructure, yet two-fifths (40%) of organisations do not maintain dedicated, Active Directory (AD)-specific backup systems.
That’s a worrying statistic when you consider that 84% were targeted in the previous 12 months.
Although AD is included in 66% of disaster recovery plans – which is still too low – the figure drops even further for Entra ID (55%) and Okta (42%).
The road to AD recovery
What does best practice recovery look like in an AD world? Consider decoupling AD backup from OS and general data backups, as these might have malware on them.
Back up at least two domain controllers per domain in the AD forest for redundancy, storing backups securely and offline or to Azure/AWS blob storage configured for immutability.
It is reccommended back up regularly: 24 hours is common practice.
Some organisations put AD on virtual machines (eg VMware or Hyper-V). If they do so, they should avoid relying on snapshots of the domain controller for AD recovery.
That’s because a forest recovered from snapshots may cause data consistency issues.
If there’s malware on a domain controller when the snapshot is taken, it will be restored too.
Further, hypervisor administrators should also be considered Tier 0 as threat actor control of this environment will quickly lead to control of AD.
Finally, don’t leave AD recovery to chance.
Ensure a disaster recovery plan includes regular testing of AD backup and recovery, especially if the idea is to do this manually.
Manual AD recovery testing is especially time-consuming and requires a high degree of AD expertise, which historically has prevented most organisations from doing it.
Beyond AD
As important as AD is, enterprise identity management increasingly extends beyond these systems.
For organisations operating a hybrid environment, Entra ID is a popular choice.
Then there are third-party platforms like Okta that play an important role in a growing number of companies.
When looking at cloud identity provider backups, you should not assume the providers are backing up your data; until very recently the answer was “no.”
Microsoft has introduced Entra ID backups for a limited set of use cases, but for broader recovery capabilities and expanded use cases, you should investigate more comprehensive third-party solutions.
When managing these cloud identity providers, IT and security leaders should start by ensuring backup retention exceeds expected threat actor dwell time.
The latter now stands at 14 days on average globally, according to Mandiant.
The focus should first be on rapid recovery of security posture, including users and groups, object ownership, conditional access policies, roles and Privilege Identity Management (PIM) and device configuration, among others.
Planning ahead is also vital.
Understand what policies and configurations must be restored first and which apps are needed to get the business back on track, and practice restoring them in tabletop exercises.
Backup without recovery is meaningless
Backing up enterprise data is of course important, but getting this right is only half of the battle.
Backups matter primarily not because they preserve data but because they enable recovery.
As threat actors narrow their focus on identity systems to accelerate and amplify attacks, this is where backup/recovery efforts must start.
“World Backup and Recovery Day” doesn’t quite trip off the tongue, but from a messaging perspective, it’s right on the money.

