The New Measure of Cybersecurity Success Is How Fast You Recover
The security industry spent decades managing only half the risk equation.
Every risk model a CISO has presented to a board has two items. One is how likely the bad thing is. The other is how bad it is when it happens. For about twenty years, security teams put nearly all their money and talent into the first. Firewalls, endpoint agents, vulnerability scanners, email filtering, and threat intelligence all exist to lower the odds that an attacker gets in. The second got a continuity plan, a backup product, and an annual tabletop exercise.
That imbalance is where the 2026 State of Recoverability Report begins. Our new research report combines studies published between 2024 and 2026 by seventeen institutions, including the Cyentia Institute, Accenture, Allianz Commercial, and Munich Re, with field data from more than 500 hands-on ransomware recoveries performed by Fenix24’s breach recovery experts. The industry is changing how it defines success, and the incident data explains why.
The Cyentia Institute’s long-run incident research shows how the imbalance played out. The annual probability of an organization experiencing a significant cyber event has nearly quadrupled since 2008. In 2008, about 450 significant security incidents entered the public record each quarter. By 2024 the figure was roughly 3,000, an increase of 566%. Security spending rose for a decade over that period, and incident frequency rose along with it. Costs rose fastest of all, and by Cyentia’s analysis, cyber events now consume eight times more of a victim’s annual revenue than they did fifteen years ago.
Security programs that concentrate on the probability of impact and leave its severity unmanaged produce exactly this curve. Likelihood kept rising despite the investment, and very little had been built to limit the damage once an attacker got through.
Ransomware has driven much of the growth. In Cyentia’s ransomware research, it accounted for under 1% of reported incidents in 2015 and averaged 52% of monthly reported cyber events by 2023.
Ransomware’s main cost is time. Once it detonates, the business loses money for every hour it can’t operate, through orders that don’t ship, staff who can’t work, contract penalties, and customers who move to a competitor. The attack type now dominating the incident record is the one that prevention-focused programs are least equipped to handle. After the encryption runs, the only variable left is how long recovery takes.
Everyone who prices risk has already adjusted
Breach normalization is now the official stance of every institution that prices cyber risk. Markets, regulators, and customers increasingly treat incidents as an ordinary cost of operating rather than proof of negligence. Security leaders need to build strategies around limiting impact, maintaining operations, and recovering quickly. From a business outcome perspective, mitigation has become functionally equivalent to prevention.
Executives agree. In Accenture’s mid-2026 survey of 1,000 CEOs and CISOs, 87% describe cyber disruption as a recurring operating reality, and 72% say preventing all of it is no longer realistic.
If an incident contained and recovered within hours costs the business about the same as one that never happened, the breach stops being the failure. The failure becomes the gap between the downtime leadership was promised and the downtime the business experiences.
What that means for the person in the CISO chair
Many security leaders still work as though their standing depends on keeping the breach count at zero. Boards have stopped judging them on that. A CISO who told the board recovery would take two days and then spent three weeks restoring the business has a far worse story to tell than a peer who took a ransomware hit, disclosed it, and had operations back the next morning. The second company comes out of it looking well run. Boards, shareholders, and regulators increasingly read a fast recovery as a sign of strength.
Most security leaders are carrying a recovery promise they have little chance of keeping, and many don’t know it. In Fenix24’s client engagements, documented recovery time objectives typically promised 24 to 48 hours. Across more than 800 clients, four came close to that for partial business operations. None reached full operational capacity until several weeks after the incident. The RTO in the plan is usually a number someone wrote down, and in most cases, nobody has ever tested it against the environment it describes.
Absence was never a metric
The old scorecard had a problem deeper than misaligned incentives. Prevention can’t be proven, because a quiet quarter often looks exactly like a lucky one.
Take three companies that each went a full year without a significant incident. The first has excellent controls. The second has an attacker inside its network who hasn’t acted yet. The third was never targeted. A prevention scorecard gives all three the same result, and none of them can tell from that result which company it is. That’s why the industry’s familiar metrics are proxies. Endpoint coverage, patch compliance, and phishing click rates measure activity around prevention, because prevention itself leaves no evidence behind.
Recovery produces evidence. A recovery objective is met or missed, a restore sequence works or stalls, and both can be rehearsed against a clock well before an incident. That’s why resilience became the strategy boards and regulators organize around. It can be measured, and so organizations that claim it can be asked to show the measurement. Resilience that has never been measured is only a position, and a board can’t assess a position.
This isn’t permission to stop defending
Some readers will hear “breach normalization” as a reason to spend less on keeping attackers out. That gets the data backwards.
Resistance still determines how often the business has its worst day. Recovery determines how long that day lasts and what it costs. As the annual odds of a significant event keep climbing, more of the total outcome depends on the second term, which is why Fenix24 has long argued that resistance is necessary and recovery is critical.
Resistance and recovery also meet at a specific point. Across more than 500 hands-on ransomware recoveries, Fenix24 has watched attackers go after recovery infrastructure early and on purpose, because an organization that can restore has no reason to pay. The directory is typically the first major system to fall. In 94% of the organizations Fenix24 recovers, backup systems are joined to that same production directory. Protecting backup repositories, isolating identity, and locking down management consoles are all resistance work, but the benefit shows up during recovery. The budget question is where resistance spending goes, and more of it belongs on the systems recovery depends on.
Reading the new definition of winning
The definition of success has changed from “nothing happened” to “it happened, and we were operating again in hours.” Each part of that sentence sets a requirement most organizations haven’t met.
“Operating” refers to the business, not its infrastructure. An organization can restore two hundred virtual machines and still be unable to ship an order or run payroll, because the service depends on something that hasn’t come back yet. That gap separates recoverability from operational recoverability. Individual servers can be recoverable while the business as a whole isn’t, and only the business counts toward the new definition.
“Again” means there is an order. Some systems have to return before anything else can run. Because the directory is usually compromised first, identity typically has to be re-established before any business system can safely return. An organization that hasn’t worked out its recovery sequence ahead of time will work it out during the incident, with the downtime still accruing.
“In hours” means a number that has been measured. The 24- to 48-hour RTO in a continuity plan meets that standard only if a restore has demonstrated it against the current environment. For most organizations, no such restore has ever been run.
Building the instruments
Very few organizations have instrumented the new definition, and the reason is structural. Resistance metrics come with the tools. Endpoint platforms report coverage and scanners report vulnerabilities as part of what they do. Recovery metrics don’t come from any tool by default. They have to be produced by testing, and by keeping an accurate model of how the business depends on its technology.
A scorecard built for the new definition would track, at minimum:
- The demonstrated recovery time for each critical business service, measured in a test and reported next to the stated RTO.
- The date of the last end-to-end restore of that service against current recovery targets.
- The share of that service’s dependencies covered by backups that are current, able to survive a privileged attacker, and restorable within the objective.
- A validated method to authenticate a recovery when the primary directory can’t be trusted.
- A recovery sequence that reflects the environment as it runs today rather than as it was originally designed.
Fenix24 built Argos99 to produce those measurements. It models which business services the organization depends on, what each service depends on, what backup coverage exists, what order recovery requires, and if the stated objectives can be achieved. It updates that model continuously as the environment changes.
You can start with a smaller version of the scorecard today. Pick your most revenue-critical business service and put its demonstrated recovery time next to the RTO in its plan. If no restore has ever produced a demonstrated time, that missing figure is the first item on your new scorecard, and it’s also the number your board is starting to ask for.
Download the full report
The 2026 State of Recoverability Report includes the data behind everything above, plus what the insurance claims record shows about the cost of downtime, how far executive confidence sits from demonstrated recovery, and why recovering from an adversary differs from recovering from an outage. It combines research from seventeen institutions with field data from more than 500 hands-on ransomware recoveries.