90% of security leaders say they're confident they can recover from a cyber incident.
Among organizations actually hit by ransomware, 28% got all of their data back. 44% recovered less than three-quarters of it. (Veeam Data Trust & Resilience Report 2026 — 900+ senior IT, security and risk leaders.)
The distance between those two numbers is the distance between a belief and a system. A backup that has never been restored is a belief. It costs money every month, it produces green checkmarks every night, and nobody finds out whether it works until the one day it has to.
The test that settles it — one afternoon, this week:
1.Pick the system whose loss stops revenue.
2.Restore it from backup to isolated hardware. Not "the job log says success" — restore it, boot it, open the data.
3.Time it, end to end. Compare that number to whatever recovery time you've promised customers — or assumed.
4.Write down everything that broke. Something will. That list is your real disaster-recovery plan; the binder on the shelf was the draft.
If you want the fuller standard, it's called 3-2-1-1-0: three copies, two media, one offsite, one immutable — and zero errors in a restore you actually verified. Most companies stop at 3-2-1. The last two digits are where recoveries die: the copy the attacker can't touch, and the test nobody scheduled.
The same report found that organizations that increased security budgets recovered fully 40% of the time, versus 16% for those that didn't. It also found those organizations were likelier to have invested in fundamentals like immutable storage. Two findings, not one causal chain — but they point the same direction.
What changes on Monday: a 90-minute restore test goes on the calendar with a name attached to it. If it passes, you bought certainty for the price of an afternoon. If it fails, it failed on a day you chose — not on the day that chooses you.
Sources
1.Veeam press release, April 14, 2026 — Data Trust and Resilience Report 2026
2.Veeam — The 3-2-1 Backup Rule (3-2-1-1-0)
This is general guidance, not legal or architectural advice for your environment. Recovery obligations and design depend on your jurisdiction, sector and systems.