Searching for That Good Restore Point

What CISOs Want From Data Protection

With a sharp rise in cyber-attacks in recent years, CISOs have become more involved in areas of data management, including backup and disaster recovery.

In interviews with a dozen CISOs and people performing CISO functions we conducted this year, we found all of them were heavily involved in evaluating and purchasing data backup products.

I spoke with the CISOs as part of a research project to determine the tools and processes they use to thwart ransomware and other cyber-attacks. We also conducted a survey of 163 people with CISO responsibilities in large (1,000 employees or more) companies. I wrote about their strategies involving people in their organizations here. In this note, I will address the tools and services they are using now and what is missing.

Cyber-Recovery Wish List

Respondents were more concerned about faster detection than faster recovery. Nearly three-quarters (71%) said faster/earlier detection of a cyber-attack was among their highest priorities for cyber-resiliency analytics. That was by far the highest response. 43% listed faster identification of last-known good recovery point and 41% listed increased confidence that malware was eradicated from the environment. Only 12% said “avoid paying a ransom” and 10% said the ability to preserve good data were highest priorities.

Most of the respondents said they already have data analytics/machine learning (73%) to detect suspicious activity, data loss prevention software (61%), and continuous monitoring for suspicious software (56%).

When asked what capabilities they want but cannot get from their current vendors, responses were evenly spread. The most-cited capabilities were audit data for sensitive content (35%), post-ransomware forensics (29%), continuously monitor for malicious software (29%), storage assessment to find where data resides (27%), rapid cyber incident response (25%), and storage risk/vulnerability assessment (20%). Of nine capabilities and “others” to choose from, only 11% said “none of these,” which indicates few are getting all they need from current tools.

“You’re not doing this by pushing the easy button,” said a cybersecurity adviser and former CISO for a Fortune 500 company. “The challenge in this day and age is knowing where all your structured and unstructured data is, because if I don’t know where it is, I can’t recover. So, you’d just have to write it off and say, ‘We can’t recover that data.’”

“Data forensics is an area of weakness for our organization,” said a CISO of a California-based financial services institution. “That’s the primary area that we’re focused on right now is the forensics.”

He said his firm’s cyber insurance includes forensic services and other tools handle some forensics. Still, he lacks confidence that those tools can identify the entry point of a ransomware attack, which files have been affected, and if the ransomware is still present.

Searching for That Good Restore Point

A few CISOs said they struggled with simplifying the process of finding the last known good copy of data after an attack.

“For us, it’s an estimated guess [at a good recovery point] based on log data and other data points that we have,” said the head of cybersecurity at a US-based poultry farm. “If we have an incident, it’s an exercise where everybody’s coming together and saying, ‘I don’t see this, or I see this here.’ We wouldn’t recover anything unless we were comfortable that we had a known good backup or a known good state.”

In interviews, most CISOs said they could get critical data within a day, but it would take longer – sometimes weeks – to get everything back in case of a severe attack.

A CIO who manages security teams at an oil company said tabletop exercises show his IT team can respond within 24 hours, but his field operations would require 3-5 days to fully recover.

“We can live with a delay of 3 to 5 days,” he said. “Anything beyond that may impact the business. And we have to be concerned about the impact on the outside world. You can lose the trust of your customers.”

The type of attack also has a major impact on recovery time. A major ransomware attack that encrypts data would prove more difficult to recover from than a simple distributed denial of service (DDoS) that knocks systems offline but does not encrypt data. Restore times would also be considerably longer if systems such as Active Directory and Domain Name System (DNS) records are corrupted.

“For our organization, I would expect it to take anywhere from a few hours for a simple DDoS attack to perhaps as much as a week for a significant ransomware attack,” said the CISO of a California-based financial institution. “That would be an absolute worst case scenario.”

Encryption Is Popular for backups, Air Gaps Still Not So Much

For backup and recovery, 64% of the survey respondents said they are encrypting data and 52% are classifying data for ransomware protection. Another 40% said they had instant recovery capability. Only 15% said they were air gapping, which was lowest on the list of nine possibilities.

Among the 24 respondents who are air gapping, 63% are using a disconnected system offsite and 38% a public cloud service.
A VP of infrastructure and security said air gapping is not always easy to set up because it may require a network reconfiguration.

“We don’t have a completely separate network where the backups exist, and you can kind of turn it on and off,” the VP said. “We might need additional hardware for that.”

A credit union CISO said he relies on backups to understand the last-known good copy, but concedes there would likely be data loss if there is a serious attack. He said his company accepts that data saved within the last day may not be recoverable.

“We do full and incremental backups, so we always have an incremental backup to restore to from at least 24 hours prior, along with a full backup to restore to a secondary data center,” he said. “We have a philosophy from a recovery point objective that we may have to lose some data. And that’s OK. Otherwise, you have to go off-site with real-time backups, and that’s very, very expensive. I don’t think many organizations will commit to that.”

Author Information

Dave focuses on the rapidly evolving integrated infrastructure and cloud storage markets.

Latest Insights:
GPT-6 Astra Sharpens Cross-File Bug Detection at a 2.5× Price
September 5, 2026
Article
Article

GPT-6 Astra Sharpens Cross-File Bug Detection at a 2.5× Price

CodeRabbit's evaluation reveals GPT-6 Astra catches 20% more bugs than GPT-5.6 Sol on cross-file reviews, demonstrating superior multi-system reasoning despite premium pricing at $10/M input tokens....
Guidewire FY2026: AI Demand Accelerates the Cloud Transition
September 5, 2026
Article
Article

Guidewire FY2026: AI Demand Accelerates the Cloud Transition

Guidewire closed FY2026 with $1.24B ARR (19% growth) and $1.48B total revenue (23% growth), with AI emerging as the primary catalyst for insurance customers' cloud transition and platform modernization....
Forescout Brings National-Scale OT Security to Water Utilities
September 5, 2026
Article
Article

Forescout Brings National-Scale OT Security to Water Utilities

Forescout Technologies joins Project Watershed 250, a White House and Texas-backed initiative delivering continuous monitoring and AI-enabled defense to water and wastewater utilities across the nation....
OpenAI’s GPT-6 Astra: Benchmarks, Cyber Risks, and Market Impact
September 4, 2026
Article
Article

OpenAI’s GPT-6 Astra: Benchmarks, Cyber Risks, and Market Impact

Nick Patience, VP and Practice Lead, AI Platforms at Futurum, shares his insights on GPT-6 Astra and what its cyber threshold and monitorability trade-offs mean for Anthropic and Google....
Latest Research:
The Platform Payoff How AI Makes the Case for a Unified Enterprise Stack
September 4, 2026
Research
Research

The Platform Payoff: How AI Makes the Case for a Unified Enterprise Stack

In our latest thought leadership brief, The Platform Payoff: How AI Makes the Case for a Unified Enterprise Stack, completed in partnership with Salesforce, Futurum Research examines why enterprise buyers...
Escaping Data Gravity and Infrastructure Debt Why the AI Era Demands an Agentic Data Cloud
September 2, 2026
Research
Research

Escaping Data Gravity and Infrastructure Debt: Why the AI Era Demands an Agentic Data Cloud

In its latest report, Escaping Data Gravity and Infrastructure Debt, completed in partnership with Google Cloud, Futurum Research examines how decoupled data architectures are driving up costs and operational overhead...
Operationalizing Autonomous AI Architecting the Agentic Enterprise on a Converged Data Foundation
August 27, 2026
Research
Research

Operationalizing Autonomous AI: Architecting the Agentic Enterprise on a Converged Data Foundation

In its latest report, Operationalizing Autonomous AI: Architecting the Agentic Enterprise on a Converged Data Foundation, completed in partnership with Snowflake, Futurum Research examines why enterprises must move beyond bolted-on...

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.