Why Cyber Recovery Now Depends on Identity Recovery
by Zachary Symm, Product Manager at Rackspace Technology

Recent Posts
Escalado de soluciones de IA en nube privada: de la fase de pruebas a la de producción
Diciembre 4th, 2025
Guía completa para la aplicación del PVC
Noviembre 11th, 2025
Extorsión de datos con IA: Una nueva era del ransomware
Septiembre 2nd, 2025
Move to Azure Without Rebuilding Your VMware Environment
Agosto 15th, 2025
Related Posts
AI Insights
Escalado de soluciones de IA en nube privada: de la fase de pruebas a la de producción
Diciembre 4th, 2025
AI Insights
Guía completa para la aplicación del PVC
Noviembre 11th, 2025
AI Insights
Extorsión de datos con IA: Una nueva era del ransomware
Septiembre 2nd, 2025
AI Insights
El primer paso de la IA es la preparación de los datos. Así es como los usuarios empoderados y las plataformas de datos están dando forma a la próxima etapa de la IA generativa
Agosto 28th, 2025
Cloud Insights
Move to Azure Without Rebuilding Your VMware Environment
Agosto 15th, 2025
Modern ransomware attacks increasingly target the systems organizations rely on to recover. Learn why identity resilience has become a critical part of cyber recovery.
Cyber recovery has long been built around a straightforward assumption: if critical systems and data can be restored from backup, the business can recover from an attack. That assumption still holds true in many environments. But the challenge today is that data is often only one part of the recovery process.
Identity systems such as Active Directory, Entra ID and Okta sit at the center of most enterprise environments. They control access to applications, services and data across the organization. When those systems are compromised, recovery can become far more complicated, even when backups are available.
This is one reason identity has become a growing focus in cyber resilience planning. Restoring data may be relatively straightforward. Restoring trusted authentication, administrative access and identity relationships across a hybrid environment is often much more difficult.
Attackers understand this, and many ransomware groups now target identity infrastructure, backup systems and other recovery dependencies as part of their operations. Their goal is not only to disrupt business operations, but also to make recovery slower and more painful.
These changes are forcing many IT leaders to take a closer look at how identity fits into their recovery strategy and what it would take to restore trusted access after a major incident.
How ransomware attacks have evolved
For many years, cyber recovery focused primarily on data. Attackers encrypted files, demanded a ransom and expected payment. Recovery teams restored from backup and got the business running again. It was painful, but linear.
Today, attackers increasingly target the systems organizations depend on to operate and recover, including identity infrastructure, virtualization platforms and backup environments. Recent research highlights how frequently identity and recovery infrastructure are involved in modern attacks:
- Nine out of 10 ransomware attacks now target Active Directory. Mandiant estimates that the overwhelming majority of intrusions it investigates culminate in domain controller compromise.
- More than 80% of ransomware attacks now involve the compromise of identity infrastructure — Active Directory, Entra ID, or cloud identity providers.
- 88% of breaches involve compromised credentials, according to the Verizon 2025 Data Breach Investigation Report.
- Only 27% of organizations maintain dedicated, Active Directory-specific backups, according to Semperis. The other 73% are relying on general-purpose backup tools that were never designed to recover a Tier 0 identity system.
These trends help explain why identity resilience has become a larger part of the cyber recovery conversation.To learn more about why identity is now the foundation of cyber resilience, download the Identity-First Recovery e-book for insights into modern recovery strategies and best practices.
The case for treating identity as a Tier 0 system
Active Directory is 25 years old. Entra ID is its modern cloud sibling. Okta sits alongside them in many enterprises. Together, these systems do something deceptively profound: they answer the question, “Who is this, and what are they allowed to do?” for every single user, application, service account, API call and AI agent in your environment.
When identity works, no one thinks about it. But, when identity fails, nothing else works:
- Your ERP can’t authenticate users.
- Your Microsoft 365 estate is unreachable.
- Your SaaS applications reject logins.
- Your privileged admins are locked out alongside your end users.
- Your DevOps pipelines, your service accounts, your machine identities — all of it grinds to a halt.
Recovering Active Directory is often far more complex than restoring data from backup. Microsoft’s Active Directory Forest Recovery Guide describes a process that can involve 40 to 100+ discrete manual steps, depending on the complexity of the environment. It requires careful sequencing of domain controllers, FSMO role seizure, replication validation and trust relationship rebuilds.
For CIOs and recovery teams, this complexity can become a significant challenge during a major cyber incident. These tasks must be performed while teams are also managing business disruption, security concerns and broader recovery operations. Done manually and under pressure, Active Directory recovery can take days or even weeks. In many cases, some of the longest ransomware recoveries reported in the press are tied to the complexity of restoring trusted identity systems.
Recovery also requires confidence that the restored environment can be trusted. If Active Directory backups include the operating system layer, organizations may risk restoring persistence mechanisms such as malicious Group Policy Objects, rogue service accounts, backdoors or other attacker-created artifacts. Recovery teams must be able to validate that restored identity systems are functional, secure and free from attacker persistence before returning them to production.
Why identity resilience is gaining attention
Three developments are converging to push identity resilience from a technical concern to a board-level priority.
1. Attackers have professionalized the destruction of recovery infrastructure
The 2026 Mandiant M-Trends report describes attackers compressing virtual hard disks on hypervisors, deploying ransomware at the virtualization layer, extracting dozens of credentials from enterprise vaults in a single session and forcing password resets on privileged accounts to lock defenders out during the incident itself. These examples illustrate how recovery infrastructure has become part of the attack surface.
2. Regulators are catching up
DORA in the EU, the SEC’s cyber disclosure rules in the U.S., NIS2 across European critical infrastructure and sector-specific frameworks in healthcare, financial services and energy are all converging on a common theme: Boards are accountable for operational resilience, not just data protection. The ability to demonstrate that you can recover identity in a tested, documented, repeatable manner is fast becoming a compliance requirement.
3. AI has raised the stakes
AI agents, Copilot deployments and automated workflows rely on identity systems to authenticate users, services and machine accounts. Machine identities now outnumber human identities in most enterprises by an order of magnitude. The blast radius of an identity compromise has grown exponentially, and so has the value of being able to restore it cleanly.
Recovery teams are increasingly focused on more than backup availability. They need confidence that trusted authentication can be restored across the enterprise and that attacker persistence has not been reintroduced during the recovery process. This is where purpose-built identity recovery solutions are beginning to play a larger role.
How Rackspace Identity Vault supports identity recovery
Rackspace Identity Vault combines identity recovery technology from Rubrik with Rackspace managed services to help organizations recover critical identity systems after a cyber incident. It combines Rubrik’s Identity Recovery platform — which uniquely spans Active Directory, Entra ID, and Okta — with Rackspace’s managed services expertise, global data center footprint and 24x7x365 operational support.
At a technical level, the solution delivers:
- Immutable, air-gapped backups of your identity environment: Identity data is captured into logically air-gapped, immutable storage that ransomware cannot encrypt, modify, or delete, regardless of whether the attacker has compromised your production identity infrastructure or your primary backup systems.
- Hybrid identity coverage in a single platform: Most organizations run a hybrid identity estate that includes Active Directory on-premises, Entra ID in the cloud and identity providers such as Okta. Recovering those environments requires coordinated restoration across multiple identity systems. Rubrik is the only platform that protects all three, and Rackspace operationalizes that capability as a fully managed service.
- Clean-room recovery to isolated environments: When identity services need to be restored, they are recovered into a Rackspace-managed isolated environment that is fully separated from production. This reduces the reinfection risk associated with traditional in-place recovery. Domain controllers can be validated and trust relationships restored before reconnecting to the production network.
- Granular and forest-level recovery: Restore a single deleted user, group, application registration or conditional access policy in minutes. For larger recovery events, automated and tested runbooks support full Active Directory forest recovery and can significantly reduce the time and effort required compared to manual processes.
- Rebuilding identity relationships, not just objects: This is subtle but critical. In hybrid environments, identity objects often have dependencies such as application assignments, conditional access policies, group memberships and attributes that synchronize from on-premises Active Directory to Entra ID. Native recycle bin tools can restore individual objects, but they do not restore the relationships around them. Rubrik reconstructs identity end-to-end. This is what makes the difference between a "restored" environment and a functional one.
- Fully managed by Rackspace: View recovery as an operational discipline that incorporates well-defined processes, testing and operational expertise to ensure recovery can be executed effectively. Your security and infrastructure teams are not on their own at 2:00 a.m. on a Sunday; they have a partner who has run this playbook before.
Identity recovery as a managed service
The cyber resilience market is crowded. Almost every backup vendor will tell you they protect Active Directory. Almost every MSP will tell you they offer cyber recovery. So, what makes this combination different?
- Specialization at the right layer: Rubrik Identity Recovery addresses identity recovery as a dedicated discipline rather than an add-on feature. It is the only platform spanning AD, Entra ID and Okta with immutable backup, orchestrated forest recovery and clean-room restoration. Most backup tools treat AD as another workload. Rubrik treats it as the Tier 0 system it is.
- Managed service depth, not just software: Software that no one operates is shelfware in a crisis. Rackspace turns a powerful platform into a 24x7x365 managed service, with the readiness assessments, recovery runbook development, periodic recovery testing and incident response coordination needed to transform a license into an operational capability.
- A complete cyber resilience portfolio: Identity Vault doesn’t sit alone. It is part of a broader Rackspace and Rubrik cyber resilience suite that includes Rackspace Cyber Recovery Cloud (an isolated recovery environment for mission-critical workloads), Rackspace Cyber Recovery Service (cyber recovery for public cloud workloads with Infrastructure-as-Code automation), and Rackspace Data Resiliency for Microsoft 365 (immutable backup for collaboration data). Organizations can start with identity — the highest-leverage point — and extend protection across the full estate.
- Global reach, regulated-industry expertise: Rackspace operates a global data center footprint and supports customers across healthcare, financial services, energy and other regulated industries where data residency, compliance reporting and audit readiness are non-negotiable. Those considerations often extend to identity recovery planning, particularly when the systems being protected are subject to regulations such as HIPAA, PCI DSS, SOX, GDPR, DORA or NIS2.
- Faster time to resilience: Building an identity recovery capability in-house requires sourcing the platform, designing the architecture, developing recovery runbooks, staffing 24x7x365 operations and conducting recovery exercises. For most organizations, that effort becomes a 12-to-18-month program. Rackspace Identity Vault reduces that timeline to weeks.
Identity recovery readiness starts with three questions
In your next leadership meeting, consider asking your team the following questions to help assess your organization's identity recovery readiness:
- If Active Directory and Entra ID were compromised by ransomware, how long would it take to restore trusted authentication across the enterprise based on documented procedures and tested recovery exercises?
- How confident are we that identity services could be restored without reintroducing attacker persistence mechanisms?
- Who is responsible for identity recovery during an active incident, and what processes are in place to support that effort?
The answers can provide valuable insight into current recovery capabilities and help identify areas that may require additional planning, testing or operational support.
If you would like to better understand your organization's readiness, Rackspace Technology can help. Start with a Cyber Recovery Readiness Assessment, schedule a demonstration of Rackspace Identity Vault powered by Rubrik or work with our team to develop a deployment roadmap aligned to your identity environment, recovery objectives and regulatory requirements.
The Value: What This Looks Like on a CFO’s Spreadsheet
The hardest part of the identity resilience conversation is translating it from a technical narrative into business value. Here is how it lands at the executive level.
- Time to recovery, compressed by an order of magnitude: Industry research suggests that organizations without dedicated identity recovery typically need several weeks to fully restore trust in their identity environment after a major incident. With Rackspace Identity Vault, that timeline collapses to hours. If your business loses roughly $X per day during a major outage — a number every CFO can calculate — the math on prevention becomes very straightforward.
- Dramatic reduction in reinfection risk: Clean-room recovery and immutable backups break the loop where organizations restore an environment, declare victory, and find themselves re-encrypted weeks later. According to recent industry data, repeat attacks remain alarmingly common, often because attacker credentials and backdoors were never fully eradicated. Identity Vault breaks that pattern.
- Reduced ransom exposure: Organizations that can credibly recover do not pay. Organizations that cannot, often do — repeatedly. Semperis research has found that the majority of ransomware victims pay, many of them multiple times in a single year. A tested identity recovery capability fundamentally changes the negotiating position.
- Audit-ready compliance posture: Tested, documented, repeatable identity recovery is increasingly what regulators, cyber insurers, and major customers are asking to see. Identity Vault is built to produce the evidence — recovery test results, runbook documentation, and immutability attestations — that those stakeholders require.
- Operational leverage for your team: Your identity, security, and infrastructure leaders should be focused on enabling the business, not architecting forest recovery runbooks at 11 p.m. on a holiday weekend. Rackspace Identity Vault gives those teams a partner, not another tool to learn.
Identity recovery is one part of a broader cyber resilience strategy. Learn how Rackspace Technology and Rubrik help organizations protect and recover identity systems, business data and critical workloads here.
Tags: