In May 2025, napkin manufacturer Fasana became the target of a cyberattack. Within a few hours, core IT systems were encrypted, communication and order processing failed, and production came to a standstill. Just 13 days later, the long-established company was forced to file for bankruptcy.
The incident highlights a key problem faced by many industrial companies: Even if data is backed up, that does not automatically mean that production can resume quickly. There is much more between a successful backup and a functioning production environment than simply restoring individual systems.
Backups are an indispensable part of any IT security strategy. They protect against data loss and make it possible to restore systems after an outage.
However, there is a crucial difference between restoring data and resuming business operations, because a manufacturing company needs more than just backed-up data, it needs functioning processes. ERP systems, databases, user management, network services, and production applications all need to be able to communicate with each other again before operations can fully return to normal.
Disaster recovery describes the entire process of making critical systems and business processes available again following an outage.
Modern production environments consist of numerous interconnected systems. Applications access databases, users require central authentication services, and production systems depend on a functioning IT infrastructure.
Restoring a system in isolation does not automatically mean the processes built on top of it will work. That is why dependencies must be considered, systems must be prioritized, and recovery sequences must be defined in advance.
In an emergency, every hour counts. Companies should therefore determine in advance which systems are particularly critical and which processes must be restored first.
Recovery plans take both technical dependencies and business requirements into account. Not every application needs to be available at the same time. The key is to first restore the systems required for production, logistics, and core business processes.
A clear strategy prevents valuable time from being lost due to unclear responsibilities, missing priorities, or an incorrect recovery sequence.
As the complexity of modern IT landscapes increases, automating the recovery process becomes more important. Manually restoring individual systems is time-consuming and increases the risk of error, especially under high time pressure.
Automated recovery processes help ensure that predefined procedures are executed reliably, dependencies are taken into account, and critical systems are prioritized. This transforms a simple backup strategy into a comprehensive approach to business continuity and cyber resilience.
However, even the best recovery plan is only reliable if it is reviewed regularly. Disaster recovery tests reveal whether processes work, whether documentation is up to date, and where potential weaknesses lie.
The cyberattack on Fasana makes it clear that the real challenge often lies not in the backup itself, but in the recovery process. A successful data backup is a prerequisite for restoration, but it does not guarantee that production can resume.
Companies that understand their systems, document dependencies, plan recovery processes, and test them regularly create the foundation for restoring business operations as quickly and reliably as possible after an outage.
Because in an emergency, the question is not just whether a backup exists, but how quickly it can be used to restore production operations.
The story of Fasanа shows how quickly a cyberattack can disrupt business operations. Let’s talk about how you can make your IT more resilient and optimize your recovery processes.