And even if most data were backed up, most computers still have to be wiped and reinstalled. I don't think most companies backup the entire disks off all employees, it's normally just a dedicated file area. So while the data can be restored, the IT department still have to set up hundreds of computers for all kinds of different workers or machines on the spot.
Nothing is ever easy, don't be so dismissive about things you haven't thought through.
- It should be easy to reinstall to a known good image with all the relevant software, settings, drivers, etc. then restore the backed up data. This is relatively common in corps.
- Once you observe the malware and know how it reaches the C&C server, you can push rules blocking that host or block the bad binary network-wide.
Of course there will be companies that didn't have good enough system in place and once exploited are doomed.
It should be, but enterprise servers are often the embodiment of configuration drift.
Even if they could comfortably restore a backup from a year prior, they are left with hackers who know how to penetrate their network until they determine how it occurred..
Also replace your IT security provider and/or person.