Skip to content
Cyber Resilience & Data Security

Recovery-Ready or Just Recoverable?

Many organizations have invested heavily in protection and recovery capabilities, but few can confidently demonstrate that they can recover from a disruptive cyber event.


For years, resilience conversations have centered on technology. Do you have backups? Do you have a disaster recovery plan? Do you have protections in place to prevent an attack? 

Those remain important questions. But increasingly, they’re not the ones I’m hearing from executives. 

Instead, I’m hearing a much simpler question: If we experience a cyberattack tomorrow, can we come back from it, and can we prove it?  

NewIDC research, based on a survey of 539 IT and resilience decision makers across the U.S. and Canada, reveals a growing reality: Having recovery technology doesn’t automatically make an organization recovery ready. 

Recently, I joined Jason Cray from Commvault’s Product Experience team to discuss that research from IDC. What emerged from our conversation wasn’t simply a discussion about backup, recovery, or cyber resilience.  

It was a discussion about confidence. More specifically, why so many organizations believe they’re recoverable, but struggle to prove they’re actually recovery ready. 

Regardez laRecovery Readiness Webinar On Demand. 

Points clés à retenir 

  • The difference between being recoverable and recovery ready is like the difference between theory and proof. 
  • IDC found that 57.7% of organizations have not fully defined their minimum viable business. If you don’t know what you need to recover, how can you prioritize what needs to come back up first? 
  • Recovering everything is not a viable strategy. Successful recovery depends on prioritization and business context. 
  • Cyber recovery requires a team approach to be successful.  
  • The fundamental difference between cyber recovery and disaster recovery is the need for trust. 
  • Speed may not be the best measure of recovery, especially if you can’t trust your backups. 
  • Organizations build confidence through testing, not planning alone.  
  • ResOps provides a framework for turning resilience into an operational discipline. 
What’s the Difference Between Being Recoverable and Being Recovery Ready? 

A few years ago, many resilience discussions ended with a checklist. 

  • Backups? Check. 
  • Recovery plan? Check. 
  • Disaster recovery testing? Check. 

Today, that level of assurance is no longer enough. 

During the webinar, Jason shared a perspective I hear frequently from customers: Organizations can usually tell you exactly how much they invest in security and protection technologies, but far fewer can confidently explain how they would recover if those controls failed.  

The distinction may sound subtle, but it’s important. 

Being recoverable means you have mechanisms in place that could support recovery. Being recovery-ready means you’ve demonstrated those mechanisms can successfully restore critical business operations under real-world conditions. 

As resilience becomes a board-level concern, assumptions are giving way to evidence. Leaders want confidence that recovery plans will actually work when the pressure is at its highest. 

When the Chips Are Down, Does Your Organization Know What Matters Most? 

One of the most striking findings from theIDC researchis that57.7% of organizations have not fully defined their minimum viable business. 

A minimum viable business isn’t simply a list of critical applications. It’s the combination of people, processes, systems, and data required to keep the organization functioning during disruption. It answers a critical question: What absolutely must come back first? 

This is where many recovery strategies begin to fall apart. 

I’ve worked with organizations that understand which applications are important but haven’t mapped the dependencies supporting them. Others continue treating nearly every workload as mission critical. While that approach might seem prudent, it creates a practical problem during recovery. 

When Everything Is Critical, Nothing Is 

Recovery takes time. Infrastructure has limits. Dependencies matter. 

Organizations cannot realistically expect to recover an entire multi-petabyte environment immediately following a large-scale cyber event. Prioritization becomes essential. 

The organizations that recover most effectively tend to know exactly what must come back first, what can wait, and what business outcomes depend on those decisions. That’s what defining a minimum viable business enables. 

Sneak Peek: Recovery Readiness Webinar 

One of the themes Jason and I explored throughout the webinar is the fact that cyber resilience is a shared responsibility. There’s a disconnect in many organizations that recovery readiness is an infrastructure challenge. It is not; it’s an organizational challenge. It requires alignment across security, IT, legal, communications, and business teams to confirm critical applications, processes, and recovery priorities are clearly understood before disruption occurs. 

Recovery Plans Fail in Silos 

Many organizations still approach resilience through disconnected teams. Infrastructure teams focus on systems. Security teams focus on threats. Business leaders focus on continuity. Legal and communications teams often become involved only after an incident occurs. 

The problemis thatdisruptions don’t respect organizational boundaries. 

Successful recovery depends on coordinated decision-making across all of those functions. Recovery priorities, customer communications, business operations, legal obligations, and technical restoration efforts must all work together in real time.  

One customer recently described their resilience planning efforts as building a team of superheroes. While they meant it jokingly, it perfectly captured the reality of modern recovery readiness. Organizations recover as teams, not technologies. 

Why Cyber Recovery Is Fundamentally Different From Disaster Recovery 

One misconception we discussed during the webinar is the belief that traditional disaster recovery plans can simply be adapted for cyber recovery. 

In reality, they solve different problems. 

Traditional disaster recovery was often built around predictable failure scenarios. A site outage. Infrastructure failure. A known disruption that triggered a documented response. Cyber events are fundamentally different. 

Organizations must determine what systems have been compromised, what data can be trusted, and whether recovery actions could inadvertently reintroduce risk. The challenge isn’t simply restoration. It’s validation. 

You can’t restore what you can’t trust. That uncertainty creates a very different recovery process. 

If organizations restore compromised systems or infected data, they risk bringing the problem back into production. As attacks continue to grow in sophistication, validating the integrity of recovered environments becomes increasingly important. 

Recovery is no longer just about bringing systems online. It’s about restoring trust. 

Why Trust Matters More Than Speed: A Fast Recovery Can Still Be a Failed Recovery 

That brings us to one of the most important points from our discussion. For years, recovery success was largely measured by speed. 

  • How quickly can systems be restored? 
  • How quickly can operations resume? 

Those questions still matter. But speed alone is no longer enough.  

A recovery that reintroduces malware, compromised identities, or untrusted data into production isn’t truly successful. That’s why more organizations are investing in isolated recovery environments, validation exercises, and recovery testing designed to verify the integrity of recovered assets before they return to production.  

Recovering quickly only matters if you’re recovering something you can trust. 

MTCR: The NewMeasure of Recovery Confidence 

As organizations rethink how they measure resilience, many are moving beyond traditional recovery time objectives (RTOs) and recovery point objectives (RPOs). 

Instead, they’re focusing on mean time to clean recovery (MTCR).  

What makes MTCR valuableis thatit reflects the realities of modern cyber recovery. It’s not just about how quickly an organization restores data. It includes the time required to validate, assess, and confidently return systems to production.  

That distinction matters because organizations don’t simply recover infrastructure. They recover business operations. MTCR better reflects how quickly the organization can safely return to a trusted operating state. 

Confidence Comes From Testing 

If there’s one lesson I’ve learned from working with organizations across various stages of resilience maturity, it’s this: Confidence doesn’t come from documentation. 

Confidence comes from testing.  

Static recovery exercises often validate known processes under ideal conditions. Real-world disruptions are rarely that predictable. 

Recovery-ready organizations test continuously. They simulate realistic conditions. They introduce uncertainty. They identify dependencies. They uncover weaknesses before attackers do.  

Most importantly, they build organizational muscle memory. 

During the webinar, Jason shared a perspective I’ve always found compelling: Organizations can choose to figure things out during a period of stability, or they can try to figure them out in the middle of a crisis. The better option is obvious.  

Testing doesn’t simply validate technology. It validates people, processes, communications, priorities, and assumptions. And that’s where real confidence is built. 

ResOps Is What Happens When Recovery Becomes an Operational Discipline 

Throughout our discussion, nearly every challenge we identified pointed back to the same need: Organizations need a way to consistently define priorities, align stakeholders, validate recoverability, and improve over time.  

That’s exactly why resilience operations, or ResOps, is gaining momentum. 

ResOps isn’t about introducing another tool or process. It’s about operationalizing resilience. It brings together people, process, and technology under a common framework for continuous validation and improvement.  

Because ultimately, recovery readiness isn’t a project. It’s a discipline. 

The organizations that will differentiate themselves in the years ahead won’t simply be the ones with recovery technologies or documented plans. They’ll be the organizations that can demonstrate those plans work: 

  • They’ll know what matters most. 
  • They’ll understand how to recover it. 
  • They’ll validate that it’s safe to recover without risk of reinfection 
  • And they’ll have evidence to prove it.  

In other words, they won’t just be recoverable. They’ll be recovery-ready. 

En savoir plus 

The IDC report also found that overall organizational resilience among the organizations surveyed is impaired both by gaps in individual technologies and by the absence of a coordinating framework that brings business, infrastructure, and security functions together around a shared recovery objective. 

For a deeper look at the research: 

FAQ 

Q : Qu’est-ce que ResOps ? R :ResOps (resilience operations) is an operational discipline that helps organizations continuously validate and improve their ability to recover from disruption. It brings together people, processes, and technology to make recovery readiness measurable and provable.  Q: What is a minimum viable business? R :A minimum viable business is the combination of systems, processes, people, and data required to continue operating during a disruption. It helps organizations prioritize recovery efforts when everything cannot be restored simultaneously.  Q: Why is cyber recovery different from disaster recovery? R :Traditional disaster recovery assumes predictable failure scenarios. Because the nature of cyber attacks is unpredictable, cyber recovery requires organizations to change their focus to determining what systems can be trusted, validating recovered data, and ensuring threats are not reintroduced into production environments. Q: What is mean time to clean recovery (MTCR)? R :MTCR measures how long it takes an organization to recover to a verified, trusted operational state. It incorporates recovery, validation, and confidence-building activities rather than focusing solely on restoration speed. Q: Why does recovery testing matter? R :Testing helps organizations uncover hidden dependencies, validate assumptions, build muscle memory, and improve recovery processes before a real disruption occurs. Recovery confidence is earned through practice, not paperwork.  Q: Why is identity resilience important? R :Identity systems play a foundational role in recovery. If users cannot access production systems, recovery environments, or critical data, even the best recovery plans may be difficult to execute successfully.  Q: How can organizations measure recovery readiness? R :Organizations can begin by defining their minimum viable business, testing recovery processes regularly, validating recovered environments, and measuring outcomes using metrics such as mean time to clean recovery (MTCR). 

Vidya Shankaranest directrice technique sur le terrain chez Commvault. 

More related posts


Cyber Recovery

Read more about Cyber Recovery