“Can you actually prove a business will recover?”
Sure, you can show that you passed recovery tests. But can you prove or otherwise demonstrate true business resilience capabilities? The nuance lies in confidence level you can instill in your executive team.
Traditional resilience updates — meeting RTO targets, successfully restoring backups, or passing DR tests in isolated environments — are not inherently bad. They simply no longer go far enough. The former describes motion and IT mechanics. Today’s executives need to understand whether their business will survive a cyber threat.
Those two are not the same.
Ransomware has changed the game. No longer is resilience simply about recovering from a disaster (e.g., storm or earthquake) with an easy rebuild and restore. Today, resilience teams must assume a hostile environment (threat actor) where the backup infrastructure itself is a target; the “last known good” state is difficult to identify; and recovery must happen during an ongoing and active criminal investigation.
The executive team wants to know if data can be trusted after a major breach. If the attacker is truly and completely out of the environment. And, whether core business functionality has been fully restored. Then comes potential legal and financial fallout. Can the business defend the recovery steps and processes to regulators and cyber insurance providers. Have they lost shareholder and customer confidence?
Here are five steps we recommend our clients follow to modernize their resilience strategy and prove recovery to their executive team:
When you present clear evidence of successful disaster recovery, working business systems, strong cybersecurity measures, and who’s responsible for what, the discussion shifts. Trust increases.
Leaders start asking forward-thinking questions instead of doubting ones. They’ll feel confident that the company can fight off sophisticated cyberattacks, survive a real security incident, and keep running.
The best teams won’t be those that simply test the most. They’ll be the ones that can clearly and consistently prove the business will make it through the next attack.
Learn how to modernize your business resilience plans.
Sherri Flynn
Principal Business Resilience Consultant,
GuidePoint Security
Sherri Flynn is a Business Resilience professional with over 20 years of experience in the field of Business Continuity Management. Throughout her career, Sherri has developed comprehensive Business Continuity Programs, Crisis Management Programs, led Corporate Awareness Training initiatives, and developed and facilitated Exercise programs tailored to diverse audiences, including employees at all levels, strategic committees, Senior and Executive Management, and Board of Directors.
Sherri currently works for GuidePoint Security as Principal Business Resilience Consultant. Her certifications include Master Business Continuity Professional (MBCP) and Certified Cyber Resilience Professional (CCRP) from DRI International, ISO 22301 Lead Implementer and Certified Information Security Manager (CISM) from ISACA.
Sherri is a past recipient of DRI’s Consultant of the Year award.