Cyber-recovery is still a relatively new concept, only coming into prominence as its own distinct discipline over the past decade as cyber-attacks became more frequent and sophisticated. Of course, cyber-threats existed before that, but businesses were getting by with standard disaster recovery plans. While these plans were primarily designed to address incidents such as accidental file deletion and physical disasters like floods or fires, their core objective was the same: restoring lost data and getting systems back up and running.
However, this approach is no longer fit for purpose. The route to recovery is far more complex today than it was ten years ago. As cyber-attacks have evolved, recovering from malicious activity requires additional capabilities so that systems can be restored securely and free from compromise, and importantly in an appropriate amount of time.
Yet, recovery metrics haven’t changed. Recovery Time Objective (RTO) and Recovery Point Objective (RPO) – which measure the maximum amount of time and data that your business can afford to lose during recovery – aren’t obsolete, but they are often set far too high when measured against cyber-threat recovery. Businesses can’t afford days or weeks of downtime. Customers across all industries expect businesses to be ‘always-on’ so any amount of time lost to an attack results in reputational damage and profit loss.
In addition, hitting recovery metrics doesn’t automatically equate to a successful recovery. Unlike previous disaster recovery situations, where data was restored from backups unaffected by the attack, today, businesses cannot be so confident that their backups will be clean. Cyber-criminals increasingly infiltrate backups with malware, trapping organisations in a loop of restoring the very thing that took them offline in the first place.
Threat actors also frequently lay dormant in systems for long periods of time before launching their attacks, making it harder to track exactly where and how they gained access in the first place. An increasingly important part of cyber-recovery, in that case, is to remove all illegitimate access and identify all open back doors or entry points to build confidence that bad actors are out and can’t return.
In summary, a successful recovery today means a clean recovery.
The new kids on the block
To ensure a clean recovery, new methods and measurements are needed. For businesses, this provides an opportunity to reshape how recovery is understood, managed, and planned for – by both business leaders and security teams.
A crucial part of cyber-recovery is identifying and understanding what systems have actually been compromised. This is much more complex than disaster recovery plans, where the disruption is easier to locate – a flooded server room, failed storage system, or a stressed employee who hit delete on the wrong files will give that away! With cyber-recovery, it is much less obvious, especially when threat actors have laid low in your systems for months to identify and plan the best way to attack and disrupt.
So a comprehensive and successful cyber-recovery must start with determining which datasets and systems are clean, and which are not. Modern tools can help with this, identifying where files have been compromised and what the last clean backup was. The most advanced can even pick the clean elements from various files and piece these together to make a new clean file with the most recent data.
But with the average modern business holding petabytes of data, where do you start?
This is where a new acronym comes in. A crucial part of any cyber-recovery strategy is identifying your Minimum Viable Company (MVC). This consists of all the most critical systems, datasets, and a subset of Important Business Services that are required to maintain business operations. What this is made up of will differ from business to business, but it often consists of base technology systems, communication channels, financial systems, and identity and access management databases.
By identifying your MVC beforehand and having the recovery playbook ready, IT and security teams can immediately get started on analysing these areas of the business after an attack – avoiding hours or days of paralysis time that can happen without this prior strategy. The isolated clean versions of these datasets and systems can then be confidently restored knowing that the threat has been contained outside of those that provide minimum operational capability to keep your business afloat.
This simple knowledge of knowing where to begin and what to prioritise cuts downtime to a minimum. This forms another required metric for modern cyber-recovery measurement: Mean Time to Clean Recovery (MTCR).
MTCR shifts focus to a more mature and secure approach to recovery from cyber-events. Complementing the traditional RTO/RPO metrics, it takes measurement a step further to reinforce that recovery is not just done quickly, but also cleanly and safely. By making clean data verification part of the recovery metric, organisations can build repeatable, auditable processes that can contribute to more steadfast and reliable RTO and RPO measures. Remember, RPT/RTO metrics (and others) are absolutely required for BCP/DR, but in order to bring a cyber-event down to those tight measures, MTCR gives you the baseline, and testing, learning and improving, and testing in a continuous cycle allows you to bring the MTCR window down towards the business requirements.
A more secure future
Cyber-recovery is more complex today than it has ever been, and that trajectory continues as we see evolutions in technology such as Frontier AI on the horizon, so businesses must update their security processes and expectations with objectives that reflect the reality of modern recovery.
Yet metrics only go so far. To achieve their MTCR, organisations need tried-and-tested recovery plans. It is not just about defining the MVC in advance, but knowing how to restore it, so that in the middle of a crisis the teams responsible know exactly what to do.
The challenge is that recovery plans are only as effective as the organisation’s ability to execute them under pressure. That is why testing and validation have become essential components of modern cyber-recovery strategies.
Those that respond best during a cyber-attack will have gone beyond tabletop exercises to execute recovery procedures in a simulated isolated environment. This enables risk-free testing and gives organisations the opportunity to identify weaknesses and iron out any issues, while providing assurance that recovery efforts will restore a trusted environment. And to repeat it. And to repeat it.
By making ‘clean’ a key recovery priority, organisations can ensure their plans and objectives are aligned with the cyber-security challenges of today.
Mark Molyneux is Field CTO Northern Europe at Commvault
Main image courtesy of iStockPhoto.com and Dilok Klaisataporn
Click Here For The Original Source
