For any organisation establishing or refining its cybersecurity strategy, the typical mindset is aligned around prevention and, should the worst happen, a speedy recovery. This is a sensible perspective, with the “when, not if” mindset now firmly established across even the most well-resourced security teams.
Yet, this approach can also mask a serious disconnect between how quickly victims of cybercrime expect to recover and how long the process generally takes. One study found that 72% of business leaders expect to recover from a cybersecurity incident within five days, with 23% aiming to be back in operation within a day or less. In practice, the recovery process is often far longer, with IT leaders reporting that restoring even a minimum level of business operations typically takes between three and four weeks.
Recent high-profile incidents certainly bear this out, with the likes of JLR and Marks & Spencer seeing some or all of their systems offline for weeks and even months on end, with huge financial implications.
Cyber recovery is changing
So, what’s behind this gap? In most cases, the problems aren’t about failures in tools or processes but rather a reflection of changes in the nature of cyber recovery itself. Today, recovery is no longer just about getting back online as quickly as possible; it’s also about making sure that when systems are restored, they are safe to operate and, crucially, can be fully trusted.
As a result, the way organisations measure their recovery effectiveness, standards, and performance is also changing. Traditional recovery metrics such as Recovery Time Objective (RTO), the target time within which systems, applications, or processes must be restored after a disruption, and Recovery Point Objective (RPO), the maximum acceptable amount of data loss measured in time, were designed for a very different risk environment, where disruption was typically caused by physical incidents rather than deliberate compromise.
"It’s essential that businesses adapt and put themselves in the strongest possible position to recover not just quickly but with the maximum levels of integrity. Those who do will be ideally placed to meet contemporary and future security risks head-on."
In these situations, recovery was relatively straightforward because data was restored from clean backups unaffected by the attack. So, success was a product of speed and data loss, not the integrity of what was being restored. Today, however, it’s not uncommon for threat actors to remain undetected within environments for extended periods, a situation which puts traditional backups and recovery processes at much greater risk of compromise.
Even when RTO and RPO targets are met, it does not necessarily equate to a successful recovery, particularly if compromised data is reintroduced into the environment.
Adapt to meet the risks head-on
This ‘preparedness gap’ is at its most dangerous when organisations believe they are ready to recover but actually lack visibility into whether their data and systems can actually be trusted. In many cases, backups are assumed reliable without validation, creating a false sense of confidence in recovery plans.
What can then happen is that organisations actually need to determine which systems and data are clean, a process that can significantly extend recovery timelines, and helping to explain why real-world recovery often takes weeks rather than the days leaders expect.
For example, clean recovery involves tasks such as identifying compromised elements, isolating clean versions of data, and checking that restored environments are free from hidden threats. This is a much more complex and exacting process than those associated with RTOs and RPOs. It also means that recovery must be planned and measured differently from traditional approaches.
Instead, organisations need processes that focus on maintaining essential business operations during and after an attack. This concept is often referred to as a Minimum Viable Company (MVC), and it focuses recovery efforts on the core components required for continued operation.
Setting performance targets and measuring success depend on how long it takes to restore these critical systems using clean, validated data, as measured by Mean Time to Clean Recovery (MTCR). MTCR accounts for the need to verify data integrity and ensure that restored environments are safe and trustworthy, and rather than replacing RTO and RPO, it complements them by adding a more realistic and comprehensive measure of recovery effectiveness.
In practical terms, recovery planning changes from a theoretical exercise to a more focused and repeatable process that instils trust within security teams and the wider organisation alike. By embedding data validation and system integrity checks into recovery workflows, for example, organisations are less exposed to the risks of failed restorations and reinfection. Crucially, it also establishes and manages expectations at the leadership level and supports decision-making during incidents, particularly when prioritising which systems to restore first.
Given the nature of high-profile security incidents, it’s essential that businesses adapt and put themselves in the strongest possible position to recover not just quickly but with the maximum levels of integrity. Those who do will be ideally placed to meet contemporary and future security risks head-on.
Mark Molyneux
Mark Molyneux is the Field CTO of North Europe at Commvault. Previously, he held roles as EMEA CTO at Cohesity and UK Business Development CTO at Dell Technologies. He is a strong senior leader with expertise in strategic technology decision-making, financial management, workforce development, and 20 years’ experience managing large globally diverse teams.


