Cohesity: Faster cyber recovery requires restoring what matters most
Cohesity VP says restoring what matters most – the Minimum Viable Company – is key to faster recovery from cyberattacks.
In the aftermath of a major cyber incident, the instinct to bring every system back online as soon as possible usually slows recovery down, reintroduces cyber risk and undermines trust. The fastest recoverers start from a different premise: they assume large parts of the organization will be unavailable or untrusted, and they focus on restoring what matters most quickly and in a trusted state.
This is the idea behind the Minimum Viable Company (MVC) concept, sometimes called the Minimum Viable Organization. It defines what must exist for an organization to survive challenging conditions such as a cyber incident. It is not just a technology concept but a business definition of survival, covering the minimum combination of people, processes, technology, documentation, facilities, and third-party dependencies required to keep the business functioning.
Operationalizing an MVC requires five key capabilities. First, clarity on critical services: organizations must map systems to business value and understand the systems and dependencies that directly support revenue and mission-critical operations. They need structured assessment, alignment across business and technology stakeholders, and realistic simulations of recovery under pressure, defining what must function in the first 24 hours, 72 hours, and first week.
Second, a trusted foundation, or Tier 0, which acts as the control plane for recovery. It includes identity and access management, networking and DNS, privileged access controls, core security tooling, physical access systems, and secure communication channels, as well as non-technical dependencies like incident response playbooks, contact lists, insurance policies, and contracts with external responders.
Third, isolation of recovery assets: organizations must recover critical systems from clean snapshots in an isolated manner, protecting backups, configurations, and recovery tooling from the same blast radius as production. Fourth, a clean-room recovery capability, described as a "Digital Jump Bag" – a secure, isolated repository with everything needed to rebuild systems without reintroducing compromise. Fifth, validated ability to operate: resilience must be proven through realistic crisis scenarios, because an untested plan remains theoretical. Rehearsals also help answer the board's most direct question: how long will it take to restore critical services to a trusted state?
The most common cyber resilience risks are failing to define what must come back first and how to bring it back in a state that can be trusted. That, according to the article, is the difference between recovery as a process and recovery as a capability. The MVC is not static; as an organization evolves, its definition of minimum viability must evolve too.