drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

Disaster vs. Cyber Recovery

Cyber Resilience & IT Disaster Recovery
cyber recovery vs. disaster recovery

Closing the Gap to Bolster Resiliency

Before the cloud, IT resilience was defined by an organization’s ability to maintain operations during events like natural disasters, power outages, vandalism or any other incident knocking out access to underlying technology they owned and operated.

Increasingly, enterprises must consider not just the IT hardware they own and operate, but also the vast environment of services that reside in external cloud environments. This breakdown of the historic “perimeter” security model has altered what it means to be resilient, forcing businesses to establish their own cyber recovery plans alongside historical disaster recovery strategies that might trace to the pre-cloud era.

Of the two, cyber recovery remains the bigger challenge. In fact, 70% of businesses think it’s more problematic than disaster recovery, according to a recent survey conducted with 500 IT and cybersecurity professionals from midmarket and enterprise organizations across North America, Western Europe and Asia Pacific.

Having an effective cyber recovery strategy in the cloud era is crucial to the continuity of a business. Whether it’s a cyberattack or an update gone awry, enterprises must prepare for digital disruptions that could take critical services offline for extended periods of time — amounting to potentially hundreds of millions of dollars in damages. As reliance on data and AI technologies continues to grow, the risks of extended downtime will escalate.

That doesn’t mean disaster recovery isn’t still difficult — or important. However, with 52% of organizations still basing their cyber recovery strategies on longstanding disaster recovery plans, its key businesses understand the differences and similarities between the two. Ultimately, a company’s ability to respond will be contingent on how well it tests and fine-tunes recovery protocols in advance of a breakdown — whether from a natural disaster or a criminal hack.

Bridging the Understanding Gap

While executive leaders and board members have grown to understand disaster recovery, the concept of cyber recovery can muddle that understanding. IT leaders need to differentiate between the two and make a compelling business case to ensure the unique risks of cyber threats are effectively managed.

To secure investment in cyber recovery initiatives, IT leaders should focus on these three key points in their business case:

  • Quantify the cyber risk exposure: Present clear data on the potential financial and operational impact of cyber incidents, including how cyber threats can lead to extended downtimes, data breaches, and significant financial losses beyond what traditional disaster recovery plans cover.
  • Highlight the limitations of traditional disaster recovery: Explain how traditional disaster recovery strategies are insufficient against sophisticated cyberattacks that target backups and infrastructure, emphasizing the need for specialized cyber recovery measures.
  • Demonstrate return on investment through resilience: Show how investing in cyber recovery enhances overall business resilience, reduces recovery times, protects the organization’s reputation, and meets compliance and regulatory requirements, while also fostering trust with customers and partners, thereby providing a strong return on investment.

To strengthen cyber recovery strategies and bridge the gap with disaster recovery plans, enterprises should focus on these key actions to enhance their overall IT resiliency.

Actual Typhoon vs. Salt Typhoon

When an IT incident occurs, companies must operate on the assumption every technology is compromised. It’s the biggest difference between cyber and disaster recovery strategies. A disaster recovery plan might assume the problem can be isolated to only the hardware and software directly affected by the calamity.

Under the increasingly common threat of cyberattacks, hackers are targeting the assets businesses need to quickly get back online. In fact, 92% of businesses that have incurred attacks say the hackers specifically targeted data backups.

It’s crucial to make sure backups are stored in a secure, isolated environment and are being continually tested to ensure they’re free from malware. That way, companies can more confidently execute their cyber recovery strategies. With isolated backups, data recovery experts can get clean data to the application teams faster, helping them quickly get the actual end systems up and running again.

Test, Test, Test

Too many organizations, though, still lack the clean environments needed to safely and cost-effectively verify the effectiveness of plans in advance of an incident. Even with the right technology in place, if procedures aren’t pressure-tested in advance, organizations often run into real-time issues that prolong recovery, amplifying the financial and reputational risks the business faces.

In disaster recovery, businesses often have a much clearer idea of the expected impact. The company would know in advance, for example, which services would be affected if a hurricane hit a specific region or if a data center was taken offline because of a power outage.

With cyber recovery, however, the impact is much more uncertain. After an attack or some other cloud-impacted mishap, enterprises typically aren’t immediately aware of the extent of the damage. Because many digital applications work in tandem with one another, the impact of any incident can spread far beyond a single infected system.

This is why businesses need a secure and cost-effective way to test their recovery plans against different potential situations. And while it’s unlikely any real-world incident ultimately plays out exactly like a test environment, the skills and processes developed during training exercises will help specialists respond with greater agility and flexibility.

The Talent Challenge

Finding specialists who can create and test a cyber recovery plan is getting much more challenging for businesses. According to the survey, 59% of respondents cited finding and retaining cyber recovery staffers as a key hurdle, compared to the 15% who cited staffing as a challenge for disaster recovery. Without the right skills, it’s harder for businesses to create and test the resiliency of their IT environments.

This is where technology can play a critical role. Cloud-based cleanrooms provide instant access to isolated environments, alleviating understaffed internal teams from the expensive and arduous process of building their own testing center.

Cyber recovery can build upon and complement the best practices of disaster recovery. But cyber recovery poses its own additional challenges. Recognizing these unique difficulties and adopting measures to help address them lets businesses operate with the confidence that, whether it’s a natural disaster or a hacker attack, they’re prepared to get back online.

ABOUT THE AUTHOR

Chris Montgomery

Chris Montgomery is a nationally recognized cybersecurity strategist with more than 30 years of experience in the technology sector, including pivotal roles as a CIO, CTO and CISO. An Air Force veteran with a broad background in technology, Montgomery has honed his expertise in cybersecurity, risk management, organizational change management, and digital transformation. He advises boards, leadership teams, elected officials, and policymakers in both public and private sectors, offering strategic guidance on cyber resilience and modernization. His expertise and strategic insights have made him a respected leader and valuable resource, helping organizations navigate the complex landscape of cyber threats and technological advancements. To view findings from the survey mentioned in this article, please click here.

Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.