The difference between an outage and an attack is that the attack has a will. A fire does not destroy the backup power on purpose. A flood does not go looking for the backups. An attacker does both, and does them first, precisely because they know the copies are the only thing standing between the organisation and a payment.
The chapter opens with the shift from traditional continuity planning to cyber resilience, and what that shift demands of plans written for a different kind of interruption. Then follows the business impact analysis, the work of deciding which functions have to work, how quickly they have to be back and how much data the operation can stand to lose. Without that analysis the restart order is improvised, and that improvisation happens at the worst possible moment. The backup strategy gets a substantial section because it has to be rebuilt for a reality where the copy is a target in itself. The decisive question is not whether backups are taken but whether anyone has tried restoring from them and knows how long it takes. After that comes the crisis management plan, with weight on roles, decision paths and communication when the usual systems are unavailable. One section deals with resilience across the whole conflict scale, from everyday disruption to heightened alert. Exercises get their own space, as does a review of the continuity requirements in the Cybersecurity Act. The acute handling is covered in chapter 17 on incident response, while this chapter takes over for the longer course of events.
Why now comes down to continuity being an explicit requirement area in the law, and to the most common shortcoming not being that plans are missing but that they have never been tested against a scenario where the attacker also takes out the fallback. A plan that has never been tested is in practice a hypothesis about how the organisation will behave, and hypotheses are rarely confirmed under pressure.
This page shows what the chapter covers and why the plans need testing. The analysis model, the backup strategy and the exercise design are in chapter 23 of the book.
Resilience is not tested in good times. That is why you build it in advance.
Key insights
- Continuity planning assumes something breaks. Cyber resilience assumes someone actively destroys, including the fallback.
- The business impact analysis decides what gets priority on restart. Without it the order is improvised.
- A backup nobody has restored from is a hope. Recovery time is what counts.
- Resilience has to hold across the whole scale, from everyday disruption to heightened alert.
- Continuity is one of the ten requirement areas of the Cybersecurity Act and has to be demonstrable.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
The Toolbox
Templates and tools for the systematic work, free of charge.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.