Cyber Resilience
Cyber resilience is the ability to withstand, detect and recover from a security incident. It starts from the assumption that a breach will eventually get through, and designs for how quickly and with how much damage the business keeps working.
Enquire about this catalogueWhat it covers
- Detection: catching unusual activity while it is still containable, not after it has spread.
- Containment: isolating an affected system or account quickly, before it reaches the rest of the estate.
- Recovery: restoring services and data from copies that are clean, current and tested, within a time the business can absorb.
- Continuity: keeping essential operations running, even degraded, while the rest of the recovery happens.
Why it is separate from prevention
- Prevention has a limit: no control stack stops every attempt. Resilience is what governs what happens after the attempt that succeeds.
- Ransomware model: modern attacks assume initial access. The difference between a bad week and a bad year is mostly in the recovery design.
- Backup integrity: a backup that is reachable by the same attacker as the live system is not protection. Offline or isolated copies are what count.
What to weigh
- Recovery targets: how long each system can be down before the cost exceeds the recovery itself. The honest number per system, not the optimistic one.
- Testing: a recovery plan that has never been exercised is a draft. The test is where the gaps appear, cheaply.
- Decision authority: who can declare an incident, who can order a shutdown, and who can order a restore. Defined beforehand, not improvised at 2 a.m.
How NobleConsul can help
Where relevant, NobleConsul may support the review of detection and recovery coverage, the design of realistic recovery targets per system, and the planning of a test that proves the design holds, as possible consulting activities.
Enquire about this catalogue
Thank you for your enquiry. One of our team members will contact you shortly.