Cyber Resilience

Cyber resilience is the ability to withstand, detect and recover from a security incident. It starts from the assumption that a breach will eventually get through, and designs for how quickly and with how much damage the business keeps working.

Enquire about this catalogue

What it covers

  • Detection: catching unusual activity while it is still containable, not after it has spread.
  • Containment: isolating an affected system or account quickly, before it reaches the rest of the estate.
  • Recovery: restoring services and data from copies that are clean, current and tested, within a time the business can absorb.
  • Continuity: keeping essential operations running, even degraded, while the rest of the recovery happens.

Why it is separate from prevention

  • Prevention has a limit: no control stack stops every attempt. Resilience is what governs what happens after the attempt that succeeds.
  • Ransomware model: modern attacks assume initial access. The difference between a bad week and a bad year is mostly in the recovery design.
  • Backup integrity: a backup that is reachable by the same attacker as the live system is not protection. Offline or isolated copies are what count.

What to weigh

  • Recovery targets: how long each system can be down before the cost exceeds the recovery itself. The honest number per system, not the optimistic one.
  • Testing: a recovery plan that has never been exercised is a draft. The test is where the gaps appear, cheaply.
  • Decision authority: who can declare an incident, who can order a shutdown, and who can order a restore. Defined beforehand, not improvised at 2 a.m.

How NobleConsul can help

Where relevant, NobleConsul may support the review of detection and recovery coverage, the design of realistic recovery targets per system, and the planning of a test that proves the design holds, as possible consulting activities.

Enquire about this catalogue