Cyber recovery is the ability to restore systems and data after a cyberattack, such as ransomware, when the attacker may have also damaged, encrypted or infected your normal backups. It combines protected copies of data, often held in an isolated recovery vault, with steps to find a clean restore point, rebuild in a safe environment and bring systems back in the right order.
At a glance
- Cyber recovery plans for an attacker, not just an outage: recent copies may be compromised, and the attacker may still be inside.
- Protected copies are kept isolated from production and normal administration, often immutable, in what is commonly called a cyber recovery vault.
- Recovery includes checking that restore points are clean, often by scanning or analyzing copies, before systems go back into use.
- It works alongside incident response: investigation, eradication and recovery happen together.
What problem it solves
Traditional backup and disaster recovery were designed for hardware failures, mistakes, fires and floods. In those cases the newest copy is usually the best one, and failing over to a second site is the fastest route back. Ransomware changed that. Attackers commonly look for backup systems, delete or encrypt copies, and steal administrator credentials before they launch the visible attack. Malware may sit in systems for weeks, so recent backups and replicated DR copies may contain it too.
An organization that restores from a compromised copy can be reinfected, and one whose backups were reachable from the production network may have nothing left to restore. Cyber recovery is the planning and tooling that keeps at least one set of copies out of the attacker’s reach and gives the team a tested, safe way to rebuild.
How it works
Protected copies. Critical data and system images are copied to storage separated from the production environment. Common protections include immutable backup, which prevents changes or deletion for a set period; separate accounts, credentials and administration; and network isolation. An air-gapped backup is one form of isolation, whether a physical disconnect or a logical one that opens only for scheduled copy windows.
The recovery vault. Many cyber recovery designs put these copies in a dedicated vault, either on-premises, at a second site or in a provider’s cloud. Access is tightly limited, often requiring multiple approvers, so a single stolen administrator account isn’t enough to destroy it.
Clean-point identification. Before restoring, the team needs to know which copy predates the compromise or is free of the attacker’s tools. Some products scan copies for malware or unusual changes; otherwise the investigation team works backward from what it finds.
Clean-room rebuild. Systems are restored into an isolated environment, checked, patched and hardened, then returned to production in priority order, often starting with identity services and core infrastructure. This is coordinated with incident response (IR) so the attacker’s access is removed first.
Testing. Plans are exercised regularly with realistic scenarios to measure real recovery time objectives (RTO) for an attack, which are often longer than for an outage.
When it matters for buyers
- When ransomware is a top risk. It is the scenario cyber recovery is built for.
- When your backups share credentials or networks with production. That is a common way attackers reach them.
- At cyber insurance renewal. Insurers increasingly ask about backup isolation, immutability and tested restores.
- When reviewing a DR or DRaaS contract. Ask whether the service covers recovery after an attack, not only failover after an outage.
- When regulators or customers ask about resilience. Cyber recovery is a practical part of cyber resilience.
To compare backup and recovery services, see our disaster recovery as a service overview.
Questions to ask vendors
- How are recovery copies isolated from our production network and our normal backup administrators?
- Are copies immutable, for how long, and who can change retention settings?
- How would we identify a clean restore point, and do you scan or analyze copies for compromise?
- Where would we rebuild systems during an attack, and is a clean environment included?
- What recovery time can you show for a ransomware scenario, not just a failover test?
- Do you support recovery of identity services and infrastructure, not only file and database data?
- What help do you provide during an actual incident, and how does it work with our incident response provider?
How it differs from backup and disaster recovery
Backup makes copies of data so it can be restored after loss or corruption. Disaster recovery, part of business continuity and disaster recovery (BCDR) and often bought as disaster recovery as a service (DRaaS), restores operations after an outage, usually by failing over to a recent copy at another site. Both generally assume the copies are trustworthy. Cyber recovery assumes they may not be: it keeps copies isolated from attackers, checks that they are clean, rebuilds in a safe environment and coordinates with the investigation. Many organizations build cyber recovery on top of existing backup and DR rather than replacing them, but a DR plan that only covers failover is not by itself a cyber recovery plan.
