While you’re working urgently to establish the facts, the attacker is likely still altering them.
By Ed Bednar
Your defenses failed.
They got in.You just finished a call with the FBI.
Your lawyers are mobilizing.Every decision you make will be examined by regulators.
Your cyber insurer will soon explain what the policy requires of you.Your customers already want answers.
Nothing you planned to do today matters anymore.Everything is fucked.
The Fight Starts Here
In a destructive cyberattack, many of the assumptions about your systems and data may no longer be valid.
And at this point, while the entire organization is responding, it is still trying to understand what it is responding to.
It’s also likely that no one in the organization has ever actually had to fight an active cyberattacker in this situation, and planning for a fight is very different from finishing one.
Cyber Recovery Is Different From Disaster Recovery
Few organizations ever tell the full story of a cyberattack.
The breach itself may be disclosed, along with a timeline of events, and, perhaps for effect, the ransom demand. But the technical analysis often only explains how the attackers gained access and moved through the network.
What happened next is rarely explained.
Most organizations simply have little incentive to risk publicly revealing one of the worst events in their history. As a result, there are remarkably few firsthand accounts of what it actually took to recover and the limitations of recovery itself.
The British Library is a notable exception.
The British Library Ransomware Attack
Following its 2023 ransomware attack, the British Library published one of the most detailed public accounts of recovering from a destructive cyberattack.1
Rather than focusing solely on the attack itself, the report candidly examines why recovery proved so challenging, a dark read for sure.
The Library had secure copies of its digital collections and many systems, but recovery was constrained by how much of the surrounding technology remained viable.
The Library’s documented experience illustrates that the central challenge of cyber recovery is determining what can still be trusted, what can safely be restored, and what must be rebuilt.
The Recovery Problem
But by the time systems have been compromised in a cyberattack, the architectural decisions that will shape the recovery effort have already been made.
The enterprise enters a state where the integrity of its facilities, systems, infrastructure, security, applications, and data can no longer be assumed.
Sometimes there is actually very little left to trust.
Don’t Just Plan for Cyber Recovery, Architect for It
Earlier in this series, we established what business continuity and disaster recovery are intended to preserve in What Must Survive: A Practical Look at Business Continuity in a World That Never Stops Failing.
We then examined the conditions that make survival and recovery possible in Defining Survival: How First Principles Shape Business Continuity and Disaster Recovery.
In the next two articles, we will build on those foundations and look more closely at the role of cyber recovery in BCDR strategy.
In Understanding Destructive Cyberattacks, we examine the anatomy of these attacks and how sophisticated adversaries dismantle defenses, extend their reach across your systems and data, and compromise recovery paths.
Then, in How to Architect for Cyber Recovery, we detail how to engineer the trust, control, isolation, and recoverability needed to survive the attack and put the business back together.
The Computer Is Going to Do Something – Join an ongoing, practical examination of technology strategy, enterprise architecture, systems engineering, and technology operations.
Notes:
1. British Library. (2024). Learning Lessons from the Cyber-Attack: British Library Cyber Incident Review. March 8, 2024. Retrieved from https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf

Leave a Reply