it-sa 365: What fundamentally distinguishes traditional cyber defence from the cyber resilience approach, and why is pure defence no longer sufficient today?
Christian Kubik: Unfortunately, being successfully attacked is now merely a question of time. It is no longer a matter of if it will happen, but when. Companies must prepare for a threat landscape in which AI capabilities are evolving faster than conventional security assumptions. Their resilience will depend on whether they are able to detect, contain and restore normal operations when control mechanisms fail.
How companies are preparing for this threat landscape and which attack patterns are currently in focus is explored on the topic page Cyber Attack: Hacking & Defence.
The underlying problem is that, during a cybersecurity incident, organisations can no longer trust their data, including their backups. Until recently, it was commonly said that attackers could remain within target networks for up to 200 days while extending their reach. Through the use of artificial intelligence, this timeframe has been drastically reduced. In some cases, data begins leaving the organisation within minutes of the initial breach. This fundamental challenge has therefore intensified further. Backup systems are a preferred target because they can render a ransomware attack ineffective.
How companies can better protect their data using AI-supported anomaly detection is shown in the article The key to AI-supported cyber data resilience.
Anyone who simply restores data from backups and merely meets their desired RTO and RPO targets misses the central objective of cyber resilience today. Uncontrolled restoration of backups also restores backdoors, malicious code and fake accounts, enabling attackers to re-enter the network with ease. Systems become compromised again, IT teams are forced back to the beginning of the recovery effort, and they must decide how far back in the backup timeline they need to go to find a clean backup. All of this happens under intense time pressure and stress. Their reputation with executive management and customers declines with every day lost.
What role do redundancy, segmentation and system isolation play in the resilience of an IT infrastructure?
Christian Kubik: IT security and infrastructure teams must work closely together during an ongoing attack to assess data integrity before restoring data from backups. This process requires companies to keep backup data air-gapped, meaning invisible to attackers, in a remote location. That data must first be examined in a clean room, searched for attack artefacts and then restored within an isolated recovery environment.
The ten protective measures against malware that companies should take overall are outlined in the practical guide Understanding and defending against malware: The practical guide for businesses.
To ensure teams know exactly what to do in such a high-pressure situation, these procedures must be tested regularly. Commvault enables organisations to practise this restore process at any time in an isolated environment created with a single click, either in the cloud or on-premises, without affecting production IT operations.
How such a clean room approach can also be secured from a regulatory perspective – for example with regard to DORA and NIS2 – is shown in the session AI-powered data security & management for operational cyber resilience at it-sa Expo & Congress 2024.
In addition, so-called runbooks support teams by providing detailed recovery steps for specific workloads, such as Active Directory. The runbooks explain each individual step within the GUI, guide users through complex configurations and automate much of the process. If a recovery environment differs significantly from the norm, bespoke steps and configurations can be incorporated into the runbook. In effect, organisations create their own runbook tailored precisely to their environment. During the most stressful phase of an attack in particular, the experience gained through advance testing and incorporated into runbooks helps save time, money and effort.
How can an organisation determine whether it is resilient? Are there metrics or maturity models that have proven effective in practice
Christian Kubik: Data integrity must be assessed before data is returned to production. We therefore need to move beyond a purely RTO and RPO-focused discussion and view cyber resilience as an end-to-end process. At Commvault, we refer to this analysis and the average time required for complete recovery as Mean Time to Clean Recovery (MTCR). In essence, MTCR defines the average time required for IT security and infrastructure teams to restore predefined critical business applications, the underlying systems and infrastructure, and the associated clean, validated data following a cyberattack. It therefore captures the entire process from beginning to end.
Those who follow this approach will be able to measure the size of their resilience gap accurately and discuss realistic scenarios with executive management. They will also be better equipped to justify why an existing backup environment must be modernised into a true cyber resilience environment. How companies anchor resilience organisationally and remain capable of acting even in geopolitical crises is explored in the article Cyber resilience & incident response in geopolitical crises.
What specific organisational and technical steps must a company take to move from a purely defensive strategy to genuine cyber resilience?
Christian Kubik: Most organisations still have considerable scope to improve their resilience, particularly in the event that preventive security measures fail for whatever reason. Operational readiness is the key differentiator between organisations that recover quickly and smoothly and those that struggle with prolonged disruption.
Many decision-makers still associate resilience primarily with backup technologies or recovery solutions. While these are absolutely critical, such thinking can create a false sense of security. Having recovery technologies does not automatically mean an organisation is capable of restoring operations under real-world attack conditions. True recovery capabilities that can be relied upon in a crisis also depend on planning, continuous testing and validation, and a deep understanding of the interdependencies between critical business processes. These capabilities are referred to as “Resilience Operations”, or “ResOps” for short. At their core is the continuous verification of recovery capabilities so organisations can be confident they will remain operational when it matters most.
Why structured incident response strategies can turn resilience into a genuine competitive advantage is shown in the session From emergency to success factor: How cyber resilience protects companies at it-sa Expo & Congress 2025.
Imagine two companies affected by the same ransomware attack. Both possess backups. However, only one knows exactly which systems must be restored first and has already validated its forensic, remediation and recovery procedures. The other must first gain an overview of system dependencies and make recovery decisions while business operations remain suspended. The decisive difference between the two has very little to do with technology and far more to do with how well prepared they were for the attack.
So is it crucial to establish the right priorities before any cyberattack occurs?
Christian Kubik: The key to rapid recovery lies in correct prioritisation. The Minimum Viable Company (MVC) is the minimum combination of systems and services required to sustain operations after an incident. The aim is to restore those functions that enable the organisation to continue serving customers and performing its most important activities; this may differ from restoring all systems simultaneously.
Defining the MVC requires organisations to identify essential business services, establish impact tolerance thresholds and map system dependencies before an incident occurs. This prevents business-critical recovery decisions from having to be made under severe time pressure. Typical components include identity services, operational databases, communication platforms, finance or billing systems, and other applications indispensable to daily operations. These components vary from company to company.
More on identity services and access management as central building blocks of the MVC can be found on the topic pageData Center Security & Identity Access Management.
Depending on the level of integration, organisations may also need to assess whether AI-related components, such as data pipelines or autonomous AI workflows, have become business-critical. It is important that MVC parameters evolve alongside the organisation rather than remaining static. A broader overview of the role of artificial intelligence in IT security is available on the topic page AI & Cybersecurity: Harnessing Potential, Managing Risks.
It stands to reason that organisations which have identified and validated their MVC can typically restore essential operations more quickly because recovery priorities have already been defined. Combined with a sharpened understanding of what resilience truly means, organisations will be exceptionally well prepared.
How artificial intelligence and automation, combined with targeted human oversight, contribute to sustainable cyber resilience is shown in the sessionIT under control, attackers out – sustainable cyber resilience made in Germany at it-sa Expo & Congress 2025.
Want to connect directly with experts in cyber resilience and recovery strategies? At the it-sa EXPO & Congress you can expect live talks, hands-on use cases and direct exchange with exhibitors on cybersecurity and data resilience. Register as a visitor now!
The interview was conducted by Andreas Knoll.
