Table of Contents

Cyber Security - Cybersecurity Recovery Objectives

The primary objective of a cybersecurity disaster recovery plan is to protect the organizational data and assets after a security mishap has happened.

The plan should address very specifically the steps the organization will follow to reconstitute assets after an incident.

Cybersecurity recovery efforts should consider:

Consider:


Layered Protection


Plan for the Recovery Phase

Not all cyber attacks can be avoided. Therefore plan for all possible cyber incidents, their containment and the recovery process.

To determine priorities, perform a business impact analysis to evaluate potential effects of cyber events; financial, legal, regulatory, etc.


Continuous Improvement

Any recovery planning process needs to be fluid. The recovery plan should be updated regularly to keep up to date with the threats landscape, best practices and lessons learned from response to breaches that have affected similar businesses.

It is imperative to test periodically that the recovery plan does work.


Track Recovery Metrics

Keep track of real data to gauge the position.


Document Everything

Procedures, roles and responsibilities, metrics tracking, and adjustments should be documented for improved response times and recovery.

NOTE: The Recovery Plan should be discussed with Security teams, Business continuity teams and Contingency planning teams.