Cyber Security and Disaster Recovery

Protecting the data you hold and proving you can recover it — the plan, the testing, and what an auditor will ask to see.

An IT support team at work on service desk calls

Most organisations have never answered that question numerically, which is why DR investment is so often deferred until after an incident.

What downtime costs

Gartner puts the cost of downtime at around $5,600 per minute. That figure is worth sitting with, because it reframes disaster recovery from an insurance-style overhead into an operational calculation: how many minutes can you afford, and what would it cost to reduce them?

Most organisations have never answered that question numerically, which is why DR investment is so often deferred until after an incident.

Ransomware changed the threat model

Traditional disaster recovery was designed for failure — hardware, power, flood. Ransomware is not failure; it is an adversary who has had time to look around, and who will target your backups first because that is what determines whether you pay.

The consequence is that a backup which is merely offsite is no longer sufficient. If it is reachable from the network that has been compromised, it should be assumed compromised too.

An IT support team at work on service desk calls

Air gapping, and why adoption has risen

Air gapping means keeping a copy of critical data physically or logically isolated, with no live network path to it. It is the direct answer to the problem above: an attacker cannot encrypt what they cannot reach.

The design principles are simple to state and easy to get wrong:

  • Genuine isolation — no persistent connection, no shared credentials
  • Immutability — copies that cannot be altered or deleted within their retention window
  • Regular, verified copies, so the isolated copy is recent enough to matter
  • Separate authentication, so one compromised administrator account does not reach both

Recovery is a three-step process

Preparation, response, restoration — and the third is where untested plans fail.

A backup that has never been restored is a hypothesis. Industry survey data backs this up directly: nearly a quarter of businesses with a DR plan admit they have never tested it, most often citing lack of time or lack of resources rather than lack of concern. Organisations routinely discover during an incident that the restore takes four days, that a critical system was never in scope, or that nobody currently employed has done it before.

What to do about it

Set a recovery time and recovery point objective per system, and be honest about which systems genuinely need the tightest ones. Keep at least one immutable, isolated copy. Then test the restore on a schedule and time it — because the number you get is your real recovery objective, whatever the policy says.

The organisations that come through an attack intact are rarely the ones with the largest security budget. They are the ones that had practised.

Get the full guide

Tell us who you are and the guide opens straight away, all 12 pages, to read online or download as a PDF.

Download the guide

What housing providers say

Named people at named organisations, in their own published words.

“We realised that we had a gap around the golden thread of data, in terms of the availability and accessibility of the data we held in seventeen different systems… That meant colleagues could immediately see all non-compliant properties.”
Notting Hill Genesis logo

Jake Le Page Head of Building Safety Regulations Notting Hill Genesis

“Neo brought strong Dynamics 365 expertise, worked collaboratively with our internal teams and applied Microsoft best practice within a live operational environment… We would be pleased to recommend them as a Microsoft Dynamics 365 partner within the housing sector.”
Sage Homes logo

Wayne Human Head of IT Change Sage Homes

“The successful deployment of this solution has significantly increased transparency and improved the operational efficiency of our contact centre, allowing us to deliver greater value to our customers.”
VIVID

Philip Wragg Infrastructure Programme Manager

“The Neo Technology model allows us to scale our development capacity, accelerating our transformation programmes while future-proofing our business, while achieving substantial industry cost savings.”
Notting Hill Genesis logo

Group CIO Notting Hill Genesis

Related proof

See how this works in practice

Thirty minutes, walked through by the people who deliver it. Bring your questions.

Get the guide

Tell us who you are and the guide downloads straight away.