Cyber Security and Disaster Recovery
Protecting the data you hold and proving you can recover it — the plan, the testing, and what an auditor will ask to see.
Most organisations have never answered that question numerically, which is why DR investment is so often deferred until after an incident.
What downtime costs
Gartner puts the cost of downtime at around $5,600 per minute. That figure is worth sitting with, because it reframes disaster recovery from an insurance-style overhead into an operational calculation: how many minutes can you afford, and what would it cost to reduce them?
Most organisations have never answered that question numerically, which is why DR investment is so often deferred until after an incident.
Ransomware changed the threat model
Traditional disaster recovery was designed for failure — hardware, power, flood. Ransomware is not failure; it is an adversary who has had time to look around, and who will target your backups first because that is what determines whether you pay.
The consequence is that a backup which is merely offsite is no longer sufficient. If it is reachable from the network that has been compromised, it should be assumed compromised too.
Air gapping, and why adoption has risen
Air gapping means keeping a copy of critical data physically or logically isolated, with no live network path to it. It is the direct answer to the problem above: an attacker cannot encrypt what they cannot reach.
The design principles are simple to state and easy to get wrong:
- Genuine isolation — no persistent connection, no shared credentials
- Immutability — copies that cannot be altered or deleted within their retention window
- Regular, verified copies, so the isolated copy is recent enough to matter
- Separate authentication, so one compromised administrator account does not reach both
Recovery is a three-step process
Preparation, response, restoration — and the third is where untested plans fail.
A backup that has never been restored is a hypothesis. Industry survey data backs this up directly: nearly a quarter of businesses with a DR plan admit they have never tested it, most often citing lack of time or lack of resources rather than lack of concern. Organisations routinely discover during an incident that the restore takes four days, that a critical system was never in scope, or that nobody currently employed has done it before.
What to do about it
Set a recovery time and recovery point objective per system, and be honest about which systems genuinely need the tightest ones. Keep at least one immutable, isolated copy. Then test the restore on a schedule and time it — because the number you get is your real recovery objective, whatever the policy says.
The organisations that come through an attack intact are rarely the ones with the largest security budget. They are the ones that had practised.
Get the full guide
Tell us who you are and the guide opens straight away, all 12 pages, to read online or download as a PDF.
Download the guide
What housing providers say
Named people at named organisations, in their own published words.
“We realised that we had a gap around the golden thread of data, in terms of the availability and accessibility of the data we held in seventeen different systems… That meant colleagues could immediately see all non-compliant properties.”
Jake Le Page Head of Building Safety Regulations Notting Hill Genesis
“Neo brought strong Dynamics 365 expertise, worked collaboratively with our internal teams and applied Microsoft best practice within a live operational environment… We would be pleased to recommend them as a Microsoft Dynamics 365 partner within the housing sector.”
Wayne Human Head of IT Change Sage Homes
“The successful deployment of this solution has significantly increased transparency and improved the operational efficiency of our contact centre, allowing us to deliver greater value to our customers.”
Philip Wragg Infrastructure Programme Manager
“The Neo Technology model allows us to scale our development capacity, accelerating our transformation programmes while future-proofing our business, while achieving substantial industry cost savings.”
Group CIO Notting Hill Genesis
Related proof
See how this works in practice
Thirty minutes, walked through by the people who deliver it. Bring your questions.