Tony Colon
Contributor

Principles every enterprise must test before the attack arrives

Opinion
23 Jul 20267 mins

True cyber resilience requires independent backups, board-aligned recovery plans and stress-testing for total, destructive blackout scenarios.

System administrator typing supercomputer hub disaster recovery plan on laptop to provide fast restoration of service, limiting damage and minimizing interruptions to normal operations
Credit: DC Studio / Shutterstock

I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.

Imagine this: A major global enterprise, a company most of us interact with indirectly every single day, wakes up to find its entire digital environment obliterated. Thousands of employees in dozens of offices and remote locations are suddenly offline. Customers are cut off, supply chains grind to a halt and regulators are notified with a chilling admission: “We have no idea when we’ll be back.”

This wasn’t ransomware. There was no negotiation, no decryption key to buy, no easy way out. It was destruction — deliberate, coordinated and geopolitically motivated — not monetary.

As a chief customer officer who’s worked with countless customers on cyberattack risks, my perspective hits a bit differently than a CISO or a CTO. I see the aftermath, not just the attack surface. I see the faces behind the tickets, the operations team locked out of their own systems, the support agent answering panicked calls at dawn. And I ask: How many organizations have actually stress-tested their response to this scenario — not a hypothetical, but this very real, lights-out event? Here’s what every leader needs to confront today:

Recovery is not just a technical exercise

The first assumption to break during a real crisis is the belief that recovery is purely technical.

Many organizations have done tabletop exercises and have a backup and recovery playbook, so they feel prepared. They can point to backup windows, retention schedules and immutability controls. The moment a true blackout happens, a different reality surfaces. The people who own the recovery steps either do not know each other, lack the authority to make decisions without supervisor approval or need guidance from offline systems.

The reality is that technical infrastructure almost always holds up better than human infrastructure. Organizations have built their recovery strategy around the assumption that someone competent will be awake, available and empowered when a cyber event happens.

Still, backups are only as good as their independence. Let’s be blunt: If your recovery infrastructure shares identity, authentication or network trust with your Microsoft tenant (such as Azure, Microsoft 365 or Teams), you don’t actually have a recovery plan; you have a false sense of one — and a liability. A recent survey found that while 90% of organizations express confidence in their ability to recover from a cyber incident, fewer than one in three ransomware victims fully recovered their data.

True resilience means immutable, air-gapped backups, untouchable by the same compromise. Anything less is an illusion. I talk to customers about their recovery plans constantly. The customers who have rehearsed all scenarios sleep soundly. Those who haven’t? They’re rolling the dice.

Most business continuity plans ignore ‘total blackout’

I’ve reviewed hundreds of business continuity plans. Almost all assume partial failures — a region, an application, a data center. But what if every system, in every country, goes dark simultaneously? That’s an entirely different playbook. If your team hasn’t run a drill for a global, simultaneous outage, you’re not prepared. The probability is low, but the cost of being unready is existential.

Connected devices, OT systems, field hardware, partner integrations — they all plug into your enterprise network. When the core collapses, it’s not just IT at risk. It’s operational technology, physical safety systems and in regulated sectors, potentially human lives. Understanding and testing those interdependencies is non-negotiable.

This is also where boards need to change the conversation. A study found that only 5% of companies have cybersecurity experts on their board of directors. Recovery time objectives (RTOs) should not be buried in technical appendices. It’s all jargon to boards. That makes translation essential. RTOs must be explained in terms of business impact. “We can recover in four hours” is a technical statement. “Every hour of downtime costs us $2.3M and creates regulatory exposure in three jurisdictions” is a board statement.

That is the level of clarity leaders need.

The most prepared organizations do not wait for an incident to educate the board. They bring the conversation forward proactively. They frame recovery in business terms: revenue, regulatory standing, customer trust and brand reputation.

The most effective framing is often simple. Show the most critical systems. Show what happens if each one is down for one hour, four hours, 24 hours and 72 hours. Show the current recovery capability against each and then show the gap.

If your board is not demanding real answers, your business continuity strategy is likely underfunded and your business is exposed. This is a risk conversation worth forcing because the consequences do not stay inside IT. They can show up in customer churn or missed revenue and ruin an organization’s reputation.

Threat intelligence must be actionable, not archived

Geopolitical attacks, hacktivist campaigns and nation-state targeting aren’t abstract threats. They are active risks, and that intelligence cannot languish in the security team’s inbox. Executive leadership must be looped in — and immediately — so gaps can be closed before they’re exploited. Too often, intelligence enters the security operations function and never reaches the teams responsible for recovery infrastructure or executive decision-making.

If a threat actor is targeting a specific class of backup agents, the team responsible for those agents needs to know now, not two weeks from now. If intelligence suggests destructive activity against a sector, recovery owners need to validate isolation, access paths and restoration procedures immediately. If geopolitical tension increases the likelihood of targeting, executive leadership needs to understand what exposure exists and what actions are being taken. The organizations that survive aren’t just the best at incident response. They’re the ones who anticipated, rehearsed and invested before the attack.

Part of investing in a recovery strategy requires closing the loop between signal and action. The most prepared organizations have already mapped their critical recovery dependencies to specific threat categories. When intelligence touches one of those categories, there is a named owner and a clear set of actions. No guessing or forwarding emails into the void is needed because the distance between the warning and the employees’ ability to do something is shortened.

Looking ahead, the conversation will continue to evolve beyond traditional cyber response. Because in an AI-enabled enterprise, the new question is whether the data within those systems can still be trusted. When AI systems make decisions based on enterprise data, the attack surface becomes the data’s accuracy. A threat actor who quietly corrupts a dataset over 90 days before a recovery event has done more damage than just downtime. They can poison the inputs driving decisions across the business.

Regardless of how AI will change threat intelligence and cyber response, these principles remain the same. Know your problem, whether structural or technological. Ensure your human infrastructure keeps pace with your technical infrastructure, with clear cross-functional ownership and the tools and knowledge to act autonomously. Communicate with your boards often — and correctly.

Let’s not wait for the next headline to ask, “Are we ready?” Have those conversations now. Test your assumptions. Close your gaps. Because in today’s threat landscape, resilience isn’t IT’s job — it’s everyone’s mandate.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

Tony Colon

Tony Colon is chief customer officer at Veeam, where he leads global customer success, professional services and technical support teams. He has over 20 years of experience leading large-scale customer organizations at companies including ServiceNow, Cisco and Salesforce. At Veeam, he focuses on improving customer outcomes in data resilience, cybersecurity and cloud data protection.