Steps for Planning for Cyber Resiliency

Prevention

1) Verify all security settings for systems – access and administration at all level, software including operating systems and applications, networks, and other management/monitoring tools. A plan for auditing and regular updating of security settings should be developed and followed.  This should be exercised according governance practices but at least monthly.

2) Tools used to detect attempts to penetrate the environment should be implemented and tested periodically. These tools continue to evolve and will require continual updating and transitioning to improved tools.

Detection

Detection of an attack in progress is done through a limited number of means:

  • – Log analysis software collects logs from software and hardware systems and performs analysis to determine if suspect activity is occurring. This software will do alerting, notification to systems/software that could be used to freeze activity, and report on detailed activity that could be used to identify the point in time of an attack.
  • – Software that interacts with data such as backup software that monitors access to the protected data and can determine if anomalous activity is occurring. The actions to be taken upon detection can vary and are usually configurable.
  • – Some storage systems that are used for data protection (backup targets) can monitor for anomalous activity, similar to backup software. These systems report on the activity and may also take action based on control settings.

Recovery

There is great variance in what the recovery processes are considering the environment – systems and software.  There are some general considerations to be undertaken but detailed understanding of recovery requires efforts with technical staff who understand the environment and the organization requirements.

1) The first step is to understand what potentially is required to be done in the case of a recovery due to a cyber-attack. The starting point for this, from an expediency standpoint, is to begin with an existing Disaster Recovery plan.  Using that will serve as an outline where the reasons for recovery with an understanding of the potential for altered/infected data and those implications can the introduced.

2) The recovery sequence from a cyber attack is what will be developed first. With the DR recovery sequence as an outline (without a DR recovery plan that includes a detailed sequence of actions, the effort becomes much greater).

    1. 1) The first consideration is to add steps to validate the information before proceeding. ‘Was the data protected (before the problem/infection occurred?’ is the first question assuming the time of the first indication of an attack is known. This is where the identification of the different recovery copies and the understanding of recovery points becomes critical and the expertise of the staff and their data protection strategy is important.  Some primary storage systems provide capabilities to make copies of data as ‘logical air gaps’ that can be used to reduce the recovery point and recovery time.  These storage systems need to be factored into the recovery strategy if they are available.
    2. 2) Dependencies such recovering identity access management credentials and authentication systems must be addressed first as these have been seen major target to compromise in attacks.
    3. 3) The sequence to recover will be very dependent on the expertise of staff, knowing the relationship of data and applications and the status of the protected copies.

3) Use of existing DR plans is an expedient outline after understanding what data could be infected/altered and the systems that could be compromised. Examination of the DR plan with a focus on where recovery changes for cyber attack would need to be made will lead first to additional investigation that may need to be done and then insertion of additional steps for this type of recovery.  Adding the steps for identification of ‘known good copy’ of data and validation of data are the first consideration.  Another is the ‘sandbox.’  Propagation of an infection/alteration during recovery is a major concern during recovery.  To address this, recovering data to a trial area, termed a ‘sandbox’ where tests can be done to prove the validity of the data recovered is an additional, time-consuming step that needs to be taken.

4) Exercising the recovery from a cyber attack must be added to the regular process for IT operations.

Author Information

Randy Kerns

Randy has written numerous industry articles and papers as an educator and presenter, and he is the author of two books: Planning a Storage Strategy and Information Archiving – Economics and Compliance. The latter is the first book of its kind to explore information archiving in depth. Randy regularly teaches classes on Information Management technologies in the U.S. and Europe.

Related Insights
So This Is How AIs Attack- Observations From the OpenAI & Hugging Face Incident
July 24, 2026

So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident

Fernando Montenegro and Mitch Ashley, VPs at Futurum, read the OpenAI and Hugging Face agentic incident as a live test of enterprise readiness to detect and contain AI agents that...
ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth
July 23, 2026

ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth

Futurum Research analyzes ServiceNow Q2 FY 2026 earnings, focusing on AI Control Tower adoption, security expansion, and workflow demand....
Alphabet Q2 FY 2026: Google Cloud Leads Growth Amid Rising AI Investment
July 23, 2026

Alphabet Q2 FY 2026: Google Cloud Leads Growth Amid Rising AI Investment

Futurum Research analyzes Alphabet’s Q2 FY 2026 earnings, focusing on cloud AI demand, Gemini adoption, Search monetization, and rising AI infrastructure spending....
Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?
July 23, 2026

Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?

Mend.io's security team identified 199 malicious RubyGems and achieved complete takedown within hours, intercepting a cryptomining campaign before execution and demonstrating the critical importance of continuous open-source monitoring....
Hugging Face Breach: A Wake-Up Call for AI Agent Security
July 23, 2026

Hugging Face Breach: A Wake-Up Call for AI Agent Security

The Hugging Face breach reveals how autonomous AI agents exploit code flaws to harvest credentials and move laterally at machine speed. Enterprise leaders now recognize identity security as urgent, with...
Intel Foundry Lands Fortinet SP6 as Custom Silicon Validation
July 22, 2026

Intel Foundry Lands Fortinet SP6 as Custom Silicon Validation

Brendan Burke and Fernando Montenegro, analysts at Futurum, share their insights on the Intel-Fortinet SP6 collaboration, what it validates about Intel Foundry's custom silicon strategy, and why the supply chain...

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.