Shifting the executive mindset from assuming absolute security to planning for inevitable breaches.
Cybersecurity threats affecting UK businesses have seen a sharp increase. Recent UK government data has found that almost half of businesses (43%) and over two-thirds (69%) of large firms have experienced a cyber incident in the past year.
In response, the government announced a £90m cybersecurity investment earlier this year to better protect businesses and accelerate Cyber Essentials adoption. Alongside this, the UK’s pending Cyber Security & Resilience Bill, which aims to update 2018 NIS Regulations, will soon place businesses under more scrutiny by imposing stricter reporting standards and turnover-based financial penalties for non-compliance.
Combined, these factors are placing businesses and security teams under more pressure to secure operations and demonstrate resilience. Yet, wider industry discussion tends to focus on tooling and defensive capabilities.
While threat prevention is essential, it only represents part of a complete strategy. An equally important metric that’s often overlooked is recovery time. If a business cannot measure its tolerance to different threats and understand how long it takes them to recover from a beach, then are they truly secure?
The true cost of downtime
As businesses continue to digitise critical functions like finance and procurement, the margin for operation error is thin.
Industry data around recovery times has reinforced this, revealing that the average business can only sustain up to three consecutive days of downtime before productivity and finances suffer lasting damage. In a business climate defined by tighter margins, rising overheads and supply chain fragility, even a brief disruption can lead to a loss of customer trust and regulatory penalties.
When an attacker slips past defences, the clock starts immediately. Whether a business can resume normal activity in three hours or three days now determines if it survives or permanently closes.
Backups are only part of the recovery process
Many businesses assume that because their data is stored and backed up, then their recovery is sound. The reality is that there is a clear difference between secure backups and being able to execute a full system restoration quickly.
Data backups are only as effective as its last successful, timed restore test. Business systems are dynamic and constantly evolving; deferred software updates and workflow changes can introduce unexpected bottlenecks that stall recovery efforts.
That means instead of assuming resilience, businesses should focus their efforts on testing it. Regardless of whether security is managed in-house or outsourced to an MSP, any businesses that consider themselves secure should be able to confidently identify where their data is backed up, how it is protected and their exact recovery timeline.
Leaning into AI
Because attack kill chains are getting shorter due to advancements in machine learning and generative AI, modern security tools also play a vital role in accelerating recovery times. Automated remediation and AI-driven malware detection for example can help businesses contain breaches faster and reduce alert fatigue, allowing teams to focus immediately on higher-priority threats.
These tools are often most effective when they are accessed through consolidated security, as they still enable security businesses to access the latest technologies without worsening tool sprawl or requiring teams to monitor multiple environments simultaneously.
The regulatory and insurance gap
Beyond internal operational benefits, robust recovery capabilities are becoming mandatory for compliance and risk transfer. UK regulatory bodies increasingly evaluate businesses on overall operational resilience rather than static compliance checklists.
Similarly in the insurance industry, underwriters are taking on a more disciplined approach to managing risk and now require granular proof of resilience, which includes test logs and MFA enforcement, before providing cover and honouring claims.
For many businesses, insurance is often the final safety net to recover financial losses when all other efforts fail. However, given that 40% of claims are rejected, many businesses could be operating under the assumption that they’re more covered than they actually are. This turns limited recovery capabilities into a fundamental business continuity risk, rather than a mere IT issue.
Businesses are only secure if they can recover
Focusing on threat prevention creates a dangerous blindspot for businesses. While defensive measures are critical for keeping attackers at bay, assuming that security perimeters are unbreachable and not putting the same effort into recovery is a flawed strategy.
Security maturity is not defined by who has the most advanced tech stack or absence of cyber incidents. Rather it is defined by the speed and control in which a business recovers when those defences are placed under pressure.
Even the best tools on the market are not perfect. When an incident occurs, business leaders need absolute confidence that operations can recover. How businesses approach a recovery might vary, but those who treat recovery as ongoing discipline where regular testing and clear protocols matter just as much as the tools themselves will be best placed to survive even the most severe of attacks.
Myles Bray is CEO of CyberSentriq.


Be First to Comment