Sean Tilley at 11:11 Systems outlines the common mistakes made by businesses in resilience and cyber recovery strategies, and how organisations can build recovery plans that remain adaptable to business operations

A business can invest heavily in resilience and yet still be unprepared for recovery. Secondary data centres, replicated storage and protected backup environments are important for disaster recovery, but they do not guarantee the safe restoration of critical services after a cyber-incident.
Often, recovery plans lag behind the pace of business change. As organisations adopt cloud services, add applications, acquire companies, modernise processes and connect systems in new ways, environments become increasingly complex and difficult to fully understand.
These gaps often stay hidden during normal operations and only become apparent during a crisis.
Boards are used to asking about prevention. They want assurance that attacks are being stopped, controls are improving, and detection is getting faster.
Recovery rarely gets the same attention, partly because it is harder to prove before anything has gone wrong.
Plans can appear sound in workshops or spreadsheets, but a live incident will quickly reveal whether the organisation understands the dependencies behind the services that customers, employees, and partners rely on.
For example, a customer service platform may rely on multiple databases, identity systems and third-party integrations, while manufacturing processes may depend on applications managed by different teams across different locations. Revenue-generating services could also be linked to infrastructure that was never originally deemed business critical.
These links are often overlooked during normal operations, but during a cyber-incident they can determine whether recovery is controlled or prolonged by problems the organisation had not anticipated.
At that point, decisions about service priority, system trust, recovery order, and accountability are made while the business is already under strain.
Many resilience strategies are still built around a relatively simple pattern of disruption.
A server fails, a data centre goes offline or a network connection drops, and the organisation works to restore availability as quickly as possible.
A cyber-incident creates a more complex recovery challenge.
During an attack, the organisation may not know which systems, applications or data can be trusted, which means recovery depends on validation as well as restoration.
Data may need to be checked before it returns to production, dependencies need to be understood and recovery priorities need to reflect business impact rather than technical architecture.
Older resilience models may show where infrastructure sits, but they do not always show how the business should respond when trust, sequence and timing are uncertain.
A secondary site, immutable backups and replicated environments all have value, but they do not, on their own, tell the business what to recover first, what can be trusted, or how connected services will behave once they are brought back online.
Many recovery plans are still shaped by the assumption that recovery begins after an attack.
In practice, effective recovery starts much earlier, with a clear view of the services the business cannot afford to lose and the applications, data, suppliers and processes that support them.
Regular testing is essential because businesses do not stand still. New systems are introduced, processes evolve and responsibilities shift, which means a plan that worked two years ago may not be fit-for-purpose for how it operates today.
The resilience of recovery plans needs to remain adaptable to how the business works, rather than becoming a plan that is completed, approved and quietly filed away.
Board discussions about cyber-resilience often begin with whether the right technology is in place.
Technology has a critical role, but it cannot answer whether the business can recover in the way leadership expects.
A stronger test is whether leadership can explain which services would be prioritised, which dependencies support them, and whether recovery assumptions have been tested against the organisation as it operates now.
That provides a clearer view of resilience than a checklist of technologies.
After years of investment, many organisations have the outward signs of resilience, while operational complexity has continued to develop behind the scenes.
The next cyber-incident will test more than the organisation’s technology, and it will test whether the business understands itself well enough to recover.
Sean Tilley is Senior Director of Sales for EMEA at 11:11 Systems
Main image courtesy of iStockPhoto.com and BlackJack3D
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543