Ask most business owners how well protected they are from a cyber-attack and you'll get a confident answer. Firewalls, antivirus, monitoring, a good IT provider keeping watch. All of it sensible. All of it needed.
Now ask a slightly different question. If something got through tomorrow morning, say ransomware on the main system or a lost device full of customer data, what would the business actually do? Who makes the first call? How long could you keep serving customers? Who tells the staff, and what do they tell them?
This is usually where the confident answers run out. And it matters just as much as the first question, because cyber resilience isn't only about keeping attackers out. It's about being able to keep trading, and recover quickly, when one eventually gets in.
Protection and recovery are not the same thing
It's easy to treat these as one and the same. Good security lowers the chance of an incident. Continuity planning lowers the damage when one happens. You need both. Putting all your effort into one and very little into the other leaves a gap that only shows up at the worst possible moment.
The plain truth is that no amount of security brings the risk down to zero. Threats change, people click the wrong link, suppliers get breached, devices go missing. Businesses that cope well accept this and plan for it. Businesses that struggle assume prevention will hold, and then have to make it up as they go.
Where continuity planning tends to go missing
In most cases the recovery side isn't missing entirely. It just isn't in a shape anyone could rely on when the pressure is on. A few patterns come up time and again.
None of these are unusual or dramatic failures. They're simply what happens when a business grows faster than its processes, and when prevention gets all the attention because it's the part people are used to buying.
The good news is that the fix is usually cheap
Here's the part that surprises people. Closing this gap is often low cost and straightforward. It's rarely about buying more technology. Most of the value comes from a few simple steps.
Turning an informal habit into a written, practised plan is one of the best value things a business can do for its own resilience.
How Ascentium can help
At Ascentium, we help businesses strengthen both sides of resilience: how well protected they are, and how well they could recover. We did this recently for an established business that had been running for over 40 years and invested significantly in technology.
We were able to help independently identify any technology gaps and address recovery plans which were missing. The owners left happy that they knew the business risks and had expertise on hand to ensure the gaps were closed.
Our Cyber Resilience and Recovery Reviews are independent, based on real conversations rather than tick boxes, and written in plain language. We look at your protection, governance, people, systems and continuity, rate each area simply as red, amber or green, and turn what we find into a clear list of actions your leadership team can get on with. We always start with the changes that give the most back for the least cost and effort.
Where a continuity or incident plan is missing, informal or untested, we help you build one and practise it, so the good instincts already in your business become something anyone could follow on a bad day.
Good security keeps most incidents out. A tested plan makes sure the ones that get through don't turn into a crisis. If you feel sure about the first but less sure about the second, that's usually the conversation worth having.
Ascentium offers independent cyber resilience and continuity advice. If this raised a question about your own business, we're always happy to talk it through.
I wanted to create a company that allowed SME's to access world class technology expertise without the huge price tag. I was fed up of organisations getting paid to deliver slide decks without…