Here is a question most businesses cannot answer until the day they desperately need to: if ransomware encrypted your systems this morning, how long would it take to get the business running again? Not whether you have backups — almost everyone says yes to that. How long, in hours or days, until your people are working, your customers are served, and your data is back. The honest answer, for most businesses, is “we don’t know,” and not knowing is itself the problem.
Why “we have backups” is not the answer
Having backups and being able to recover are different things, and the gap between them is where businesses get hurt. Backups fail more often than anyone expects. They are incomplete, missing a critical system nobody thought to include. They are out of date, running less often than assumed. They are reachable by the attacker, so the ransomware encrypts the backups too. Or — most common of all — they have never actually been tested by restoring from them, so nobody knows whether they work or how long they take.
A backup you have never restored from is a hope, not a plan. The first time you find out whether it works should never be during a real incident.
Free · 4 minutes
If your most senior engineer left tomorrow, would anyone still understand the system?
Fourteen questions on documentation, dependencies, and the gap between how the architecture works and how many people know it. Banded finding on screen, full sheet by email.
What actually determines recovery time
Recovery time depends on more than the backups themselves. It depends on how quickly you can stand up clean systems to restore onto, which is far harder if your environment is complex or partly undocumented. It depends on the order of recovery — which systems must come back first for the business to function at all. It depends on whether anyone has the runbook, or whether recovery is being improvised under pressure while the business bleeds. And it depends on dependencies: a system frozen on unsupported software, the kind described in the compound problem, can be far harder to rebuild cleanly than anyone expects.
Two numbers capture what matters. How much data you can afford to lose — the gap between your last good backup and the moment of attack. And how long the business can survive without its systems. If you have never set these targets, you are recovering blind.
Why this is now a business and insurance issue
Ransomware is no longer a rare, exotic threat; it is one of the most common ways a business is seriously disrupted. That is why it sits at the centre of cyber insurance questionnaires — insurers ask directly about backups, testing and recovery, because recoverability is what determines whether a ransomware event is a bad week or an extinction event. A business that cannot evidence its recovery position pays for it in premium, in cover, and potentially in a denied claim.
It is also the sharp end of business continuity more broadly — the same question as whether your business could operate tomorrow if the worst happened, with a specific, increasingly likely cause.
How to find out — safely
The way to answer the question is a recovery assessment, and it takes about a day. Confirm what is actually backed up and how often. Test a restore, so “we have backups” becomes “we have proven we can recover.” Establish the order of recovery and write the runbook. Set the two targets — acceptable data loss and acceptable downtime — and check whether your current setup can meet them. The exercise turns an unknown into a known, and almost always surfaces gaps that are cheap to fix now and catastrophic to discover during an attack.
Most businesses do not know how long recovery would take until they need to, and by then it is too late to change the answer. A recovery assessment changes that permanently. We will find out how long you would actually be down — before you have to.
Start a ConversationFree interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming