Principles every enterprise must test before the attack arrives
Executive Take
Boards and executives should demand recovery plans framed in dollar and regulatory-exposure terms, not technical jargon, and verify that backup infrastructure has zero shared identity or trust with production systems like Microsoft 365 or Azure AD.
Executive Summary
A Foundry contributor op-ed argues enterprises must stress-test recovery plans for total, destructive cyberattacks (not ransomware). Citing a survey where 90% of organizations expressed recovery confidence but under one-third of ransomware victims fully recovered data, and a study finding only 5% of boards have cybersecurity experts, it urges air-gapped backups and business-impact framing of RTOs.
Why It Matters
Cybersecurity and technology leaders should care because the piece exposes a widespread false sense of resilience most continuity plans assume partial outages, not total, coordinated, geopolitically-motivated blackouts, leaving critical business functions and boards under-informed about real recovery gaps.