---
title: "You Don’t Know If You’re Resilient Until Everything Goes Dark"
date: "2026-08-18"
summary: "Most organisations don't have a recovery plan—they have a collection of assumptions. Here's why true cyber resilience is about much more than backups and disaster recovery."
canonical: "https://thepragmaticcio.net/articles/you-dont-know-if-youre-resilient-until-everything-goes-dark/"
tags: "Cyber Resilience, CIO, Disaster Recovery, Business Continuity, Cybersecurity, Leadership, Enterprise Risk"
---

# You Don’t Know If You’re Resilient Until Everything Goes Dark

Most organisations don't have a recovery plan—they have a collection of assumptions. Here's why true cyber resilience is about much more than backups and disaster recovery.

![The real test of resilience isn’t how quickly you recover. It’s how well your organisation functions while everything is still offline](security-darkness.png "The real test of resilience isn’t how quickly you recover. It’s how well your organisation functions while everything is still offline")

**Most organisations don't have a recovery plan.**

**They have a collection of assumptions.**

Imagine every digital system in your organisation disappeared at **09:00 tomorrow morning.**

**What would still work by 09:15?**

Most organisations would begin by thinking about the technology.

Which systems can we recover?

Are the backups intact?

How quickly can we restore the ERP?

Those are important questions.

They're just not the first questions.

In every major cyber incident I've been involved with or studied, the biggest surprises weren't technical.

They were human.

The right people couldn't communicate.

The wrong people had the authority.

Recovery documentation lived inside the very systems that had disappeared.

Decisions slowed precisely when they needed to accelerate.

That's why I believe many organisations don't actually have recovery plans.

They have a collection of assumptions that nobody realises exist until they're tested.

## The 09:00 Test

Business continuity plans are usually written around plausible failures.

A regional outage.

A failed application.

A cyberattack affecting a single environment.

A failed data centre.

But what if none of those assumptions applied?

What if every digital system disappeared at exactly the same moment?

Not degraded.

Not partially available.

Gone.

No Microsoft 365.

No Teams.

No identity platform.

No ERP.

No CRM.

No finance systems.

No HR systems.

No customer portal.

No cloud console.

No privileged access.

No email.

At 09:00 on a Monday morning.

How would your organisation function by 09:15?

That is the real resilience test.

Not whether you can recover technology.

Whether your business can continue making decisions while technology is being recovered.

## Recovery Is Not a Technical Exercise

Technology is usually the easiest part.

People are harder.

Do business leaders know who is making decisions?

Can they contact each other without corporate systems?

Can legal approve emergency actions?

Can procurement engage suppliers?

Can HR communicate with employees?

Can customer services continue operating?

Can manufacturing continue safely?

Recovery plans often assume competent people will simply appear, already connected, already informed and already authorised.

Reality is rarely that kind.

The technical infrastructure often survives better than the human infrastructure.

That's the assumption many organisations never test.

## A Backup Is Not a Recovery Strategy

One of the most dangerous assumptions is believing backups automatically create resilience.

They don't.

A backup is simply a copy.

Recovery depends on everything surrounding that copy.

Can you authenticate?

Can you access it?

Can you trust it?

Can you restore it at scale?

Can you recover without relying on the same identity platform that has already been compromised?

If your recovery environment depends on the very systems you're trying to recover from, you haven't removed the dependency.

You've duplicated it.

The uncomfortable truth is that many organisations have invested heavily in backup technology while investing very little in proving they can actually recover.

Those are not the same thing.

## The Four Assumptions Every CIO Should Challenge

Rather than asking whether your disaster recovery plan exists, I'd start somewhere else.

Challenge the assumptions behind it.

### 1. We can still communicate.

If Teams, email and corporate telephony disappear together, what is your first communication channel?

Who knows how to use it?

Who owns it?

### 2. We know who is in charge.

Recovery isn't slowed by technology.

It's slowed by uncertainty.

If decisions require five approvals, recovery will always move slower than the attacker.

### 3. We can trust what we recover.

As AI becomes embedded across the enterprise, another question emerges.

How do you know the recovered data is trustworthy?

An attacker doesn't always need to encrypt your data.

Quietly corrupting it may cause even greater damage.

AI systems trained on compromised information will make compromised decisions.

Recovery increasingly means restoring confidence as much as restoring systems.

### 4. We can keep operating while recovering.

The objective isn't to recover servers.

The objective is to continue serving customers.

Technology recovery is only valuable if the business can survive long enough to benefit from it.

That's the distinction many resilience programmes still miss.

## The Board's Conversation Needs to Change

Too often, resilience is discussed using technical language.

Recovery Time Objective.

Recovery Point Objective.

Immutable backups.

Identity isolation.

Air gaps.

Those terms matter.

Boards rarely think in those terms.

They think in consequences.

How much revenue is lost after four hours?

What happens after twenty-four?

Which regulators need notifying?

What happens to customer trust?

How does this affect shareholder confidence?

The CIO's job isn't simply to explain recovery technology.

It's to translate technical capability into business impact.

That's how resilience receives the attention—and investment—it deserves.

## The Pragmatic View

Cyber resilience isn't measured by how quickly you recover after disaster.

It's measured by how well your organisation continues to function while recovery is happening.

Technology matters.

Backups matter.

Identity matters.

Threat intelligence matters.

But assumptions matter most.

Because assumptions are invisible until they're tested.

The organisations that cope best with major incidents aren't always the ones with the newest technology.

They're the ones that have already challenged their own thinking.

They've rehearsed difficult conversations.

Removed unnecessary dependencies.

Empowered people to act.

And accepted that resilience is ultimately an organisational capability—not a technical feature.

The first system you lose during a major cyber incident isn't your ERP.

It's your assumptions.

---

**If every digital system in your organisation disappeared at 09:00 on Monday morning, what would still be working by 09:15—and are you certain, or are you assuming?**
